Title: ZeroBot Security – Login Protection, Firewall &amp; Bot Blocker
Author: ZeroBot
Published: <strong>ಮೇ 17, 2026</strong>
Last modified: ಅಕ್ಟೋಬರ್ 6, 2026

---

ಪ್ಲಗಿನ್‌ಗಳನ್ನು ಹುಡುಕಿ

![](https://ps.w.org/zerobot-security/assets/banner-772x250.png?rev=3534940)

![](https://ps.w.org/zerobot-security/assets/icon-256x256.png?rev=3534888)

# ZeroBot Security – Login Protection, Firewall & Bot Blocker

 ‍[ZeroBot](https://profiles.wordpress.org/zerobot/) ಮೂಲಕ

[ಡೌನ್ಲೋಡ್](https://downloads.wordpress.org/plugin/zerobot-security.1.1.1.zip)

 * [ವಿವರಗಳು](https://kn.wordpress.org/plugins/zerobot-security/#description)
 * [‍ವಿಮರ್ಶೆಗಳು‍](https://kn.wordpress.org/plugins/zerobot-security/#reviews)
 *  [ಸ್ಥಾಪನೆ](https://kn.wordpress.org/plugins/zerobot-security/#installation)
 * [ಅಭಿವೃದ್ಧಿ](https://kn.wordpress.org/plugins/zerobot-security/#developers)

 [ಬೆಂಬಲ](https://wordpress.org/support/plugin/zerobot-security/)

## ವಿವರಣೆ

ZeroBot Security protects your site from the first minute, with no account and no
setup.
 Activate it and two protections start working inside WordPress itself. Nothing
is sent anywhere.

#### Free, no account needed

 * **Login Brute-Force Guard** — Counts failed logins per IP and locks the IP out
   after 5 attempts
    for 15 minutes (both adjustable). Blocks password-guessing 
   bots on wp-login.php.
 * **XML-RPC Kill Switch** — Shuts down xmlrpc.php, the endpoint bots use to try
   hundreds of
    passwords in one request and to abuse pingbacks. Skipped automatically
   when Jetpack is active, because Jetpack needs it.
 * **Attack counter** — The dashboard shows how many failed logins, lockouts and
   XML-RPC requests
    were stopped over the last 7 days.
 * **Spoof-proof IP detection** — Proxy headers are only trusted from real Cloudflare
   edges and
    local reverse proxies, so attackers cannot fake their IP to dodge 
   a lockout.

#### Network protection (free 7-day trial, then a ZeroBot plan)

Connect the site from the plugin dashboard: enter your email, confirm it, and the
plugin activates
 itself. The trial includes 100 IP checks and needs no credit card.

 * **Site-Wide Firewall** — Switches on automatically when you connect. Every public
   request is
    checked against IPs, VPNs, Tor nodes and datacenters seen attacking
   the ZeroBot network, with optional country rules. If ZeroBot is slow to answer,
   the visitor is let through after 3 seconds.
 * **Browser Fingerprint** — Detects headless browsers, VMs and automation frameworks.
 * **Comment Guard** — Blocks bot comments before they are saved.
 * **REST API Guard** — Screens public REST calls, with configurable exempt routes.
 * **Shared blacklist** — IPs locked out by the login guard are pushed to your ZeroBot
   blacklist
    and blocked on every site you connect.

When a trial or plan ends, network protection pauses and the free protections keep
running.

#### Full Platform Management

 * **Domain Rules** — Create, edit, and delete antibot rules from inside wp-admin.
 * **Whitelist** — IPs, CIDR ranges, and ASNs scoped per service. Bulk import supported.
 * **Blacklist** — Same scoping and bulk import as the whitelist.
 * **Threat Logs** — Filterable, paginated viewer of every traffic event with CSV
   export.
 * **Dashboard** — Live stats, 7-day traffic chart, recent threats, account info.

