Firewall & login

404 Guard

Block IPs that generate too many 404 errors. Configure threshold, time window, and block duration in Security Ninja Pro.

404 Guard (Pro) watches for IPs that request many missing pages. When an IP exceeds your threshold inside the time window, Security Ninja blocks it for a set duration. That cuts scanners probing for weak plugins and themes without slowing normal visitors.

404 Guard runs as part of Cloud Firewall. The Cloud Firewall master switch must be on for it to enforce blocks. Settings live under Security Ninja → Firewall → 404 Guard.

404 Guard current status panel

How it works

  1. Each 404 from an IP increments a short-lived counter for that IP.
  2. When the count reaches your 404 Error Threshold inside the Time Window, the IP is banned for the Block Duration.
  3. Known search engines and validated crawlers are allowed through. Manual whitelist rules are respected.
  4. Block and warning events are written to the Events Logger.

Logging starts from the second 404 onward for an IP, so a single mistyped URL does not fill the log.

Settings

SettingDefaultRange
Enable 404 GuardOnOn / Off
404 Error Threshold105 to 50
Time Window (seconds)300 (5 minutes)60 to 3600
Block Duration (seconds)600 (10 minutes)300 to 86400

Recommended starting point: threshold 10 to 20, window 300, block 600.

404 Guard threshold, window, and block duration fields

Safety notes

  • Blocks expire automatically. They are not permanent bans.
  • Your firewall whitelist is not overridden.
  • If a real visitor is blocked after hitting many broken links, raise the threshold or whitelist their IP.
  • Review activity under Security Ninja → Events.

Video walkthrough

See how 404 Guard blocks scanners that flood WordPress with 404 errors.

Still stuck? Get help or contact us.

Larger screenshot

Enlarged image