Title: Witen Blocker — Login Lockout, 2FA &amp; AI Crawler Blocking
Author: witenlabs
Published: <strong>2026-يىلى 22-سېنتەبىر</strong>
Last modified: 2026-يىلى 4-ئۆكتەبىر

---

قىستۇرما ئىزدە

![](https://ps.w.org/witen-blocker/assets/banner-772x250.png?rev=3706552)

![](https://ps.w.org/witen-blocker/assets/icon.svg?rev=3706552)

# Witen Blocker — Login Lockout, 2FA & AI Crawler Blocking

 يازغۇچى [witenlabs](https://profiles.wordpress.org/witenlabs/)

[چۈشۈر](https://downloads.wordpress.org/plugin/witen-blocker.0.6.50.zip)

 * [تەپسىلاتلار](https://ug.wordpress.org/plugins/witen-blocker/#description)
 * [باھالاشلار](https://ug.wordpress.org/plugins/witen-blocker/#reviews)
 *  [ئورنىتىش](https://ug.wordpress.org/plugins/witen-blocker/#installation)
 * [ئىجادىيەت](https://ug.wordpress.org/plugins/witen-blocker/#developers)

 [قوللاش](https://wordpress.org/support/plugin/witen-blocker/)

## چۈشەندۈرۈش

Witen Blocker helps protect your WordPress site from password guessing, unwanted
bots, and comment spam. Add two-factor authentication, check suspicious file changes,
and review detections and blocks in your WordPress dashboard.

Start with free local protection. Connect to Witen when you want blocklists informed
by attacks seen across participating sites and servers.

#### Protect your logins

Limit repeated failed login attempts and add two-factor authentication with an authenticator
app. Recovery codes give you a way back in if you lose your device.

#### Block known exploit requests

Built-in checks block template traversal and comment exploit requests before they
reach the affected WordPress handlers. These checks work without an account. Keep
WordPress, themes, and plugins updated as well.

#### Decide which bots can visit

Choose which recognized search crawlers, AI crawlers, and automated clients to allow
or block. Manage trusted addresses and review detections before blocking.

#### Cut down comment spam

Catch automated submissions with hidden form fields and timing checks. These checks
run on your site without sending comment text to a spam service.

#### Find unexpected file changes

Compare WordPress core files with official checksums, monitor changes in your content
directory, and scan files for suspicious patterns. Bundled checks work without an
account. Connected sites can receive maintained malware catalogs. Review findings
before taking action.

#### Learn from attacks beyond your own site

The optional Witen service combines security reports from participating sites and
servers to identify repeat attackers and maintain shared blocklists. An enrolled
site can block listed IPs even if they haven’t attacked that site before. Reports
are processed centrally; request checks use a local blocklist.

Connecting requires a Witen account and security-event sharing. All local features
are free, with no trial expiry. Free connected WordPress sites receive a daily threat-
feed update without an added data delay. Paid plans add more sites and servers, 
other feed profiles, and optional off-site backup storage.

#### Run on shared hosting or your own server

On shared hosting, matching blocklist requests receive an HTTP 403 response from
WordPress. No server administration access is needed. On your own server, the optional
Witen Warden agent can enforce IP blocks at the firewall, before blocked traffic
reaches PHP.

**Get started:** activate Witen Blocker and open **Witen > Dashboard**. Local protection
needs no account. Use **Login** for login limits and two-factor setup, and **Firewall
> Bots and AI crawlers** to choose which crawlers can visit.

[Setup guide](https://www.witenlabs.com/docs/wordpress) | [Witen plans](https://www.witenlabs.com/pricing)
| [Support](https://wordpress.org/support/plugin/witen-blocker/)

### External Services

#### Witen Collector

Connected features use `https://collector.witenlabs.com`. Enrollment exchanges your
setup token and installation identity for a credential. Witen processes shared reports
to identify distributed attacks and provide threat intelligence.

