WordPress Security
It's blocking real visitors
Loosen things if legitimate customers are being blocked.
If real customers are being blocked, you have several dials to loosen — from gentlest to strongest.
1. Check the Threat Log first
Open Predax Security → Threat Log to see *why* an IP was blocked (VPN, proxy, country, risk score, etc.). That tells you which setting to adjust.
2. Raise the Risk Threshold
Move the Risk Threshold toward Lenient (70) so only clearly high-risk visitors are blocked.
3. Switch a type from Block to Monitor
If legitimate customers use VPNs, set VPN Detection (or Proxy) to Monitor instead of Block — see Detection Modes. You will still see them in the log without blocking them.
4. Allow-list trusted IPs
Add specific customers, office IPs, or partners to the IP Allow-list so they are never blocked.
5. Re-check country blocking
If you turned on country or region blocking, make sure you have not blocked a region your customers are in.
Still seeing false positives? Email [email protected] with an example IP and we will take a look.