Title: SecondGate
Author: SecondGateWP
Published: <strong>Awst 23, 2026</strong>
Last modified: Hydref 7, 2026

---

Search plugins

![](https://ps.w.org/secondgate/assets/banner-772x250.png?rev=3661828)

![](https://ps.w.org/secondgate/assets/icon-256x256.png?rev=3661828)

# SecondGate

 Gan [SecondGateWP](https://profiles.wordpress.org/secondgatewp/)

[Llwytho i lawr](https://downloads.wordpress.org/plugin/secondgate.1.1.9.zip)

 * [Details](https://cy.wordpress.org/plugins/secondgate/#description)
 * [Reviews](https://cy.wordpress.org/plugins/secondgate/#reviews)
 *  [Installation](https://cy.wordpress.org/plugins/secondgate/#installation)
 * [Development](https://cy.wordpress.org/plugins/secondgate/#developers)

 [Cefnogaeth](https://wordpress.org/support/plugin/secondgate/)

## Disgrifiad

This plugin’s free tier is permanent: passkeys, 2FA, brute-force protection, and
country blocking are all included, with no artificial limitation and no time-limited
trial.

#### At a glance

 * Passkeys (WebAuthn): Face ID, Touch ID, Windows Hello, or a hardware key, bound
   to your exact domain so it can’t be phished
 * Standard TOTP two-factor authentication: works with Google Authenticator, Authy,
   1Password, Bitwarden, and any other standard authenticator app
 * Trusted devices: skip the 2FA prompt on a recognised device for 30 days, one 
   click to forget it
 * Brute-force login protection: automatic IP and username lockout after repeated
   failed attempts, never locking out the real account owner
 * Country blocking: blacklist or whitelist, 166 countries, IPv4 + IPv6, matched
   locally against downloaded range data, no third-party lookup at request time
 * Verified crawler exemption: Googlebot, Bingbot, and other real search crawlers
   are automatically exempt from every block, confirmed via reverse+forward DNS 
   rather than a fakeable user-agent string, so a blocking rule doesn’t accidentally
   catch a genuine crawler

#### Why it works differently under the hood

Every check runs locally, on your own server. No API keys, no third-party accounts,
no telemetry sent anywhere. Country IP range data is downloaded once a day from 
public sources and matched against visitors entirely on your own site. Nothing about
your traffic is ever sent to us or anyone else.

Two-factor authentication is generated and verified entirely on your own server 
too. TOTP codes and passkey credentials never leave your site.

#### The one thing worth knowing about crawler verification

Blocking traffic by country is only safe if it can’t accidentally catch Google. 
Most plugins check this by trusting whatever a visitor’s browser claims to be, but
any visitor can set their User-Agent to say “Googlebot,” which means that check 
can be bypassed by anyone, and doesn’t actually protect your SEO the way it looks
like it does.

This plugin verifies real crawlers properly instead: a reverse-DNS lookup on the
connecting IP, confirming the hostname belongs to the crawler’s real network, then
a forward-DNS lookup confirming that hostname resolves back to the same IP. That’s
the method Google’s own documentation recommends for verifying a crawler is genuine,
not a name anyone could fake.

### External Services

This plugin connects to the external sources below. None needs an account or API
key.

**GitHub** (raw.githubusercontent.com): for downloading country IP range data used
by country blocking. A plain GET request for a static public file, fetched once 
daily and matched locally afterward. No data about your site or its visitors is 
sent as part of this request.

**DNS lookups**: when a visitor’s browser claims to be a known search crawler (Googlebot,
Bingbot, etc.) and would otherwise be blocked, this plugin performs a standard reverse
+forward DNS lookup on that visitor’s IP, using your server’s normal DNS resolver,
to verify the claim is real before exempting it from blocking. This is the same 
kind of lookup any web server does routinely; no data about your site or its visitors
is sent anywhere as part of it.

