Scanner says core files were modified? Open the diff. After wp2shell, that is often leftover access.

How to read it

Firewall & login

How to blacklist an IP

Easily blacklist IP addresses in WP Security Ninja. Follow these steps to navigate the Firewall tab, add IPs to the blacklist, and enhance your site's security.

How to Manually Blacklist an IP Address with WP Security Ninja

WP Security Ninja lets you manually block specific IP addresses from the Firewall tab. IP rules use one Add IP rule dialog for both blacklist and whitelist entries.

Steps to Blacklist an IP

  1. Go to Security Ninja → Firewall → IP Management.
  2. Click Add IP rule.
  3. Enter one IP address or CIDR range per line.
  4. Optionally add a Note (label for the rule, up to 150 characters). The same note applies to every IP when you add multiple lines at once.
  5. Select the Blacklist radio button.
  6. Click Save.

Add IP rule dialog with Blacklist selected

Any IP you save as Blacklist is denied access according to your firewall settings.

Important Note

If you accidentally enter your own IP address as both blacklist and whitelist, the whitelist takes precedence so you do not lock yourself out.

Blocking IP Ranges

You can also block a range of IPs by entering a subnet mask.

Whitelisting IPs

To allow an IP instead, use the same Add IP rule dialog and select the Whitelist radio button before saving. Whitelisted IPs keep access even when the firewall is active; their traffic may still be monitored.

Add IP rule dialog with Whitelist selected

If bans or logs show the wrong address (for example a Cloudflare edge IP), check Visitor IP detection on Firewall → Settings first.

Still stuck? Get help or contact us.

Larger screenshot

Enlarged image