WordPress 7.1.2: critical core security fix. Update now, then check inactive themes and comments.

Details

Developers

securityninja_social_crawler_user_agents Filter for WordPress

Allow link-preview crawlers (Facebook, LinkedIn, Twitter, Slack, Discord, and more) past Block IP Network using securityninja_social_crawler_user_agents.

Requires WP Security Ninja 5.267 or newer.

What this filter does

When Block IP Network (Global Block Network) is on, some IPs are blocked for every site on that network. Link-preview crawlers (Facebook, LinkedIn, Twitter, and similar) sometimes share those ranges.

This filter controls which User-Agent substrings count as social crawlers. Matching requests are not blocked by Block IP Network, so link previews can still work.

Matching is case-insensitive substring match against the request User-Agent.

Default list

facebookexternalhit, Facebot, LinkedInBot, Twitterbot, Slackbot-LinkExpanding, Discordbot.

Usage examples

Add an extra crawler (for example Pinterest)

add_filter( 'securityninja_social_crawler_user_agents', 'my_social_crawlers' );

function my_social_crawlers( $user_agents ) {
	$user_agents[] = 'Pinterestbot';
	return $user_agents;
}

Remove a default crawler

add_filter( 'securityninja_social_crawler_user_agents', 'my_social_crawlers' );

function my_social_crawlers( $user_agents ) {
	return array_diff( $user_agents, array( 'Discordbot' ) );
}

Disable the bypass

add_filter( 'securityninja_social_crawler_user_agents', '__return_empty_array' );

Important

This filter only affects Block IP Network. Other firewall rules can still block the request (including suspicious-request checks that use user_agent_items). If a User-Agent is on both the social crawler list and the user_agent_items blocklist, the blocklist wins.

Where to add the code

How to include custom code on your website.

Still stuck? Get help or contact us.

Larger screenshot

Enlarged image