Login IP & Country Restriction
View on WordPress.orgScores higher than 71% of indexed plugins
About
Tighten your website security and fight against dictionary bot attacks originating from other countries, by denying access.
What It Does
Login IP & Country Restriction blocks or allows access to your WordPress login page based on the visitor's IP address or geographic country. It lets administrators define country allowlists or blocklists, restrict specific IP ranges, and apply these rules to wp-login.php and wp-admin to fend off brute force and dictionary attacks from foreign botnets.
Who It's For
This plugin is best for site owners who operate from a known geographic area and want to shut the door on login attempts from everywhere else, such as US-only SaaS products, regional e-commerce stores, financial portals, and government or healthcare sites subject to jurisdictional access controls. It is also a reasonable fit for small businesses that are seeing repeated brute force traffic from overseas.
Who Should Skip It
If your audience is genuinely international, or if you rely on contributors, clients, or travelling staff who log in from changing IPs and countries, this plugin will lock out legitimate users. Sites using a CDN, proxy, or shared office network where many users share an IP range should also look elsewhere.
The Bottom Line
Login IP & Country Restriction does a narrow job cleanly, scores 78.78 out of 100, and is kept current by its developer, but its tiny install base and absent support footprint mean you are largely on your own if something breaks. It is worth a look for single-region sites that want a lightweight country firewall; everyone else should default to IP2Location Country Blocker.