**Team Cymru IP-to-ASN DNS service** (origin.asn.cymru.com): for crawlers that are
verified by network rather than by hostname (currently Meta’s link-preview crawler,
facebookexternalhit), the plugin makes a DNS query to Team Cymru’s public service
to confirm the IP belongs to Meta’s network. The only thing included is the crawler’s
IP address; nothing about your site or you as the site owner is sent. This only 
happens when a visitor claims to be that crawler and would otherwise be blocked.
Terms: https://www.team-cymru.com/ip-asn-mapping

Two-factor authentication makes **no external service calls whatsoever**. TOTP codes
and passkey verification happen entirely on your own server.

GitHub’s terms: https://docs.github.com/en/site-policy/github-terms/github-terms-
of-service

## Gosod

 1. Upload the plugin files to `/wp-content/plugins/secondgate`, or install directly
    through the WordPress plugins screen.
 2. Activate the plugin through the ‘Plugins’ screen in WordPress.
 3. Go to Settings  IP Block to configure country blocking, and Settings  2FA & Login
    Security for two-factor authentication settings.
 4. Each user sets up their own 2FA/passkey individually from their own profile page(
    Users  your name  Two-Factor Authentication).

## Cwestiynau Cyffredin

### Does blocking work with page caching plugins?

Yes, if you turn on “Cache-proof blocking” (Settings, IP Block, Advanced). Without
it, SecondGate switches page caching off while any blocking is active, because a
cache would otherwise hand blocked visitors a saved copy. With it, a small gate 
runs before WordPress and before your cache, so blocked visitors are refused and
everyone else still gets the cached page. It adds two lines to wp-config.php, a 
few to .htaccess (site root and wp-content/cache) and a folder at wp-content/secondgate-
gate/, tests every change with a live request, and removes everything when switched
off or uninstalled. LiteSpeed, Varnish and Nginx server caches are supported too(
LiteSpeed automatically; Varnish/Nginx with a config snippet the plugin generates).
Page caching done on someone else’s servers (Cloudflare “Cache Everything”, or a
managed host’s own cache) answers before your site is involved, so no plugin can
gate it: the settings panel tells you if it detects one.

### Is this actually free, or is there a premium version?

The features listed above are free, permanently, with no artificial limitation. 
A separate paid product, SecondGate Pro, exists as its own standalone plugin sold
independently. It is never required for this plugin to work, and nothing in this
plugin is disabled, nagged, or time-limited to push you toward it.

### Does this need an API key or account, for anything?

No. Nothing in this plugin requires an account, an API key, or any third-party sign-
up.

### Is my server behind Cloudflare or a load balancer, will blocking still work correctly?

By default this plugin only trusts your server’s real connecting IP address (REMOTE_ADDR),
which a visitor cannot forge. If you’re behind a proxy or CDN that rewrites the 
visitor’s real IP into a header, you can explicitly enable and select that header
in Advanced settings. It’s off by default, since trusting the wrong header by default
is a well-documented vulnerability class in software that does IP-based blocking.

Even when enabled, the header is only believed on requests that actually arrive 
from your proxy. For Cloudflare this is automatic (Cloudflare’s published IP ranges
are built in), so someone connecting straight to your server can’t fake their location.
For other proxies you can list your proxy’s addresses; addresses on your private
network are always accepted. X-Forwarded-For is read from the right-hand end, the
part your own proxy added, so a visitor can’t slip a fake address in at the start.
The settings page shows whether the page you’re looking at came through a trusted
proxy.

### Will this affect SEO?

No. Blocking only affects visitors from blocked sources viewing the site. Real search
crawlers (Googlebot, Bingbot, and others) are automatically exempt from every blocking
mechanism in this plugin, verified via reverse+forward DNS rather than trusting 
a user-agent string that anyone could fake, so a country rule that would normally
apply is designed not to catch a genuine crawler.

### What if I lose my phone and can’t get a 2FA code?

Use one of the backup codes generated when you first set up two-factor authentication,
then set up 2FA again on your new device.

