=== IP Blocker for Free (by Sham) ===
Contributors: sham330
Tags: ip blocker, security, access control, whitelist, login security
Requires at least: 6.2
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.0.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html
Plugin URI: https://www.shamwebdev.com/plugins

Restrict WordPress login, selected pages, or exact URL paths to approved IP addresses and ranges.

== Description ==

IP Blocker is a lightweight access-control plugin by Sham. It lets administrators create independent IP allowlist rules for sensitive areas of a WordPress website.

Features:

* Protect wp-login.php.
* Protect any individual WordPress page.
* Protect an exact URL path such as /private-area.
* Add and delete rules independently.
* Enable or disable individual rules.
* Emergency global protection toggle.
* IPv4 and IPv6 exact addresses.
* IPv4 wildcards such as 192.168.1.*.
* IPv4 and IPv6 CIDR ranges.
* Quick “Add my IP” control.
* Login lockout protection when saving settings.
* HTTP 403 responses with a configurable message.
* Uses REMOTE_ADDR by default instead of trusting spoofable forwarding headers.
* Optional Cloudflare CF-Connecting-IP mode for sites intentionally running behind Cloudflare.
* No tracking, telemetry, external API calls, or paid service dependency.

Important: IP allowlisting can lock legitimate administrators out when their public IP changes. Keep hosting/file access available when first configuring a login rule.

== Installation ==

1. Upload the `ip-blocker` folder to `/wp-content/plugins/`, or install the ZIP through Plugins > Add New > Upload Plugin.
2. Activate IP Blocker.
3. Open Settings > IP Blocker.
4. Add a rule and choose WordPress login, a WordPress page, or an exact URL path.
5. Add at least one allowed IP/range. For login protection, use “Add my IP” before saving.
6. Save settings and test from an allowed and a non-allowed network.

== Frequently Asked Questions ==

= What IP formats are supported? =

Exact IPv4/IPv6 addresses, IPv4 wildcards, and IPv4/IPv6 CIDR notation.

= Can I protect multiple pages? =

Yes. Create one rule per page. Each page can have a different IP allowlist.

= Can I protect wp-login.php? =

Yes. Select “WordPress login” as the target. The plugin prevents enabling a login rule that does not contain the current detected IP.

= Does this block wp-admin? =

Version 1.0.0 protects wp-login.php and selected front-end targets. It does not globally block wp-admin, AJAX, REST, cron, or CLI requests.

= Does the plugin trust X-Forwarded-For? =

No. It uses REMOTE_ADDR by default. X-Forwarded-For is not safe to trust blindly. An optional Cloudflare mode is available for sites intentionally behind Cloudflare.

= Does it send data anywhere? =

No. IP Blocker has no telemetry and makes no external API requests.

== Screenshots ==

1. IP Blocker settings and current IP.
2. Access rules for login, pages, and URL paths.
3. Per-rule IP allowlist controls.

== Changelog ==

= 1.0.0 =
* Initial open-source release.
* Login, page, and exact-path restrictions.
* IPv4, IPv6, CIDR, and IPv4 wildcard matching.
* Admin lockout protection and configurable 403 message.

== Upgrade Notice ==

= 1.0.0 =
Initial release.
