{"id":271057,"date":"2026-01-05T08:24:27","date_gmt":"2026-01-05T08:24:27","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/ipgeolocation-geo-redirects-content-control\/"},"modified":"2026-09-03T06:21:00","modified_gmt":"2026-09-03T06:21:00","slug":"ipgeolocation-geo-redirects-content-control","status":"publish","type":"plugin","link":"https:\/\/scn.wordpress.org\/plugins\/ipgeolocation-geo-redirects-content-control\/","author":23429596,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.2.0","stable_tag":"1.2.0","tested":"7.1","requires":"5.8","requires_php":"7.4","requires_plugins":null,"header_name":"IPGeolocation.io \u2013 Geo Redirects & Content Control","header_author":"IPGeolocation.io","header_description":"Powerful IP-based geolocation plugin for redirects, access control, and conditional content using shortcodes.","assets_banners_color":"f3f2f9","last_updated":"2026-09-03 06:21:00","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/wordpress.org\/plugins\/ipgeolocation-geo-redirects-content-control\/","header_author_uri":"https:\/\/ipgeolocation.io","rating":0,"author_block_rating":0,"active_installs":10,"downloads":610,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"ipgeolocation","date":"2026-01-05 08:23:52","revision":3432526},"1.1.0":{"tag":"1.1.0","author":"ipgeolocation","date":"2026-08-13 09:23:07","revision":3644769},"1.2.0":{"tag":"1.2.0","author":"ipgeolocation","date":"2026-09-03 06:21:00","revision":3679089}},"upgrade_notice":{"1.2.0":"<p>Adds IP address blocking for your site and your login page, and fixes a security problem where a visitor could fake their location using request headers. If your site is behind a CDN or proxy, check the detected address on the settings screen after updating.<\/p>","1.1.0":"<p>This update upgrades the internal API to v3. Existing plan types (Standard, Advanced, Security) will be automatically migrated to Paid Plan. No action required.<\/p>","1.0.0":"<p>Initial release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3434235,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3434235,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3434375,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3434405,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.1.0","1.2.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3432526,"resolution":"1","location":"assets","locale":"","width":1560,"height":908},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3432526,"resolution":"2","location":"assets","locale":"","width":1466,"height":804},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3432526,"resolution":"3","location":"assets","locale":"","width":1543,"height":303},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3432526,"resolution":"4","location":"assets","locale":"","width":1404,"height":533},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3679076,"resolution":"5","location":"assets","locale":"","width":1631,"height":916}},"screenshots":{"1":"Country redirect rules settings","2":"Redirect confirmation popup","3":"Country access control settings","4":"Conditional content shortcodes","5":"IP access control, showing your own address and the two access questions"}},"plugin_section":[],"plugin_tags":[1912,172575,32023,4124,1192],"plugin_category":[49],"plugin_contributors":[253323],"plugin_business_model":[],"class_list":["post-271057","plugin","type-plugin","status-publish","hentry","plugin_tags-access-control","plugin_tags-country-blocking","plugin_tags-geo-redirect","plugin_tags-geolocation","plugin_tags-ip-blocking","plugin_category-maps-and-location","plugin_contributors-ipgeolocation","plugin_committers-ipgeolocation"],"banners":{"banner":"https:\/\/ps.w.org\/ipgeolocation-geo-redirects-content-control\/assets\/banner-772x250.png?rev=3434405","banner_2x":"https:\/\/ps.w.org\/ipgeolocation-geo-redirects-content-control\/assets\/banner-1544x500.png?rev=3434375","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/ipgeolocation-geo-redirects-content-control\/assets\/icon-128x128.png?rev=3434235","icon_2x":"https:\/\/ps.w.org\/ipgeolocation-geo-redirects-content-control\/assets\/icon-256x256.png?rev=3434235","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/ipgeolocation-geo-redirects-content-control\/assets\/screenshot-1.png?rev=3432526","caption":"Country