### Is this a full security firewall, like Wordfence or Sucuri?

No. This plugin covers authentication (passkeys, 2FA, brute-force protection) and
geo-blocking. It is not a web application firewall and does not scan for malware.

### Does this work with WordPress Multisite?

The optional cache-proof blocking supports Multisite: only network admins can switch
it on, and each site keeps its own blocking rules. The rest of the plugin is built
and tested against standard single-site WordPress installs and hasn’t been fully
tested on Multisite yet.

## Adolygiadau

There are no reviews for this plugin.

## Contributors & Developers

“SecondGate” is open source software. The following people have contributed to this
plugin.

Cyfranwyr

 *   [ SecondGateWP ](https://profiles.wordpress.org/secondgatewp/)

[Translate “SecondGate” into your language.](https://translate.wordpress.org/projects/wp-plugins/secondgate)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/secondgate/), check
out the [SVN repository](https://plugins.svn.wordpress.org/secondgate/), or subscribe
to the [development log](https://plugins.trac.wordpress.org/log/secondgate/) by 
[RSS](https://plugins.trac.wordpress.org/log/secondgate/?limit=100&mode=stop_on_copy&format=rss).

## Cofnod Newid

Every entry below is a real, dated, one-line summary. The full detail for each, 
exactly what was found, how it was confirmed, and what testing backs it, lives on
Pro’s security testing methodology page (this plugin shares real, tested code with
Pro, and most fixes here are direct ports of the same real bugs found and fixed 
there), which has no length limit and is the authoritative record.

#### 1.1.9

New, optional: cache-proof blocking (the SecondGate Gate). Until now, turning on
any blocking switched page caching off for the whole site, because a cache answers
before WordPress runs. The gate is one small file loaded from wp-config.php (which
WordPress reads before any cache plugin, on every host; .user.ini/php_value only
as a fallback), plus an .htaccess guard that routes cache files Apache would serve
directly through it first, including inside cache folders that carry their own rewrite
rules. Countries and the allow/deny lists are compiled into merged binary tables
searched without WordPress or a database (about 22 microseconds per visitor). Server-
level caches (LiteSpeed, Varnish, Nginx FastCGI cache) are covered by a signed, 
daily-rotating pass token: only visitors the gate let through can ever receive a
cached page; LiteSpeed Cache is configured automatically through its own hooks, 
and a ready-to-paste Varnish/Nginx snippet is generated. Caching is only allowed
again after live checks prove a simulated blocked visitor is refused on every layer(
run by the server, or from your own browser if your host blocks the server from 
reaching itself), with a one-time nonce per check so a cached reply can’t pass as
the gate. Administrators keep access from anywhere and every logged-in user keeps
wp-admin, via signed cookies. Works on multisite (per-site rules; network admins
only). Every config change is checked with a live request and undone on any error;
turning it off restores wp-config.php byte for byte. Off by default; kill switch:
wp-content/secondgate-gate/DISABLE. Tested with WP Super Cache (both modes), W3 
Total Cache (Disk: Enhanced), Cache Enabler (both modes), Varnish and Nginx FastCGI
cache. Security hardening: authenticator codes are now accepted once only, and the
accepted window is 60 seconds either side (was 90); five wrong codes end that sign-
in attempt and the password must be entered again, even with brute-force protection
off; trusted devices are forgotten when the account password is changed or reset;
the “Remember Me” choice from the password step is now honoured after 2FA; passkey
setup requires the authenticator to confirm the user is present; new option to turn
off application passwords for users with 2FA. Proxy headers: X-Forwarded-For is 
read from the right, the Cloudflare header is only believed from Cloudflare’s own
IP ranges (built in), and an optional list of your own proxy addresses limits the
other headers the same way. The public “am I blocked” check no longer writes to 
the request log, the gate’s crawler DNS cache is pruned daily, list imports check
the uploaded file before reading it, and the 2FA settings page showed the wrong 
version number. Also fixed: an IP inside a wide allow/deny range listed alongside
narrower ranges inside it (e.g. 10.0.0.0/8 plus 10.1.0.0/16) could be missed by 
the matcher.

