Documentation · Version 1.0

Visitor IP and Cloudflare

Automatic direct/Cloudflare detection and safe custom-proxy configuration.

Free version 1.0.0 is available from the official WordPress.org Plugin Directory. Premium plans and downloads are available from the pricing page.

Automatic mode

Direct traffic uses the immediate connection address. A Cloudflare visitor header is trusted only when the immediate peer belongs to a verified Cloudflare range, which prevents an arbitrary client from spoofing that header.

Custom proxies

  • Use custom mode only for a reverse proxy or CDN not handled automatically
  • Enter only provider-verified proxy CIDRs
  • Never trust every address
  • After host, CDN, or network changes, confirm the detected visitor address before relying on velocity limits

Related resources

How the decision flow works · Compatibility matrix · Support · Public source

Version 1.0.0 · Available on WordPress.org

Put a control between checkout abuse and your payment gateway.

Install the complete Free edition from the official WordPress.org Plugin Directory. New installations begin safely in Observe Mode.