Starter
1 site
BuyPrice
From $39/year — 14-day money-back
The 404-pattern firewall that catches what generic security plugins miss.
Every WordPress site on the public internet gets hit, every single day, by a swarm of automated scanners hunting for forgotten backup files, leaked credentials and known-CVE attack surfaces. They probe paths like /wp-config.php.bak, /.env, /admin.rar, /wp-content/uploads/db.sql — and the second one of those returns a 200, your site is owned.
Your generic security plugin doesn’t see it. Your CDN doesn’t care. Your WAF only flags the obvious. Meanwhile, the bots cycle through millions of paths until something sticks — and you find out three days later, when Google blacklists your domain.
It’s a focused, enterprise-grade firewall built around a single insight: real visitors don’t generate 30 404s in 60 seconds. Bots do. When an IP crosses the threshold you configure, it’s banned at the WordPress bootstrap layer (before any heavy code runs), with a 403 served on every subsequent request — including wp-login.php.
HeadlessChrome, Selenium, Puppeteer, sqlmap, nikto and 30+ scanner signatures — without blocking your own staging tools.192.168.0.0/24 for the office network, 2001:db8::/32 for an IPv6 transit, done.CF-Connecting-IP and X-Forwarded-For when you opt in — and screams in the admin UI when proxy headers are detected but trust is off (a silent misconfiguration that makes most WP firewalls useless).It’s not a 50-MB Swiss-army-knife security plugin with malware scanners, two-factor, login captchas and a cluttered dashboard. It does one thing — stopping bots that abuse 404s — and it does that better than anything else on the market. Use it standalone, or layer it under Wordfence/iThemes for an extra perimeter that doesn’t overlap.
The firewall never stops working when your license lapses. A security plugin that disables itself on payment failure is malpractice. Yours keeps protecting; only the update channel goes silent.
Bans are enforced in the WordPress bootstrap, before themes, page builders or e-commerce code runs. A blocked bot eats less CPU than serving a 404.
Real search-engine crawlers are allow-listed by User-Agent and IP signature. We tested with sites pushing 100k+ Google crawl requests per day. Zero false positives.
Reads through Transients API, writes batched, log queries index-backed. The plugin is invisible on the front-end performance budget.
Three independent guard rails make it physically impossible to ban your own admin IP. Sleep at night.
Privacy-policy text, personal-data exporter and personal-data eraser plug into WP core privacy tools. No third-party data sharing — ever.
If your subscription ends, the firewall keeps working. Only the update channel goes silent. Security is never gated by billing.
Honours CF-Connecting-IP and X-Forwarded-For when you trust them — and warns you in the admin if you forgot to enable trust on a proxied site.
52 PHPUnit tests, WPCS-clean, full PHPDoc, accessible admin UI with ARIA labels, 4 bundled translations and a POT file you can extend.
Honest comparison vs. the most common alternatives WordPress site owners try.
| Feature | [B] 404 Bot Blocker | Other solutions |
|---|---|---|
| Detects bots by 404 patterns (not just User-Agent) | Yes — threshold, window and lockout fully configurable | Mostly UA-based or generic rate-limiting |
| Allow-lists Googlebot & SEO crawlers automatically | Built-in, signed UA fingerprinting | Often requires manual rule tuning |
| CIDR support (IPv4 + IPv6) in whitelist & blocklist | Native, with binary-comparison validation | Single IPs only on most plugins |
| Cloudflare-aware with misconfiguration warning | Detects proxy headers and warns if Trust-Proxy is off | Silently bans the whole CF range or trusts spoofable headers |
| Self-lockout protection | Three independent guard rails | "Lost access? Disable via FTP." 🙃 |
| GDPR / LGPD exporter + eraser | Registered with WP core privacy tooling out of the box | Almost nobody ships this; you have to write it yourself |
| Firewall keeps working on expired license | Always — security is never gated by billing | Many premium security plugins disable rules on lapse |
| Footprint | 27 files, ~280 KB on disk, 0 runtime Composer deps | Suite plugins ship 30–80 MB and load on every request |
| PHPUnit test coverage shipped | 52 tests / 67 assertions, 100% passing | Closed-source binary blob |
Upload the ZIP via Plugins → Add New → Upload, or drop the folder into wp-content/plugins/. Activate. The default settings (threshold 30, window 60s, lockout 1h, retention 30d) are production-ready.
Go to Settings → [B] 404 Security → License, paste the key from your purchase email, click Activate. Updates are now delivered automatically. (The firewall already runs without this step — the license only enables update delivery.)
If your site sits behind Cloudflare, AWS ALB or any reverse proxy, toggle "Trust Proxy Headers" in Settings. The plugin will warn you with a red banner if you forget — better a loud reminder than silently banning your entire CF range.
Watch the Dashboard for a couple of days. If you see legitimate traffic getting flagged, raise the threshold. If bots are slipping through, lower the window. Defaults work for 95% of sites; the other 5% just need a knob nudge.
Logs auto-prune. WP-Cron handles retention. The Block manager is there if you ever need to un-ban a customer who fat-fingered their address bar 30 times. Otherwise, the plugin works in the background, every minute of every day.
Configuration reference, threshold tuning guide, multisite notes and troubleshooting matrix at https://baqueiro.es/store/plugins/b-404-bot-blocker/docs/
Filters and actions for extending threshold logic, customising the 403 response page and integrating with external SIEMs.
52 tests covering CIDR validation, IP-list parsing, IPv6 canonicalisation, comments, CRLF tolerance and CSV-injection sanitisation. Run them yourself: `composer install && vendor/bin/phpunit`.
110 strings extracted, 4 bundled locales (en_US, es_ES, pt_BR, gl_ES). Drop your own .po into /languages/ and you're done.
Direct email line to the developer team — not a tier-1 outsourced helpdesk. 24h response on business days.
Plain-language documentation of exactly which fields are stored, retention windows, exporter/eraser usage and the legal basis under GDPR Art. 6(1)(f) (legitimate interest in network & information security).
Use cases where this plugin delivers the most value.
Stop credit-card stuffing bots before they hit your checkout. Permanent blocklist with CIDR catches entire abusive ASNs in one entry.
High-traffic sites attract scraper armies probing for leaked staging URLs and DB backups. The plugin filters them out without throttling Googlebot.
Agency-tier license covers 25 sites. Identical configuration replicates per-site; the audit log gives you proof of value at every monthly retainer review.
Login pages are honeypots for credential stuffing. The plugin protects wp-login.php with the same 404-pattern logic and refuses to ban your paying members.
Strict scanner detection (sqlmap, nikto, ffuf) without false-positive on legitimate headless tooling. Allow-list your build servers via CIDR and ship.
Run us as a thin perimeter layer in front of your existing security suite. We catch what their generic rate-limiter misses; they catch what we don't claim to do.
87 reviews
There are no approved reviews for this plugin yet.
Reviews are collected by e-mail and published by the team.
Your feedback helps other buyers and can be edited later.
Sign in with the purchasing account to submit your review.
Get started right now with [B] 404 Bot Blocker.
I want to buy now30-day full refund guarantee.