
Predax Security is a VPN, proxy, Tor and bot blocker for WordPress that doesn’t stop there: a built-in firewall, login-lockout protection, country blocking and spam and disposable-email rejection are all included, switch by switch. It checks every visitor’s IP address as they arrive and turns away the ones you don’t want — before they can log in, register, comment or load a page.
Most attacks on WordPress sites — brute-force logins, fake registrations, comment spam, vulnerability scans — arrive over VPNs, open proxies, Tor or rented servers. Predax spots those connections in real time, gives each IP a 0–100 risk score, and blocks by the rules you choose.
See what Predax knows about your own IP — free, no signup.
Off by default. A fresh install sends nothing anywhere. Pick a protection level in the setup wizard and the plugin starts working; until then it does nothing.
What it blocks
- VPNs, proxies and Tor — anonymised visitors, if you choose to block them
- Datacenter IPs — servers pretending to be people
- Known bad IPs — addresses flagged in a continuously updated threat database
- Countries and regions you don’t serve
- Attack requests — a built-in firewall stops injection, scanner and file-probe attempts
- Brute-force logins — repeated failures are locked out, faster for risky addresses
- Fake signups and spam — disposable email addresses and bot comments are rejected
Every one of these is a switch. Turn on what you need.
Control AI and SEO crawlers
Decide whether GPTBot, ClaudeBot, PerplexityBot or AhrefsBot can access your site. Predax checks each crawler’s real network, not a user-agent header anyone can fake — so a crawler that ignores robots.txt is still turned away. Search engines such as Google and Bing are allowed by default.
Safe for your rankings and your readers
- Verified search engines are never blocked by your VPN, datacenter, country or risk rules, so screening can’t cost you search traffic.
- Wrongly-blocked visitors can tell you. Their report lands in the Threat Log with the full risk detail beside it. Nothing is unblocked until you decide.
- One-click allow-listing from the Threat Log puts a genuine reader back in as fast as they were turned away.
Also included
Security dashboard with live activity and top targeted paths · Threat Log with CSV export · Custom branded block page · IP and CIDR allow/deny lists · XML-RPC and REST API protection · Settings import/export · WP-CLI commands for automation
Free plan
Click Connect with Predax in the setup wizard and your free account and API key are created for you — nothing to copy or paste. The free plan includes 5,000 IP checks a month (1,000 a day) with full VPN, proxy, Tor and datacenter detection. No credit card.
Busier sites can move to a paid plan for a bigger monthly allowance — same plugin, same settings, same key.
Third Party Services
This plugin connects to external services. By installing and activating this plugin you agree to the terms of each service you enable.
Predax API
This plugin transmits visitor IP addresses to the Predax API (https://predax.io) for real-time threat detection and risk scoring.
What is sent: The visitor’s IP address; optionally their timezone (when timezone mismatch detection is enabled and visitor protection is active); and, when disposable-email screening is enabled, the domain part of the email address entered at registration (for example “gmail.com”) — never the email address itself, and never the part before the @. The mailbox-level checks (role account, random-looking name) run locally on your own server.
When it is sent: On each page load, login attempt, registration, or comment submission, subject to your configured protection settings. IP results are cached for up to 1 hour and email-domain results for up to 6 hours, so repeat visits do not generate additional API calls.
Who operates the service: Predax (predax.io)
Terms of Service: https://predax.io/terms
Privacy Policy: https://predax.io/privacy
Email Domain Screening (only when disposable-email screening is enabled)
Used to check whether the email provider entered at registration is a disposable/throwaway service, against a server-side list of thousands of domains (the plugin’s built-in list covers only ~50).
What is sent: the domain part of the registration email address only — for example gmail.com. The email address itself is NEVER sent: the part before the @ does not leave your site, and the mailbox-level checks (role account, random-looking name) run locally in PHP on your own server.
When it is sent: during user registration, and only while the Disposable Email Addresses setting is set to Flag or Block. If the API is unreachable, the plugin falls back to its built-in local list and the registration proceeds normally. Email-domain results are cached for up to 6 hours per domain.
Endpoint: POST https://predax.io/api/v1/validate/email
Plan usage: email-domain lookups count against your Predax plan allowance, the same as IP checks. Results are cached per domain for 6 hours and the built-in list is checked first, so in practice this is roughly one lookup per new email provider your visitors use.
