5,233 GPL Products · Updated DailyPRO Versions Available · Instant Download
Country Access Control by CodeCaste 1.0.1 – WordPress Plugin

Country Access Control by CodeCaste

v1.0.1 Updated 3 days ago Live Demo ↗
Download Country Access Control by CodeCaste 1.0.1
Free download · version 1.0.1

Description

At a glance

Country Access Control by CodeCaste v1.0.1 — free WordPress plugin download. Key facts: updated September 29, 2026 · requires WordPress 5.8+ & PHP 7.4+.

The issue we kept running into

On client sites, “block visitors from these countries” sounds simple — until you look at how most tools do it. Many geolocation plugins phone home on every request, or they lean on a third-party lookup API. That means extra latency, another service in the critical path, and a privacy story that is harder to explain to a client.

We also saw the other failure mode: the rule looks correct in settings, but a full-page cache (LiteSpeed, WP Rocket, Cloudflare HTML cache, host caching) keeps serving a previously allowed page to someone who should be blocked — or the reverse.

What we think about it

Country access control has to be local-first. The decision for a visitor should happen on your server, against data you control, without a round trip to an external API on every page view.

And because the response depends on who is visiting, page caching cannot treat every visitor as if they got the same HTML. If your cache layer ignores that, geo rules will look broken even when the plugin logic is fine.

Why we built this

Country Access Control (the product we also call Geo Lockdown) is our answer for WordPress shops that need country allow/block rules without shipping visitor IPs to a lookup API at runtime.

Lookups run against IP range data stored in your site’s MySQL/MariaDB tables. You choose when to refresh that data. Admin, login, and common WordPress endpoints stay reachable so you do not lock yourself out while testing.

What you get

  • Allow-list or block-list country modes with a searchable country selector
  • Local IPv4 and IPv6 IP-to-country lookups (no external API call while enforcing)
  • MySQL/MariaDB storage — no PHP SQLite3 extension required
  • Administrator bypass to help prevent lockouts
  • Automatic bypass for wp-admin, wp-login.php, REST API, AJAX, WP-Cron, and XML-RPC
  • Verified Googlebot bypass using reverse DNS and forward confirmation (User-Agent alone never bypasses)
  • Configurable trusted proxy / CDN headers, with Cloudflare connecting-IP validation against official Cloudflare ranges
  • Custom blocked message (403) or redirect to a URL you choose
  • Optional blocked-request logging
  • IP lookup cache with configurable TTL, plus a one-click Clear Lookup Cache action
  • Diagnostics panel and a Test IP tool so you can see what the plugin decides before you go live
  • Optional one-click download of the free DB-IP Country Lite dataset, imported through staging tables and an atomic swap

How to use it

  1. Install and activate the plugin.
  2. Go to Settings Country Access Control.
  3. Open the Diagnostics panel and confirm the detected IP looks right (especially if you use Cloudflare or another proxy).
  4. Click Download Latest Database so you are not relying on the limited starter dataset in production.
  5. Choose Allow or Block mode, select the countries, set the blocked response, then enable Country Access Control.
  6. Save settings, then purge your site/page cache (see below) and test from a real visitor perspective — private/incognito while logged out is the easiest check.

Things to take care of (please read this)

1. Download a full GeoIP database before you trust the results

The plugin ships with a small starter dataset so it activates cleanly. That is enough to explore settings — not enough for production accuracy. Use Download Latest Database under the GeoIP Database panel. Nothing about your site or visitors is sent; only the public CSV file is fetched when an administrator clicks the button.

2. Page caching and CDNs

When Country Access Control is enabled, the plugin marks front-end responses as non-cacheable for common cache plugins (including LiteSpeed Cache, WP Rocket, and WP Super Cache style APIs) and purges those caches when you save settings.

That still does not cover every stack. If your host, CDN, or another plugin caches full HTML at the edge, you can get stale allow/block decisions until that cache is cleared or told not to cache HTML for the public site.

