BACK TO DIRECTORY

Gryphon Verified Client IP

by Sly Gryphon

0.0
(0 ratings)

Gryphon Verified Client IP determines the client IP by walking the forwarding chain, only trusting addresses that match your configured proxy networks (by CIDR range). It stops at the first untrusted hop, which is the true client IP. The resolved address replaces REMOTE_ADDR early in the WordPress lifecycle, allowing other plugins to use it.

The component is secure by default and only trusted proxies are traversed; spoofed headers are ignored. Both IPv4 and IPv6 are fully supported, including protocol translation.

Multiple header formats are supported including standard RFC 7239 Forwarded, common X-Forwarded-For, Cloudflare CF-Connecting-IP, or any custom header.

The component includes a diagnostics panel that can be enabled to record incoming requests with full header dumps and algorithm step traces for debugging.

For more detail, see the GitHub project site Gryphon WordPress Verified Client IP.

Compatibility Note

If your server uses Apache mod_remoteip or nginx set_real_ip_from, those modules will pre-resolve REMOTE_ADDR from forwarding headers before PHP runs. Disable the web server module and let this plugin handle IP resolution instead, or let it pre-resolve and use this plugin for any additional proxies not covered by the engine.

Screenshots

Main settings page — enable/disable the plugin, set the forward limit, and configure proto/host processing.

Main settings page — enable/disable the plugin, set the forward limit, and configure proto/host processing.

Scheme detail — configure header name, trusted proxy CIDR ranges, and optional token for a scheme.

Scheme detail — configure header name, trusted proxy CIDR ranges, and optional token for a scheme.

Diagnostics page — list of recorded requests with resolved IP and whether REMOTE_ADDR was changed.

Diagnostics page — list of recorded requests with resolved IP and whether REMOTE_ADDR was changed.

Diagnostics with IPv6 — shows IPv6 addresses and protocol translation.

Diagnostics with IPv6 — shows IPv6 addresses and protocol translation.

Diagnostics detail — full step trace showing each hop evaluated by the algorithm.

Diagnostics detail — full step trace showing each hop evaluated by the algorithm.

Comments page — WordPress comments showing the verified client IP for each commenter.

Comments page — WordPress comments showing the verified client IP for each commenter.

Plugin Details

Active Installs
0
Total Downloads
295
Version
1.2.1
Requires WP
6.4
Requires PHP
8.1
Tested Up To
6.9.7
Added
2026-04-12
Last Updated
2026-04-13 12:27pm GMT

Ratings

5
0
4
0
3
0
2
0
1
0