Who operates the service: Predax (predax.io)
Terms of Service: https://predax.io/terms
Privacy Policy: https://predax.io/privacy
Account Usage Lookup (admin pages only)
Used to show the “API Usage” meter on the plugin dashboard, and only when an API key is saved.
What is sent: your Predax API key (as the authentication header). No visitor data is sent.
When it is sent: when an administrator views the Predax Security dashboard. The result is cached for 1 hour, so at most one lookup per hour regardless of admin page views.
Endpoint: GET https://predax.io/api/v1/auth/usage
Privacy Policy: https://predax.io/privacy
Deactivation Feedback (optional, admin-initiated)
Shown only when an administrator deactivates the plugin from the Plugins screen and chooses to answer the “why are you deactivating?” prompt.
What is sent: the plugin slug, the plugin version, and a single pre-defined reason code you select (e.g. “it blocked real visitors”). No site URL, no email address, no visitor data, and no IP address are sent.
When it is sent: only when you select a reason and click “Send & deactivate”. Clicking “Skip & deactivate” sends nothing at all.
Endpoint: POST https://predax.io/api/v1/feedback/deactivation
Privacy Policy: https://predax.io/privacy
Community Threat Network (opt-in, disabled by default)
The Community Threat Network is opt-in and disabled by default. No block or monitor events are sent to the community network unless you enable it yourself in Settings Predax Security Advanced.
When — and only when — you explicitly enable it, anonymised block and monitor events (containing: IP address, action taken, block reason, country code, and risk score) are sent to the Predax API at predax.io. This data is used to build a shared threat database that improves detection accuracy for all sites in the network. You can turn community reporting back off at any time in the same settings screen.
Google reCAPTCHA
When reCAPTCHA v3 is enabled (Settings Protection reCAPTCHA), this plugin loads the reCAPTCHA script from google.com and sends form submission tokens to google.com/recaptcha for verification. Google may collect data according to their privacy policy. You must provide your own reCAPTCHA site key and secret key.
Google Privacy Policy: https://policies.google.com/privacy
reCAPTCHA Terms: https://policies.google.com/terms
Browser Fingerprinting
When browser fingerprint scoring is enabled (Settings Protection Fingerprint Scoring), this plugin collects screen resolution, timezone, platform string, WebGL renderer, and plugin count from the visitor’s browser on the login page. Fingerprint data is used locally to score bot likelihood and is stored in WordPress only while the login form is being submitted, then discarded. The visitor’s timezone may be included in the API request to detect timezone mismatch when that feature is enabled.
Cookies set by this plugin
All cookies set by this plugin are functional service cookies, not tracking cookies, and are only written when the relevant feature is explicitly enabled by the site administrator:
ipsentry_tz— carries the visitor’s browser timezone to the Predax API when timezone-mismatch detection is active. Written fromipsentry-tz.json the front-end. Expires after 24 hours.SameSite=Lax. Only set when an API key is configured AND visitor or login protection is enabled.ips_jsc— JavaScript challenge solve token. Written fromjs-challenge.jswhen a visitor passes the challenge. Expires after 24 hours.SameSite=Lax. Only set when the JavaScript Challenge feature is enabled.
No tracking or advertising cookies are written by this plugin.
By activating this plugin and entering an API key, you agree to the Predax Terms of Service and Privacy Policy. You are responsible for ensuring your use of visitor IP data complies with applicable privacy laws (GDPR, CCPA, etc.) and your own site’s privacy policy.
Screenshots

A Tor visitor blocked before reaching the site: the branded block page every high-risk visitor sees, with the block reason.

Settings page — configure API key, risk threshold, and protection types

Threat log — view all blocked events with IP, reason, risk score, and timestamp

Dashboard widget — at-a-glance threat stats on the WordPress dashboard

Country blocking — select countries and regions to allow or deny

Setup Wizard — pick a protection level (Monitor Only, Recommended, or Strict) in one step

"Predax Protection This Week" — a native WordPress dashboard widget summarizing blocked threats by category

Detection Modes — VPN, proxy, Tor, malicious-IP, and datacenter blocking, each independently switchable

Threat Log with reported access problems — visitors blocked by a category rule can tell you they are genuine; each report shows the risk detail so you can allow the IP in one click, or dismiss it

Crawler Policy — allow verified search engines while deciding separately on AI crawlers (GPTBot, ClaudeBot, PerplexityBot) and SEO crawlers. Enforced by each operator's published IP ranges, not the spoofable user-agent header.