#### Other Features

 * Cloudflare and reverse-proxy IP detection that cannot be spoofed by visitors
 * Decision cache via WordPress object cache (Redis/Memcached) with transient fallback
 * Fail-open by default — never breaks your site if the API is unreachable
 * Daily license verification via wp-cron
 * WP-admin dashboard widget showing bots/humans (24h)
 * Pure PHP + vanilla JS — no jQuery, no React, no external CDN

### External Services

The free protections (login guard, XML-RPC kill switch) run entirely inside WordPress
and
 contact no external service. The plugin only contacts ZeroBot after the administrator
either submits the “Turn on network protection” form or enters a license key.

**0. ZeroBot account signup (https://zerobot.info/v3/wp/connect)**

 * What it does: Creates a free ZeroBot trial account from inside wp-admin.
 * When it’s called: Only when the administrator types an email, ticks the consent
   box and clicks
    “Start free trial”. While the account waits for email confirmation,
   the open admin page checks every 10 seconds whether it has been confirmed.
 * Data transmitted: The email address entered (it must belong to an administrator
   of the site),
    this site’s domain and home URL, the plugin version and the server’s
   IP address. During signup ZeroBot fetches a one-time confirmation from the site,
   including a keyed hash of that email. ZeroBot then sends an activation email 
   to that address.
 * What it returns: A one-time claim code, then the license key once the email is
   confirmed.
 * Terms & Privacy: https://zerobot.info/terms — https://zerobot.info/policy

**1. ZeroBot API (https://zerobot.info)**

 * What it does: Classifies visitors as human or bot, synchronizes domain rules /
   whitelists /
    blacklists, and returns threat log data for the dashboard.
 * When it’s called: On every public request that one of the enabled protection 
   layers handles
    (Firewall, Page Protection, Login Guard, Comment Guard, REST 
   API Guard). Also called from the admin dashboard for stats, rules, lists, and
   traffic logs. Also called once per day by wp-cron for license verification.
 * Data transmitted: Visitor IP address, user agent, current URL host, site domain,
   and the
    plugin’s license key. No post content, no customer personal data, no
   form submissions.
 * What it returns: A JSON decision object (`is_bot`, `reason`, `risk_score`, optional
   
   captcha_html), plan metadata, and aggregate stats for the dashboard.
 * Terms & Privacy: https://zerobot.info/terms — https://zerobot.info/policy

**2. ZeroBot Fingerprint Collector (https://zerobot.info/fingerprint/index.js)**

 * What it does: Collects client-side browser signals (canvas, WebGL, fonts, behavior)
   to detect
    headless browsers, VMs, and automation frameworks.
 * When it’s loaded: Injected on public pages and the login screen ONLY when the
   administrator
    enables “Browser Fingerprint” in Protection Settings. It is disabled
   by default; the plugin does not load any external JavaScript out of the box.
 * Data transmitted: Browser fingerprint signals and the visitor’s IP address. No
   WordPress
    user data, no cookies, no form data.
 * What it returns: A risk score used to decide whether a visitor should face a 
   soft challenge.
 * Terms & Privacy: https://zerobot.info/terms — https://zerobot.info/policy

**3. FlagCDN (https://flagcdn.com)**

 * What it does: Serves tiny country-flag PNG images for the admin-only traffic 
   log.
 * When it’s loaded: Only inside wp-admin, only when the administrator opens the
   Dashboard or
    Threat Logs page. It is never loaded on the public site. Only 2-
   letter ISO country codes are transmitted as part of the image URL.
 * Data transmitted: The 2-letter country code and standard image-request metadata.
   No visitor
    data, no WordPress data, no cookies.
 * Service homepage: https://flagcdn.com

If you do not wish to transmit any data to ZeroBot, do not connect the site. The
free
 protections keep working without any external connection.

### Privacy

This plugin does not store visitor personal data in your WordPress database beyond
IP
 addresses in the local threat-log table (`wp_zb_threats`, dropped on uninstall).
It does not set any cookies on visitors. Data sent to the ZeroBot service is described
in the External Services section above.