redirect rules settings"},{"src":"https:\/\/ps.w.org\/ipgeolocation-geo-redirects-content-control\/assets\/screenshot-2.png?rev=3432526","caption":"Redirect confirmation popup"},{"src":"https:\/\/ps.w.org\/ipgeolocation-geo-redirects-content-control\/assets\/screenshot-3.png?rev=3432526","caption":"Country access control settings"},{"src":"https:\/\/ps.w.org\/ipgeolocation-geo-redirects-content-control\/assets\/screenshot-4.png?rev=3432526","caption":"Conditional content shortcodes"},{"src":"https:\/\/ps.w.org\/ipgeolocation-geo-redirects-content-control\/assets\/screenshot-5.png?rev=3679076","caption":"IP access control, showing your own address and the two access questions"}],"raw_content":"<!--section=description-->\n<p><strong>IPGeolocation.io \u2013 Geo Redirects &amp; Content Control<\/strong> decides what each visitor sees based on where they are and what IP address they are using.<\/p>\n\n<p>You can send people from one country to a different page, keep unwanted IP addresses away from your site or your login page, and show or hide parts of a page depending on the visitor's location. Everything is set up from one settings screen, and you do not need to write any code.<\/p>\n\n<p>The plugin uses the <strong>ipgeolocation.io API<\/strong> to work out a visitor's country and other details. Results are stored for 24 hours per address, so your site stays fast.<\/p>\n\n<h3>Main Features<\/h3>\n\n<ul>\n<li>Country-based redirects (entire site, specific pages, or URL patterns)<\/li>\n<li>Optional popup confirmation before redirect<\/li>\n<li>IP address blocking, with separate rules for your website and your login page<\/li>\n<li>Address lists that accept single addresses, ranges, wildcards, IPv4 and IPv6<\/li>\n<li>Safe list of addresses that are never blocked by any rule<\/li>\n<li>Protection against locking yourself out, with a recovery option<\/li>\n<li>Country-level access control (allow or block)<\/li>\n<li>Conditional content shortcodes<\/li>\n<li>Output visitor geolocation data via shortcode<\/li>\n<li>Page and query-string exclusions<\/li>\n<li>Redirect bypass and reset via URL parameters<\/li>\n<li>Bot detection (search engines and social crawlers excluded from redirects)<\/li>\n<li>Administrator-safe (admins are never redirected)<\/li>\n<li>IP response caching using WordPress transients<\/li>\n<\/ul>\n\n<h3>Blocking Visitors By IP Address<\/h3>\n\n<p>The IP section asks two questions, and you answer them separately:<\/p>\n\n<ul>\n<li>Who can visit your website<\/li>\n<li>Who can reach your login page<\/li>\n<\/ul>\n\n<p>For each one, you can leave it open to everyone, block a list of addresses, or allow only a list of addresses. Locking the login page to your office address is a simple way to stop password guessing bots, and ordinary visitors are not affected at all.<\/p>\n\n<p>IP rules are checked before any location lookup, so blocking somebody uses none of your API credits.<\/p>\n\n<h3>Configuration<\/h3>\n\n<p>The plugin supports the following API plans from ipgeolocation.io:<\/p>\n\n<ul>\n<li>Developer (Free)<\/li>\n<li>Paid<\/li>\n<\/ul>\n\n<p>Additional security-related features are available for paid plans only.<\/p>\n\n<p>Blocking by IP address does not need an API key. Everything based on country does.<\/p>\n\n<h3>Shortcodes<\/h3>\n\n<h3>Display Single Geolocation Field<\/h3>\n\n<pre><code>[ipgeo country]\n[ipgeo city]\n[ipgeo country_code]\n<\/code><\/pre>\n\n<p>Available fields include:\n    ip, city, state, country, country_code, zipcode, continent, latitude, longitude, currency, calling_code, languages, is_proxy, is_tor, is_anonymous, cloud_provider<\/p>\n\n<h3>Conditional Content (Show If Match)<\/h3>\n\n<pre><code>[ipgeo_if country_code=\"US,CA\" logic=\"OR\"]Visible to visitors from the US or Canada.[\/ipgeo_if]\n<\/code><\/pre>\n\n<p>Supported attributes: country, country_code, state, city, continent, is_proxy, is_tor, is_cloud_provider, is_anonymous, logic (AND \/ OR)<\/p>\n\n<h3>Conditional Content (Hide If Match)<\/h3>\n\n<pre><code>[ipgeo_if_not country=\"Germany\"]Hidden from visitors in Germany.[\/ipgeo_if_not]\n<\/code><\/pre>\n\n<p>Both shortcodes accept the same attributes, so you can hide content from one country just as easily as showing it to another.