Background sync sends events and site details (listed below) and retrieves blocklists,
bot identities, signed malware catalogs, Tor exit nodes, allowlists, service status,
network statistics, and feed profiles. Profile changes send your selection and site
identifier; IP lookups send the queried address. Block reports include the IP, rule,
outcome, request context, and site identifier.

 * **Malware samples:** off by default. Setting `WITEN_SEND_MALWARE_SAMPLES` to 
   boolean `true` in `wp-config.php` permits file-content uploads. Scans do not 
   require them.
 * **Off-site .htaccess backups:** off by default. Enabling them permits encrypted
   file uploads, with checksum and size, and dashboard-requested restores. Witen
   can decrypt the files and keeps 10 versions. Restores validate content, make 
   a local backup, and report results. Disabling the option stops uploads and remote
   restores; local backups remain available.

[Witen terms](https://witenlabs.com/terms) | [Witen privacy policy](https://witenlabs.com/privacy)

    ```
    WITEN_COLLECTOR_URL selects another collector if you operate one; its operator's policies apply. Explicitly configuring `WITEN_SOCKET_PATH` authorizes sharing with local Warden, whose configuration controls onward delivery. Detecting a socket alone does not enable sharing.
    ```

#### Cloudflare proxy ranges

Enrolled sites refresh `https://www.cloudflare.com/ips-v4/` and `https://www.cloudflare.
com/ips-v6/` during background maintenance to recognize trusted proxies. Offline
sites use bundled ranges. Requests send ordinary HTTPS network metadata, not WordPress
visitor events or account data.

[Cloudflare terms](https://www.cloudflare.com/website-terms/) | [Cloudflare privacy policy](https://www.cloudflare.com/privacypolicy/)

#### WordPress.org core checksums

Integrity scans request official hashes from `https://api.wordpress.org/core/checksums/
1.0/`, sending your WordPress version, locale, and ordinary HTTPS network metadata.
No visitor events, account data, or site content is sent.

[WordPress.org privacy policy](https://wordpress.org/about/privacy/)

The plugin does not remotely load executable code or frontend assets. Bundled bot
references cause no remote requests or crawler DNS lookups. Collector connections
use your DNS resolver. Background jobs and Apache rule checks call your own WordPress
URLs.

### Privacy Policy

Events stay local until enrollment or explicit Warden socket configuration. Earlier
events are never uploaded retroactively. Connected intelligence requires event sharing.
Deactivate the plugin to stop reporting from WordPress; a separately running Warden
keeps its own reporting configuration.

**What is shared:** IP addresses; successful and failed logins; XML-RPC, comment,
registration, and 404 events; request URLs, methods, User-Agent strings, referrers,
and query information; and attempted usernames, which may be email addresses. Installation
reports include site name and URL, WordPress/PHP/plugin versions, and a random installation
identifier. An observed IP is not necessarily an attacker. Reports help identify
distributed attacks, relate failed logins to later successful ones, and maintain
blocklists.

Event reports exclude form bodies, post content, comment text, password fields, 
cookies, and session data. URLs and metadata can contain personal data. File samples
and .htaccess backups are separate options, described above. `WITEN_NO_TELEMETRY`
stops daily installation reports, but not connected security-event sharing.

**Local storage:** the delivery queue holds up to 500 events for seven days. Witen
also keeps the latest 100 dashboard events and blocks, block and allow lists, and
health counters. Rejected events and block-decision reports have separate diagnostic
queues, each limited to 100 records or 1 MiB. Older records are removed at the limit;
diagnostics otherwise remain until uninstall.

Deactivation preserves settings and existing .htaccess and Warden firewall rules.
Uninstall removes Witen options, transients, scheduled actions, and database tables.
Collector retention follows its operator’s privacy policy; request collector-side
deletion from that operator.

## ئېكران كەسمىسى

[⌊Protection active on an unconnected WordPress installation, with optional two-
factor, crawler and account setup.⌉⌊Protection active on an unconnected WordPress
installation, with optional two-factor, crawler and account setup.⌉[

Protection active on an unconnected WordPress installation, with optional two-factor,
crawler and account setup.