## ಸ್ಥಾಪನೆ

 1. Install from Plugins  Add New (search “ZeroBot Security”), or upload the zip.
 2. Activate the plugin. Login protection and the XML-RPC kill switch are on right 
    away.
 3. Optional: open **ZeroBot  Dashboard** and, under “Turn on network protection”, 
    enter the email
     of an administrator of this site and click “Start free trial” (
    7 days, 100 IP checks, no card). Click the link in the activation email: the site
    connects and the firewall switches on. Already have a ZeroBot license key? Paste
    it under **ZeroBot  License**.
 4. Adjust the layers in **ZeroBot  Protection**.

No account is needed for the free protections.

## FAQ

### Do I need an account?

No. Login brute-force protection and the XML-RPC kill switch work right after activation,
with
 no account and no data leaving your site. An account is only needed for network
protection.

### What happens when my trial ends?

Network protection pauses and the free protections keep running. If you activate
a plan later,
 the plugin notices within a day (or immediately with “Check again”)
and switches it back on.

### I use Cloudflare or another proxy. Will lockouts hit the right IP?

Cloudflare and local reverse proxies (for example nginx in front of Apache) are 
detected
 automatically. Behind another CDN, enable “Trust proxy headers” in Protection
Settings and check “Your detected IP” on the License page.

### I use Jetpack. Is XML-RPC still blocked?

No. Jetpack connects to WordPress.com through XML-RPC, so the kill switch stands
down while
 Jetpack is active. Login protection still runs.

### Will this plugin break my site if the ZeroBot API is down?

No. The default Fail Mode is “Fail Open” — visitors are allowed through silently
and the
 incident is logged to the PHP error log. You can switch to Fail Closed 
in Protection Settings if you prefer strict security.

### How much does it call the ZeroBot API?

Every visitor decision is cached per-IP for 24 hours by default, so repeat visitors
do not
 trigger additional API calls. A page that gets 1,000 hits/hour from returning
visitors typically results in only a handful of API calls.

### Does the fingerprint collector always run?

No. The fingerprint collector is disabled by default and only injects on the public
site
 when the administrator turns on “Browser Fingerprint” under Protection Settings.

### Does it work with WooCommerce?

Yes — the REST API Guard auto-exempts `/wc/store/` routes. Add other custom routes
to the
 exempt list as needed.

### Does it support multisite?

Single-site only for now.

## ‍ವಿಮರ್ಶೆಗಳು‍

ಈ ಪ್ಲಗಿನ್‌ಗೆ ಯಾವುದೇ ವಿಮರ್ಶೆಗಳಿಲ್ಲ.

## ಕೊಡುಗೆದಾರರು & ಡೆವಲಪರ್‌ಗಳು

“ZeroBot Security – Login Protection, Firewall & Bot Blocker” ಓಪನ್ ಸೋರ್ಸ್ ಸಾಫ್ಟ್‌ವೇರ್
ಆಗಿದೆ. ಕೆಳಗಿನ ಜನರು ಈ ಪ್ಲಗಿನ್‌ಗೆ ಕೊಡುಗೆ ನೀಡಿದ್ದಾರೆ.

ಕೊಡುಗೆದಾರರು

 *   [ ZeroBot ](https://profiles.wordpress.org/zerobot/)

[“ZeroBot Security – Login Protection, Firewall & Bot Blocker” ಅನ್ನು ನಿಮ್ಮ ಭಾಷೆಗೆ ಅನುವಾದಿಸಿ.](https://translate.wordpress.org/projects/wp-plugins/zerobot-security)