<\/p>\n\n<h3>Redirect Bypass<\/h3>\n\n<p>For testing or user control, redirects can be bypassed:<\/p>\n\n<ul>\n<li><code>?geo_bypass=1<\/code> bypasses redirects for 30 days<\/li>\n<li><code>?geo_reset=1<\/code> resets the bypass cookie<\/li>\n<\/ul>\n\n<p>This does not affect IP rules.<\/p>\n\n<h3>External Services Used<\/h3>\n\n<p>This plugin connects to two outside services.<\/p>\n\n<p><strong>ipgeolocation.io<\/strong><\/p>\n\n<p>Used to find the country, region, city and security details for a visitor's IP address. This powers country redirects, country access control and the shortcodes.<\/p>\n\n<p>The visitor's IP address and your API key are sent to <code>https:\/\/api.ipgeolocation.io\/v3\/ipgeo<\/code> when a page needs location data. Results are stored for 24 hours per address, so a returning visitor does not cause a second request. Nothing is sent if you have not entered an API key, and nothing is sent for a visitor already blocked by an IP rule.<\/p>\n\n<p>An API key is required. You can get one by creating a free or paid account at <a href=\"https:\/\/ipgeolocation.io\/\">ipgeolocation.io<\/a>. Without it, the country-based features will not work.<\/p>\n\n<p>Terms of service: <a href=\"https:\/\/ipgeolocation.io\/tos.html\">https:\/\/ipgeolocation.io\/tos.html<\/a>\nPrivacy policy: <a href=\"https:\/\/ipgeolocation.io\/privacy.html\">https:\/\/ipgeolocation.io\/privacy.html<\/a><\/p>\n\n<p><strong>Cloudflare<\/strong><\/p>\n\n<p>Used only to keep an up-to-date list of Cloudflare server addresses. The plugin needs this list to tell whether a Cloudflare header can be trusted. Without it, that header could be faked by anyone.<\/p>\n\n<p>Once a day the plugin requests <code>https:\/\/www.cloudflare.com\/ips-v4<\/code> and <code>https:\/\/www.cloudflare.com\/ips-v6<\/code>. No visitor information, site information or personal data is sent. If the request fails, a copy included with the plugin is used instead. This only happens when address detection is set to Automatic or Cloudflare.<\/p>\n\n<p>Terms of service: <a href=\"https:\/\/www.cloudflare.com\/website-terms\/\">https:\/\/www.cloudflare.com\/website-terms\/<\/a>\nPrivacy policy: <a href=\"https:\/\/www.cloudflare.com\/privacypolicy\/\">https:\/\/www.cloudflare.com\/privacypolicy\/<\/a><\/p>\n\n<h3>License<\/h3>\n\n<p>This plugin is licensed under the GPL v2 or later.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin folder to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate the plugin via <strong>Plugins \u2192 Installed Plugins<\/strong>.<\/li>\n<li>Enter your <strong>ipgeolocation.io API key<\/strong> in the plugin settings.<\/li>\n<li>Configure redirect rules, exclusions, country access rules, or IP rules.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20plugin%20redirect%20logged-in%20administrators%3F\"><h3>Does this plugin redirect logged-in administrators?<\/h3><\/dt>\n<dd><p>No. Administrators are automatically excluded from redirects, and by default they are never blocked by IP rules either. You can change that in Advanced settings.<\/p><\/dd>\n<dt id=\"are%20bots%20and%20search%20engines%20redirected%3F\"><h3>Are bots and search engines redirected?<\/h3><\/dt>\n<dd><p>Known bots (Google, Bing, Facebook, X and others) are excluded from country redirects. IP rules do not skip them, because any browser can claim to be a search engine. To exempt a crawler from an IP rule, add its addresses to your safe list.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20cache%20api%20responses%3F\"><h3>Does the plugin cache API responses?<\/h3><\/dt>\n<dd><p>Yes. IP data is cached for 24 hours per IP.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20cloudflare%3F\"><h3>Does it work with Cloudflare?<\/h3><\/dt>\n<dd><p>Yes. Choose the Cloudflare option under Advanced settings. The plugin only trusts Cloudflare's headers when the request genuinely came from a Cloudflare server, so nobody can pretend to be at a different address.<\/p><\/dd>\n<dt id=\"will%20this%20slow%20down%20my%20site%3F\"><h3>Will this slow down my site?<\/h3><\/dt>\n<dd><p>No. API results are cached, and IP rules are a simple local check with no lookup involved.<\/p><\/dd>\n<dt id=\"do%20i%20need%20an%20api%20key%20to%20block%20ip%20addresses%3F\"><h3>Do I need an API key to block IP addresses?<\/h3><\/dt>\n<dd><p>No. Blocking by IP address works without a key. Country features need one.