Blocked addresses
Attack detection notices an address that attacks your sites and puts it on the fleet’s block list, which every server enforces at its firewall. It lives on Servers → Security.

How detection decides
Section titled “How detection decides”Each minute, the panel counts what every visitor address did across all sites and servers. An IPv6 visitor counts by its /64.
| Rule | Counts | Blocks at |
|---|---|---|
| Login guessing | POST wp-login.php answered 200, 401, 403 or 429 |
20 in 10 minutes |
| XML-RPC | POST xmlrpc.php |
60 in 10 minutes |
| Probing | Paths only an attacker asks for, such as /.env, at 4 points, and requests a rule refused, at 1 |
12 points in 10 minutes |
| Dead URLs | Different pages answered 404 | 60 in 5 minutes |
| Flooding | Requests a rate limit answered 429 | 300 in 10 minutes |
A first block lasts an hour. Each repeat within 30 days lasts four times as long, and never more than 30 days. A block lifted by hand is not a repeat. Every number can be changed on Detection, where Automatic blocking is On, Observe or Off. Observe writes down what it would block and blocks nothing.
Who is never blocked
Section titled “Who is never blocked”Neither detection nor a person can block these:
- Private addresses, your own servers, and the panel as each server sees it.
- Trusted proxies, by their address ranges.
- Jetpack’s servers, by the address list Jetpack publishes.
- AI assistants, by the address lists their companies publish: OpenAI, Anthropic, Google’s fetchers and agents, Perplexity, Mistral and DuckDuckGo. Site protection still limits them.
- Addresses on Never block.
- Every address that signed in to the panel or used an API key in the last 30 days.
The published lists are fetched weekly, and used only when they pass checks: about as many ranges as usual, none private and none too wide. Otherwise the last good copy stays.
Detection also leaves two kinds of visitor alone:
- A search engine’s crawler, once its address names a host under the engine’s own domain, such
as
googlebot.com, and that host names the address back. - An address with three or more different browsers behind it, which looks like a shared connection.
Block or unblock an address
Section titled “Block or unblock an address”- On Blocked addresses, choose Block an address. Block also appears beside an address in a site’s blocked requests and in its Busiest addresses.
- Enter the Address or range, pick how long under For, and add a Note.
- Choose Block. An address that is never blocked is refused, and the dialog says why.
Unblock lifts a block on every server within a minute. Never block keeps an address or range off the list for good, and lifts the blocks it overlaps. Site protection does not rate-limit those addresses either, but its refusals still apply.
How blocks are enforced
Section titled “How blocks are enforced”A block reaches every server within a minute, for ports 80 and 443 only.
| Layer | For | How |
|---|---|---|
| Network | Direct visitors | The server’s firewall drops their packets before Docker forwards them. Timed blocks end on time, with or without the panel, and stay through a reboot. |
| HTTP | Visitors behind a trusted proxy | Traefik matches the proxy’s header against the list and answers 403. At most 5,000 addresses. |
| HTTP fallback | Direct visitors, where the network layer is missing | The same, at most 2,000 addresses. |
Enforcement shows each server as In force, HTTP only, Off on the server or
Not installed. Blocked addresses reach the servers switches every block off and keeps the
list. On a server, this empties the network layer and keeps it empty until
sudo wpl7-firewall on:
sudo wpl7-firewall offLimits
Section titled “Limits”- Detection reacts within about two minutes, not seconds.
- SSH and FTP are not covered. They keep their own protection.
- A crawler on a domain the panel does not know is not verified, and can be blocked.
- A bot whose company publishes no address list is blocked like any visitor when it crosses a rule.
- Without IPv6 in Docker, direct IPv6 visitors arrive as one private address and are not detected one by one.