### ಅಭಿವೃದ್ಧಿಯಲ್ಲಿ ಆಸಕ್ತಿ ಇದೆಯೇ?

[ಕೋಡ್ ಬ್ರೌಸ್ ಮಾಡಿ](https://plugins.trac.wordpress.org/browser/zerobot-security/),
[SVN ರೆಪೊಸಿಟರಿ](https://plugins.svn.wordpress.org/zerobot-security/) ಪರಿಶೀಲಿಸಿ, 
ಅಥವಾ [ಅಭಿವೃದ್ಧಿ ಲಾಗ್](https://plugins.trac.wordpress.org/log/zerobot-security/) 
ಗೆ [RSS](https://plugins.trac.wordpress.org/log/zerobot-security/?limit=100&mode=stop_on_copy&format=rss)
ಚಂದಾದಾರರಾಗಿ.

## Changelog

#### 1.1.1

 * Security: a ZeroBot account can only be created from the plugin with the email
   of an
    administrator of the site. ZeroBot also confirms this with the site during
   signup.

#### 1.1.0

 * New: free protection without an account. The Login Brute-Force Guard and the 
   XML-RPC kill
    switch now run as soon as the plugin is active. Previously every
   protection waited for a license key, so new installs protected nothing.
 * New: create a ZeroBot trial account from inside wp-admin. Enter an email, confirm
   it, and
    the plugin activates itself. Pasting an existing license key still works.
 * New: free dashboard with 7-day counts of failed logins, lockouts and blocked 
   XML-RPC requests.
 * New: when a plan or trial ends, network protection pauses with a clear notice
   and the free
    layer keeps running. A daily check re-enables it automatically 
   after renewal.
 * Security: visitor IP detection no longer trusts proxy headers sent by the visitor.
   
   CF-Connecting-IP is only accepted from Cloudflare edges, and X-Real-IP / X-Forwarded-
   For only from local reverse proxies or when “Trust proxy headers” is enabled.
   Forged headers could previously bypass the login lockout or lock out someone 
   else’s IP. The old default of trusting all proxy headers is switched off on update.
 * Fix: a temporary API outage during the daily license check no longer switches
   network
    protection off until the next day.
 * Fix: the XML-RPC kill switch stands down while Jetpack is active.
 * Fix: a visitor flagged as a bot was kept blocked for 24 hours, even after being
   whitelisted.
    Bot verdicts are now cached for 15 minutes, and whitelisting an
   IP from the plugin applies immediately.
 * Change: the Site-Wide Firewall is on by default and switches on whenever a site
   is connected.
 * Change: without a valid license, the network layers (firewall, browser fingerprint,
   comment
    and REST API guards, shared blacklist) are shown off and cannot be switched
   on.
 * Fix: the firewall now gives up after 3 seconds with no retries if the API is 
   slow (it could
    previously hold a page for up to 24 seconds before failing open).
 * Fix: when the trial checks are used up or the plan ends, the firewall pauses 
   its API calls for
    an hour instead of calling on every page view, and the dashboard
   explains why.
 * Fix: the master protection switch is on for new installs. On update it is turned
   on only
    for sites that never saved the settings page.
 * Tested with WordPress 7.1.

#### 1.0.17

 * New: searchable multi-country picker on the Protection Settings page.
    Replaces
   the plain-text “Allowed Countries” input with a chip-based UI that lists all 
   249 ISO countries with flag emoji, alphabetical search, and a clear “Allow all/
   Only specific” mode toggle.
 * Fix: visitors blocked by country policy now correctly show a yellow
    “Denied”
   badge on the Dashboard’s Recent Activity widget. They were previously stacked
   into the red “Bot” bucket even though the block reason was “Country Denied (XX)”.
 * Fix: country flags now render in both the Dashboard widget and the
    Threat Logs
   table. The flag helper expects a 2-letter ISO code, but the API ships the country
   as a name — so flags silently failed for every row. A new `Helpers::countryNameToCode()`
   lookup resolves names to codes, and the flag image renders before the country
   name on every log row.
 * Change: removed the Score column from the Dashboard Recent Activity
    widget and
   the Threat Logs table. The Reason already explains why a request was flagged,
   and the numeric score added visual noise without decision-relevant information.
 * Security: tightened the firewall verdict cache to bot-only. Clean
    verdicts are
   no longer cached, so an IP that turns malicious mid-cache doesn’t keep passing
   through for up to 24 hours. Bot verdicts continue to be cached for instant re-
   blocking.
 * Compliance: `$_SERVER['REQUEST_URI']` in `XmlRpcGuard::register()` is
    now run
   through `wp_unslash()` and `sanitize_text_field()` before the regex match, clearing
   the two PHPCS warnings about that variable.

