What the list represents
Each row is one IP address with active strike data, not one request. The count is the number of confirmed suspicious document visits still inside the reset window. A blocked label means the count has reached the configured limit.
Toolbar actions
| Action | Result |
|---|---|
| Refresh Data | Reloads the current registry and active transient records. |
| Clear All Strikes | Removes every active strike record. Export first when the information may be needed. |
| Export Data | Downloads the current strike dataset for review or retention outside WordPress. |
| Search | Filters displayed records by address or browser identification. |
Manual IP Management
| Action | When to use it |
|---|---|
| Block IP | Immediately sets the address to the configured threshold. Use when evidence is clear and waiting for more strikes is unnecessary. |
| Add Strike | Adds one administrator-created strike while preserving progressive enforcement. |
| Whitelist IP | Adds trusted access. Choose permanent or temporary duration and record a reason. |
| Clear | Removes that address’s active strike record and restores access unless another module independently blocks it. |
Reasons and audit history
Enter a concise reason such as “Confirmed customer office,” “Internal load test,” or “Repeated credential scanner.” Manual actions are retained in the administrator action history so another administrator can understand why the decision was made.
Example: accidental customer blockReview the Activity Log first. Clear the active strikes to restore access. If the customer uses a stable business address and the traffic is known to be legitimate, add a temporary whitelist entry and monitor before making it permanent.
Relationships with other modules
- Clearing strikes does not delete Activity Logs.
- Clearing Activity Logs does not clear strikes.
- A main IP whitelist bypasses Bot Guard even if the strike row remains.
- Rate Limiting and Geographic Analysis can apply their own actions independently of the strike count.