[⌊Per-crawler AI policies: choose which recognized crawlers are allowed or blocked.⌉⌊
Per-crawler AI policies: choose which recognized crawlers are allowed or blocked
.⌉[

Per-crawler AI policies: choose which recognized crawlers are allowed or blocked.

[⌊Login limits, two-factor setup links and a custom login address in one place.⌉⌊
Login limits, two-factor setup links and a custom login address in one place.⌉[

Login limits, two-factor setup links and a custom login address in one place.

[⌊File integrity and malware scan controls, with unscanned state shown accurately.⌉⌊
File integrity and malware scan controls, with unscanned state shown accurately.⌉[

File integrity and malware scan controls, with unscanned state shown accurately.

## ئورنىتىش

 1. Open **Plugins > Add New Plugin**, search for **Witen Blocker**, and install and
    activate it. You can also upload the plugin ZIP.
 2. Open **Witen > Login** to review login limits and set up two-factor authentication
    for your account. In **Firewall**, choose your bot rules and add your own trusted
    addresses to the never-block list.
 3. To add shared intelligence, create a [Witen account](https://www.witenlabs.com),
    add your WordPress site from the dashboard, and enter its one-time setup token 
    in **Witen > Settings**. Review the terms and privacy information before connecting.
 4. Check the connection and blocklist status after background maintenance runs.

See the [setup guide](https://www.witenlabs.com/docs/wordpress) to connect a local
Warden agent or configure your site through wp-config.php.

## FAQ

### What can I use without an account?

Login limits, two-factor authentication, comment spam checks, bot controls, file-
integrity checks, bundled malware checks, and the .htaccess editor. Connecting to
Witen adds hosted intelligence and reporting; it is optional.

### Will it slow down my site?

Normal request checks use local data and do not wait for a remote service. Updates,
reporting, and scans run in background jobs and use server resources. On quiet sites,
WordPress cron may wait for a visitor before running jobs.

### Can I use it alongside another security plugin?

Check for overlapping two-factor, login, bot, and .htaccess settings. Test your 
login and site after changes. Keep WordPress, themes, and plugins updated, and maintain
a backup.

### How do I change login limits or recover from a lockout?

Open **Witen > Login > Login lockout** to set the failure window, failure count,
and ban duration. Defaults are 5 failures in 5 minutes and a 1-hour ban. Saved settings
override `WITEN_LOGIN_WINDOW_SEC`, `WITEN_LOGIN_MAX_FAILURES`, and `WITEN_LOGIN_BAN_SEC`
in wp-config.php. The same controls remain available in Settings.

Keep your 2FA recovery codes. If locked out, wait for the ban to expire or follow
the [recovery guide](https://www.witenlabs.com/docs/lockout), including WP-CLI and
SFTP steps. Deactivation leaves existing .htaccess and Warden firewall rules in 
place; the guide explains how to remove them.

### Does a scan finding mean my site is hacked?

Not necessarily. A changed file or suspicious pattern needs review; legitimate customizations
can produce findings. Witen helps identify files to investigate. It does not automatically
clean an infected site.

### What happens if Witen is unavailable?

Local protection continues. Cached intelligence is usable until it expires, and 
reports queue for background retries within the limits below. Warden socket mode
does not fall back to a direct collector connection.

### Does it support multisite?

Yes. Each site has its own settings, connection, logs, and jobs, initialized on 
its first request. The main site’s network administrator controls shared .htaccess.
User accounts and two-factor setup are network-wide. Connect each site separately
if you use a local Warden agent.

## باھالاشلار

بۇ قىستۇرمىغا تېخى باھا يېزىلمىدى.

## تۆھپىكار ۋە ئىجادكار

«Witen Blocker — Login Lockout, 2FA & AI Crawler Blocking» كودى ئوچۇق يۇمشاق دېتال.
تۆۋەندىكى كىشىلەر بۇ قىستۇرمىغا تۆھپە قوشقان.