#### 1.1.8.1

Real, complete fix, closed at both layers, not just documented: a cached page could
later be served, unchanged, to a visitor who should now be blocked, if the block
list changed after the cache was created. Now sets DONOTCACHEPAGE (reaching WordPress-
plugin-based caches) AND sends a real Cache-Control header via nocache_headers()(
reaching CDNs, reverse proxies, and server-level caches too, since that’s genuine
HTTP protocol semantics, not a WordPress-only convention), whenever any blocking
mechanism is active, for every visitor, not just a blocked one. Confirmed with real
tests. Worth the honest trade-off: no page can be cached by any layer as long as
blocking is configured, a deliberate choice, since a stale, wrongly-served page 
is worse than a slower one.

#### 1.1.8

Two real, confirmed race conditions ported from Pro (brute-force lockout and daily
stats, both fixed with real file locking after a real multi-process test confirmed
the original code lost increments under concurrent load); the deny-list capped for
consistency.

#### 1.1.7

A step-by-step modal wizard added over the existing 2FA setup flow. Three real bugs
found and fixed through hands-on testing: a false unsaved-changes browser prompt,
stale cached JS/CSS after an update, and a setup flag not clearing on the faster
path.

#### 1.1.6

Ported the new-country login alert fix from Pro’s Session Guard work; the underlying
detection mechanism didn’t exist here at all until this version, a full port, not
a redirected function call.

#### 1.1.5

A real gap found and fixed: the 2FA security-notification email used the raw connecting
IP instead of this plugin’s own trusted-proxy-aware resolver, even though it was
available. Independent static analysis run against this plugin’s own code.

#### 1.1.4

The optional per-request log moved from a predictable, unprotected file path to 
options storage. All inline script/style output converted to WordPress’s own enqueue
APIs.

#### 1.1.3

Ported the shared IP-resolution fix from Pro: brute-force lockout now uses the same
trusted-proxy-aware resolver as the rest of the plugin, instead of its own separate
copy.

#### 1.1.2

Ported a real CIDR-parsing fix from Pro: a malformed prefix length was being silently
treated as “block everyone” instead of being rejected.

#### 1.1.1

Ported the WebAuthn/passkey hardening pass from Pro: a narrowed decode whitelist,
input-size and nesting-depth limits, and broadened exception handling.

#### 1.1.0 and 1.0.0

Initial free-tier feature set: passkeys, TOTP two-factor authentication, brute-force
protection, country blocking, and verified search-crawler exemption.

## Meta

 *  Version **1.1.9**
 *  Last updated **2 ddiwrnod yn ôl**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.0 neu uwch **
 *  Tested up to **7.1.3**
 *  PHP version ** 7.2 neu uwch **
 *  Language
 * [English (US)](https://wordpress.org/plugins/secondgate/)
 * Tags
 * [2FA](https://cy.wordpress.org/plugins/tags/2fa/)[geo block](https://cy.wordpress.org/plugins/tags/geo-block/)
   [passkeys](https://cy.wordpress.org/plugins/tags/passkeys/)[security](https://cy.wordpress.org/plugins/tags/security/)
   [two factor authentication](https://cy.wordpress.org/plugins/tags/two-factor-authentication/)
 *  [Advanced View](https://cy.wordpress.org/plugins/secondgate/advanced/)

## Graddau

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/secondgate/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/secondgate/reviews/)

## Cyfranwyr

 *   [ SecondGateWP ](https://profiles.wordpress.org/secondgatewp/)

## Cefnogaeth

Rhywbeth i'w ddweud? Angen help?

 [Gweld y fforwm cefnogi](https://wordpress.org/support/plugin/secondgate/)