#### 1.0.16

 * Fix: critical error on every wp-admin page caused by a missing
    License::isDomainAuthorized()
   method that the `admin_notices` hook called. The method now exists on the License
   class, fails open when no authorization state has been recorded yet, and gets
   set true/false by activate() based on whether the auto domain-registration call
   to the ZeroBot platform succeeded (HTTP 200) or reported the domain as already
   registered (HTTP 409).

#### 1.0.15

 * WordPress.org review compliance: removed the broken `flagpedia.net/privacy`
    
   URL from the External Services section of readme.txt.
 * The chart-data bootstrap on the admin dashboard now ships via
    wp_add_inline_script()
   attached to the existing `zerobot-security-admin` handle, instead of an inline`
   <script>` tag. No behavioural change — the same JS payload is delivered through
   the official WordPress enqueue API.

#### 1.0.14

 * WordPress.org review compliance: replaced the short “zb_” prefix everywhere
    
   it appeared in PHP and JS (AJAX action names, option keys, transient keys, nonce
   names, cron hooks, JS globals, custom DB table names, WP_Error codes, and the
   admin script handle) with the full “zerobot_security_” prefix so every plugin-
   defined identifier is at least the WP.org-required 4 characters and is uniquely
   namespaced.
 * No functional or UI changes — the rename is purely cosmetic (CSS class
    names
   beginning with “zb-” are stylesheet-internal and were left unchanged, since they
   don’t conflict with WordPress core or other plugins).

#### 1.0.12

 * Second Plugin Check compliance pass: final 3 errors resolved (wrap
    countryFlagImg()
   output in wp_kses(); add translators comment for “Cleared %d cached decisions”;
   etc.). Input-sanitization warnings addressed across Helpers, Firewall, ProtectionSettings,
   LicensePage.
 * Fingerprint script now passes the plugin version to wp_enqueue_script()
    for 
   reliable cache-busting.
 * Uninstall variables renamed to zerobot_security_* prefix.

#### 1.0.11

 * Full Plugin Check compliance pass: wrap every Helpers::icon() SVG output
    through
   wp_kses() with a tight SVG tag allowlist; add wp_unslash() + sanitize calls on
   every $_SERVER / $\_POST / $\_GET read; gate error\_log() behind WP\_DEBUG; replace
   date() with gmdate(); rename plugin constants to ZEROBOT\_SECURITY* prefix; drop
   load\_plugin\_textdomain (WP 4.6+ auto-loads translations); add translators comments
   for all placeholders; LoginGuard queries use esc\_sql() for the table identifier;
   uninstall uses prefixed variables and prepared statements.
 * Fingerprint script now enqueued via `wp_enqueue_script()` with a
    script_loader_tag
   filter for the data attributes, replacing the raw echo ”. Respects standard WordPress
   script filters.
 * DecisionCache::flush() no longer issues a raw LIKE query — iterates the
    matching
   transient option names and calls `delete_transient()` for each, so the object
   cache and transient DB stay in sync.
 * Threat Logs are now always scoped to the current WordPress site’s host (the
    “
   Domain” filter is removed — it’s redundant and could leak cross-domain data).
 * Firewall self-heals domain-deauthorization in real time: the plugin flags the
   
   site immediately on the first failed API call instead of waiting for the daily
   verify cron, so the warning banner shows up right after the admin removes the
   domain from authorized_domains.
 * Admin warning banner is now shown on every wp-admin page, not only the
    plugin’s
   own screens.
 * Country flags in the Dashboard and Threat Logs render as reliable PNG
    images(
   via flagcdn.com) instead of Unicode emoji, which some platforms don’t render.

