WordPress IP Blocking
Track login attempts across all your sites and block suspicious IPs with one click.
Birtikta gathers every login attempt on your WordPress sites in one screen: which site, which username, which IP and country, and whether it succeeded or failed. When you block a suspicious IP with one click, the Birtikta plugin blocks it on the site, and you can lift the block from the same place whenever you like.
Find suspicious attempts fast
Filter attempts by site, status and date range, and search by username, IP or country. Repeat attempts from the same IP within an hour are counted on a single row, so a heavy attack does not flood the list.
Block with one click, unblock with one click
When you press Block IP, Birtikta tells the plugin on the site the attempt came from to block that IP. On Apache servers the IP loses access to the whole site through .htaccess; on other servers it is kept off the login page. The block lasts until you remove it.
What strengthens WordPress IP blocking
Brute force protection
Close the login page and xmlrpc.php entirely, so you do not have to block IPs one by one.
Brute force protectionFailed login alarm
Get the username and IP by email, Slack, WhatsApp or push whenever an attempt fails.
Alarm systemGood to know
IP blocking happens when you click; there is no automatic blocking after a number of failed attempts, and no IP range or country blocking. The block is applied to the site the attempt came from. Country information is for display and search.
Frequently Asked Questions
The Birtikta plugin sends successful and failed WordPress logins on your connected sites to the panel. Each record has the site, username, IP address, country and date. Repeat attempts from the same IP within an hour are counted on the same record.
Press Block IP on the row in the WP Login Entries screen. Birtikta tells the plugin on the site the attempt came from to block that IP.
On Apache servers the IP loses access to the whole site through an .htaccess rule. On other servers it is kept off the login page.
Until you remove it. Use Unblock IP on the same row to lift it at any time.
The server's own IP and localhost cannot be blocked. If you blocked your own IP, just press Unblock IP in the panel; the panel works independently of the site.
No. Blocking is your decision. To close the login page to bots entirely, use Brute Force Protection.