After you enable the plugin or change countries / response settings:

  • Purge the page cache in LiteSpeed, WP Rocket, W3 Total Cache, WP Super Cache, SiteGround Optimizer, or whatever you use
  • If Cloudflare (or another CDN) caches HTML, purge that cache too — or exclude the public HTML pages from cache while geo rules are active
  • Use Clear Lookup Cache in the plugin sidebar if you just updated the GeoIP database and want fresh lookups immediately

If rules still look wrong after a purge, open Diagnostics, run a Test IP, and confirm the detected IP / country before digging into theme or security-plugin conflicts.

3. Proxies, Cloudflare, and real visitor IPs

If the site sits behind Cloudflare or another reverse proxy, enable Cloudflare support and/or configure trusted proxies and the correct connecting-IP header. Otherwise the plugin may see the proxy IP instead of the visitor, and country decisions will be wrong.

4. Do not test blocks while logged in as an administrator

Administrator bypass is on by default (and wp-admin / wp-login are always bypassed). Turn administrator bypass off only while testing, and use a private window while logged out.

5. Honest limitation

This is IP-to-country mapping, not a GPS check. VPNs, proxies, Tor, and similar tools can present an IP from another country. No IP-only system can guarantee a person’s physical location.

External services

This plugin can optionally connect to one external service, DB-IP (db-ip.com), solely to let you download an updated GeoIP dataset.

What it is and what it’s used for: DB-IP publishes a free, monthly-updated “IP to Country Lite” CSV database under a Creative Commons Attribution 4.0 license. When you click Download Latest Database under Settings Country Access Control, the plugin fetches that public CSV.GZ file directly from https://download.db-ip.com/ and imports it into your site’s own database. Country lookups for your visitors always run locally afterward — DB-IP is never contacted while your site is actually enforcing geo-restrictions, only when an administrator explicitly requests a database update.

What data is sent: Nothing about your site, its visitors, or their IP addresses is sent to DB-IP. The request is a plain HTTP GET for a public, static file; no query parameters, cookies, or identifying data are included.

When it’s used: Only when an administrator manually clicks “Download Latest Database.” It never runs automatically, on a schedule, or in the background.

Service links: db-ip.com · Free Lite database & license terms

Frequently asked questions

What do I get when I download Country Access Control by CodeCaste?

Country Access Control by CodeCaste 1.0.1 is the latest version. It is a WordPress plugin you can download here free of charge under the GPL license, with the complete feature set included and no trial limitations.

Does Country Access Control by CodeCaste cost anything?

No. Country Access Control by CodeCaste 1.0.1 is 100% free — the full GPL version, not a trial or demo. There are no download limits, no accounts to create, and no upsells during the download.

How do I install Country Access Control by CodeCaste 1.0.1?

Download the ZIP file from this page, then in your WordPress dashboard go to Plugins → Add New → Upload Plugin, choose the file, click Install Now, then Activate. The plugin works immediately after activation — no license key or extra setup is required for the core features.

What are the requirements for Country Access Control by CodeCaste?

Country Access Control by CodeCaste 1.0.1 requires WordPress 5.8 or higher and PHP 7.4 or higher. Most modern WordPress hosts already meet these versions. Running older versions may cause features to break, so update WordPress and PHP first if your site is behind.

When was Country Access Control by CodeCaste last updated?

Version 1.0.1 was last updated on September 29, 2026. This page is refreshed automatically, so the download here always matches the newest version we have verified.

Is the Country Access Control by CodeCaste download safe?

The file is sourced directly from the official WordPress.org repository — the same file the developer published. It is served unmodified, so what you install here is byte-identical to the official release.

Version: 1.0.1
Updated: October 1, 2026

Technical details

Version1.0.1
Last updatedSeptember 29, 2026
Requires WordPress5.8 or higher
Requires PHP7.4 or higher
AuthorCodeCaste
Tagsaccess-control, country, geo-blocking, geolocation, security
Demo Country Access Control by CodeCaste

Download Country Access Control by CodeCaste

Download Country Access Control by CodeCaste WP Plugin

Official Page ↗

Note: if the download does not start, disable your ad blocker and try again.

Leave a Comment