#### 1.0.9

 * Per-IP decision cache extended to 24 hours to reduce API load
 * Allowed-countries enforcement moved server-side so denied requests are logged
   correctly
 * Login verification (device 2FA) toggle added per user

#### 1.0.8

 * Browser Fingerprint layer now also injects on wp-login.php and via wp_footer 
   fallback
 * Fingerprint collector no longer skipped for logged-in users (configurable)

#### 1.0.7

 * “Country Denied” badge styled distinctly from generic bot block
 * Threat Logs show the visitor path alongside IP / ISP / country

#### 1.0.6

 * /v3/openapi now receives allowed_countries from the plugin so geo-blocks are 
   enforced
    server-side and logged with the correct reason

#### 1.0.5

 * Decision caching logic refactored so every request logs correctly
 * Fingerprint injection improvements

#### 1.0.3 – 1.0.4

 * “Clear Threats for this Domain” action in Threat Logs
 * “Path” column in Threat Logs showing the URL the visitor accessed

#### 1.0.0

 * Initial release
 * Full Dashboard, License, Rules, Whitelist, Blacklist, Protection Settings, Threat
   Logs
 * Six protection layers: Page, Firewall, Login, Comment, REST API, XML-RPC
 * Decision caching with object cache + transient fallback
 * CSV export for threat logs
 * WP-admin dashboard widget
 * Cloudflare / proxy IP detection

## ಮೆಟಾ

 *  Version **1.1.1**
 *  ಕೊನೆಯದಾಗಿ ನವೀಕರಿಸಿದ್ದು **2 ದಿನಗಳು ರ ಮುನ್ನ**
 *  ಸಕ್ರಿಯ ಸ್ಥಾಪನೆಗಳು **10 ಕ್ಕಿಂತ ಕಡಿಮೆ**
 *  ವರ್ಡ್ಪ್ರೆಸ್ ಆವೃತ್ತಿ ** 5.8 ಅಥವಾ ಹೆಚ್ಚಿನದು **
 *  **7.1.3** ವರೆಗೆ ಪರೀಕ್ಷಿಸಲಾಗಿದೆ
 *  PHP ಆವೃತ್ತಿ ** 7.4 ಅಥವಾ ಹೆಚ್ಚಿನದು **
 *  Language
 * [English (US)](https://wordpress.org/plugins/zerobot-security/)
 * ಟ್ಯಾಗ್‌ಗಳು
 * [antibot](https://kn.wordpress.org/plugins/tags/antibot/)[Brute Force](https://kn.wordpress.org/plugins/tags/brute-force/)
   [firewall](https://kn.wordpress.org/plugins/tags/firewall/)[login security](https://kn.wordpress.org/plugins/tags/login-security/)
   [security](https://kn.wordpress.org/plugins/tags/security/)
 *  [ಸುಧಾರಿತ ನೋಟ](https://kn.wordpress.org/plugins/zerobot-security/advanced/)

## ರೇಟಿಂಗ್‌ಗಳು

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/zerobot-security/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/zerobot-security/reviews/)

## ಕೊಡುಗೆದಾರರು

 *   [ ZeroBot ](https://profiles.wordpress.org/zerobot/)

## ಬೆಂಬಲ

ಹೇಳಲು ಏನಾದರೂ ಸಿಕ್ಕಿದೆಯೇ? ಸಹಾಯ ಬೇಕೇ?

 [ಬೆಂಬಲ ವೇದಿಕೆಯನ್ನು ವೀಕ್ಷಿಸಿ](https://wordpress.org/support/plugin/zerobot-security/)