Witen Blocker Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
Witen Blocker provides local login protection, bot controls, and file checks without an account. Connect to Witen for shared threat intelligence.
- Limit login failures and enable two-factor authentication.
- Manage blocked IPs, trusted addresses, and individual bot policies.
- Check core files against WordPress.org checksums and monitor content changes.
- Scan files with bundled checks and connected detection catalogs.
- Review activity and reporting status.
Local features have no paid unlock or trial expiry. Hosted plans determine remote feeds, refresh frequency, and off-site backup storage. Scan findings need review; they do not prove that a file is malicious.
On shared hosting, enrolled sites check requests against local blocklists and return HTTP 403 for matches. Background jobs refresh intelligence and send reports. On managed servers, the optional Witen Warden agent can enforce blocks at the host firewall; WordPress retains its settings and bot policies.
Connecting authorizes security-event sharing. Read the service and privacy disclosures below. Unconnected sites keep events local.
External Services
Witen Collector — https://collector.witenlabs.com, or your configured collector.
Enrollment exchanges a setup token and installation identity for a credential. Background requests send events and inventory and retrieve blocklists, bot identities, signed malware catalogs, service availability, network statistics, Tor exit nodes, account allowlists, and threat-feed profiles. Profile changes send the selection and sensor identity. Manual IP lookups send the queried address for network/ASN information. Decision receipts send the IP, matched rule or policy, outcome, request context, and sensor identity. Event fields, retention, and consent are detailed below.
Malware samples are off by default. WITEN_SEND_MALWARE_SAMPLES set to boolean true in wp-config.php permits bounded file-content uploads. Scanning does not require them.
Off-site .htaccess backups are off by default. Enabling them permits uploads and background restores requested in the customer dashboard. Files are encrypted to the collector’s public key, with checksum and size sent alongside. Witen can decrypt them for restores and keeps 10 versions. Restores validate downloaded content, create a local backup, and report results. Disabling backups stops uploads and remote restores; local editing and backups remain available.
Witen terms | Witen privacy policy. Other collector operators set their own policies. In socket mode, these events go to local Warden; its configuration determines onward transmission.
Cloudflare IP Lists — https://www.cloudflare.com/ips-v4/ and https://www.cloudflare.com/ips-v6/.
Enrolled installations refresh proxy ranges during background maintenance to interpret forwarded client addresses safely. Offline installations use bundled ranges. Requests contain ordinary HTTPS network metadata, with no WordPress visitor events or account data. Cloudflare terms | Cloudflare privacy policy.
WordPress.org Core Checksums — https://api.wordpress.org/core/checksums/1.0/.
Integrity scans request official core hashes using the installed WordPress version and locale, plus ordinary HTTPS network metadata. No visitor events, account data, or site content is sent. WordPress.org privacy policy.
The plugin does not remotely load executable code or frontend assets. includes/bot-identities.json is local CC0-1.0 crawler data with adjacent license and provenance files. Website links and hostname patterns do not trigger requests or live crawler DNS checks. The configured DNS resolver receives collector hostname queries and the server address. Background jobs and Apache rule checks call the site’s own WordPress URLs.
includes/malware-catalog-public-key.txt holds the public Ed25519 verification key; the private key is not shipped. Failed catalog updates retain the last verified copy.<h3>Privacy Policy</h3>
Events are shared only after enrollment or explicit WITEN_SOCKET_PATH configuration. Earlier events stay local and are never queued or uploaded retroactively. Connected threat intelligence requires sharing; use offline mode or deactivate the plugin to stop it.
Data sent
Security observations can include IP addresses; login failures and successes; XML-RPC calls; comment, registration, and 404 events; request URIs, methods, User-Agent strings, referrers, and query information; and attempted usernames, which may be email addresses. Installation inventory includes site name and URL, WordPress/PHP/plugin versions, and a random UUIDv7 identifier. An observed IP is not necessarily an attacker. The collector uses these reports to identify distributed attacks, correlate repeated failed logins with later successful ones, and maintain shared blocklists.
Event reports exclude form bodies, post content, comment text, password fields, cookies, and session data. URLs and metadata can contain personal data; keep secrets out of URLs and logs. Separately enabled samples contain file content; off-site backups contain .htaccess content.
Retention and removal
Collector retention and deletion follow that operator’s published policy. Locally, the delivery queue holds at most 500 events for seven days. The plugin also keeps the latest 100 dashboard events and blocks, block and allow lists, and health counters. Rejected events and decision receipts are stored for diagnosis, limited to 100 records or 1 MiB per queue, with older records removed at the limit. These diagnostic records remain until replaced or uninstalled.
Uninstall removes Witen options, transients, scheduled actions, and database tables. Request collector-side deletion from its operator. WITEN_NO_TELEMETRY stops daily inventory reporting, but not connected security-event sharing.
Screenshots
No screenshots provided