تۆھپىكار

 *   [ witenlabs ](https://profiles.wordpress.org/witenlabs/)

[«Witen Blocker — Login Lockout, 2FA & AI Crawler Blocking» نى تىلىڭىزغا تەرجىمە قىلىڭ](https://translate.wordpress.org/projects/wp-plugins/witen-blocker)

### ئىجادىيەتكە قىزىقامسىز؟

[كودقا كۆز يۈگۈرتۈپ](https://plugins.trac.wordpress.org/browser/witen-blocker/)،
[SVN خەزىنە](https://plugins.svn.wordpress.org/witen-blocker/) تەكشۈرۈپ ياكى [RSS](https://plugins.trac.wordpress.org/log/witen-blocker/?limit=100&mode=stop_on_copy&format=rss)
ئارقىلىق [ئىجادىيەت خاتىرىسى](https://plugins.trac.wordpress.org/log/witen-blocker/)
گە مۇشتەرى بولغىلى بولىدۇ.

## ئۆزگىرىش خاتىرىسى

#### 0.6.50

 * Allow Starter and Growth plans to select global and SSH threat feeds consistently
   in settings and service synchronization.
 * Keep hidden Firewall pages accessible through WordPress’s native authorization
   checks.
 * Group controls into Dashboard, Firewall, Login, Scan, and Settings while keeping
   existing page links working.
 * Guide first-time activations to local protection and optional setup, with connection
   details in expandable diagnostics.
 * Show the two-factor field only after password verification for accounts using
   it. Passwords are never retained between attempts.
 * Translate more admin labels and show unscanned file integrity accurately.
 * Make login limits editable on production sites and apply wp-config.php login 
   constants consistently.
 * Show active local protection and bundled bot identities without requiring an 
   account.
 * Add Settings and recovery links, a deactivation warning, and a warning for unverified
   proxy addresses.

#### 0.6.49

 * Update the bundled Witen SDK to 1.4.7, keeping independent login observation 
   windows and matching Warden’s documented capability schema.
 * Preserve the existing WordPress login-defense behavior and settings.

See `changelog.txt` in the download for older releases.

## Meta

 *  Version **0.6.50**
 *  ئاخىرقى يېڭىلانغان ۋاقىت **13 سائەت بۇرۇن**
 *  ئاكتىپ ئورنىتىش سانى **10 دىن ئاز**
 *  WordPress نەشرى ** 6.2 ياكى يۇقىرى **
 *  **7.1.2** دا سىنالغان
 *  PHP نەشرى ** 8.1 ياكى يۇقىرى **
 *  تىل
 * [English (US)](https://wordpress.org/plugins/witen-blocker/)
 * بەلگە
 * [block ai crawlers](https://ug.wordpress.org/plugins/tags/block-ai-crawlers/)
   [bot blocker](https://ug.wordpress.org/plugins/tags/bot-blocker/)[limit login attempts](https://ug.wordpress.org/plugins/tags/limit-login-attempts/)
   [login security](https://ug.wordpress.org/plugins/tags/login-security/)[two factor](https://ug.wordpress.org/plugins/tags/two-factor/)
 *  [ئالىي كۆرۈنۈش](https://ug.wordpress.org/plugins/witen-blocker/advanced/)

## دەرىجە

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/witen-blocker/reviews/#new-post)

[بارلىق ئىنكاسنى كۆرسەت](https://wordpress.org/support/plugin/witen-blocker/reviews/)

## تۆھپىكار

 *   [ witenlabs ](https://profiles.wordpress.org/witenlabs/)

## قوللاش

چۈشەندۈرۈشىڭىز بارمۇ؟ ياردەم لازىممۇ؟

 [قوللاش مۇنبىرىنى كۆرسەت](https://wordpress.org/support/plugin/witen-blocker/)