<\/p><\/dd>\n<dt id=\"how%20do%20i%20find%20my%20own%20ip%20address%3F\"><h3>How do I find my own IP address?<\/h3><\/dt>\n<dd><p>The settings screen shows it at the top of the IP section, with a button that adds it to your safe list.<\/p><\/dd>\n<dt id=\"the%20plugin%20shows%20the%20wrong%20ip%20address%20for%20me.%20why%3F\"><h3>The plugin shows the wrong IP address for me. Why?<\/h3><\/dt>\n<dd><p>Your site is probably behind a CDN or proxy, which replaces the address your server sees. Open Advanced settings and choose the option that matches your setup, then check the address again after saving.<\/p><\/dd>\n<dt id=\"i%20locked%20myself%20out%20of%20my%20login%20page.%20how%20do%20i%20get%20back%20in%3F\"><h3>I locked myself out of my login page. How do I get back in?<\/h3><\/dt>\n<dd><p>Add this line to your wp-config.php file, log in, fix the rule, then remove the line:<\/p>\n\n<pre><code>define( 'IPGEO_DISABLE_IP_ACCESS', true );\n<\/code><\/pre>\n\n<p>The plugin normally refuses to save a rule that would lock you out, so this should be rare.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20a%20caching%20plugin%3F\"><h3>Does it work with a caching plugin?<\/h3><\/dt>\n<dd><p>Mostly. Logged-in visitors and uncached requests are handled normally. A page already saved as a cached file may still be served, because that happens before this plugin runs. Exclude any page that must always be checked.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>Added IP access control: block or allow visitors by IP address, with separate rules for your website and your login page<\/li>\n<li>Address lists accept single addresses, ranges such as 203.0.113.0\/24, wildcards such as 192.0.2.*, and IPv6<\/li>\n<li>Added a safe list of addresses that are never blocked by any rule<\/li>\n<li>The settings screen now shows your own IP address and how it was detected<\/li>\n<li>The plugin refuses to save a login rule that would lock you out, with a wp-config.php recovery option<\/li>\n<li>Security: visitor IP addresses can no longer be faked using request headers. If your site is behind a CDN or proxy, choose the matching option under Advanced settings<\/li>\n<li>Fixed an empty redirect URL in Country Access Control causing an endless redirect loop<\/li>\n<li>Fixed blocked visitors being redirected twice<\/li>\n<li>Fixed cached location data not being reused within the same page load<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Upgraded internal API from v2 to v3<\/li>\n<li>Simplified plan types: Developer and Paid Plan only<\/li>\n<li>Standard, Advanced, and Security plans auto-migrated to Paid Plan<\/li>\n<li>Rename the plugin<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial public release<\/li>\n<li>Country redirects with popup support<\/li>\n<li>Country access allow\/block rules<\/li>\n<li>Conditional shortcodes<\/li>\n<li>Bot detection and caching<\/li>\n<\/ul>","raw_excerpt":"Redirect visitors by country, block or allow visitors by IP address, and show different content to people in different countries.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/scn.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/271057","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/scn.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/scn.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/scn.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=271057"}],"author":[{"embeddable":true,"href":"https:\/\/scn.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/ipgeolocation"}],"wp:attachment":[{"href":"https:\/\/scn.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=271057"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/scn.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=271057"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/scn.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=271057"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/scn.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=271057"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/scn.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=271057"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/scn.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=271057"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}