Browse documentation
WordPress

WordPress Firewall, Blocking, Under Attack Mode and the Activity Log

Refuse common attacks, block addresses and countries, switch on an emergency browser check, and see what was stopped.

3 min readUpdated Oct 10, 2026

The Firewall, Under Attack and Activity sections of the Security tab decide who may reach your site and show you what was stopped. As everywhere on the tab, press Apply to site to make changes live (Under Attack has its own buttons that apply at once).

Firewall

The firewall refuses requests that look like SQL injection, script injection, file-inclusion tricks, probes for secret files (such as .env, .git and wp-config.php) and well-known hacking tools. It looks at the address of the request and the browser name, not at the contents of forms you submit. Visitors who are signed in and addresses on your allow list are never checked.

Block addresses, and always allow yours

  • Block these addresses: up to 300 entries, one per line. Use a single address or a range such as 198.51.100.0/24.
  • Always allow these addresses: up to 100 entries. Your office or home address goes here. It is never blocked, challenged or locked out by anything on this tab.

Single IPv4 addresses and /8, /16 and /24 ranges are refused by the web server itself, so even pages served from the page cache are covered. Other ranges and IPv6 addresses are refused on every page that runs WordPress.

Block countries

Pick the countries to block. Visitors from them see an "access denied" page. The country of an address comes from the free IP geolocation data of DB-IP.com, which FlyNode downloads for your site and refreshes by itself. A visitor whose country cannot be told is let in. Two things to know:

  • While the country block is on, the page cache is switched off for your site so that every visit is checked, so the site may be a little slower.
  • Do not block the country you work from. If you do, change it back from the Security tab (your dashboard is not affected).

Under Attack mode

Use it when bots are flooding your site. Every visitor who is not signed in first sees a short "Checking your browser" page that a real browser passes in a moment and simple bots never do. The pass lasts 12 hours and belongs to that visitor's address.

  1. Open Under Attack, choose how long (1 hour to 7 days) and press Turn on now.
  2. It switches itself off when the time is up. Turn off now ends it sooner, and you can extend it.

Not checked: signed-in users, your allow list, shop payment callbacks, WordPress's own scheduled tasks and FlyNode's 1-Click WP-Admin. Search engines and uptime monitors do see the check page and are asked to try again later, and the page cache is off while it is on. That is why it is meant for emergencies and not for every day.

Activity log

The Activity section lists sign-ins and everything the protection stopped, for the last 30 days: wrong passwords, lock-outs, wrong two-factor codes, firewall blocks, blocked addresses and countries, Under Attack checks, and visits to the old login address. Repeats from one address within a minute are shown on one line with a count. Press Block on a line to add that address to the block list. Use the filter to show one kind of event, and the switch Keep the activity log to stop recording.

The activity log records addresses of visitors who tried to sign in or were blocked. Only keep it on if that suits your privacy policy.

Still stuck?

Open a support ticket from your dashboard and include the container name.

Contact support