=== IPzentra Geo Guard ===
Contributors: your_wporg_username
Tags: country blocking, geoblocking, login security, vpn detection, woocommerce
Requires at least: 6.2
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.0.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Country rules for logins, registrations and WooCommerce, with VPN, proxy, Tor and datacenter detection, powered by the IPzentra API.

== Description ==

IPzentra Geo Guard checks where a visitor really comes from before they sign in or register, and stops the ones you do not want.

= Login security =

* Allow sign-ins only from the countries you choose, or block specific countries.
* Set a stricter extra rule for privileged roles, for example keep administrator logins to your own country.
* Block sign-ins from VPNs, open proxies, Tor and datacenter or cloud servers.
* Covers wp-login.php, WooCommerce My Account, XML-RPC and application passwords.
* Optionally turn off XML-RPC, a common target for password guessing.

= Registration protection =

* Apply separate country and network rules to new WordPress and WooCommerce registrations.

= WooCommerce country rules =

* Limit any product, or a whole category, to the countries you choose, or exclude countries.
* Show blocked products with a "not sold in your country" message, or hide them from the shop, categories and search.
* Blocked products cannot be added to the cart by any route, including the block-based Cart and Checkout.
* Checkout guard: refuse orders, or hold them for review, from chosen countries, VPNs, proxies, Tor or datacenters, or when the billing country differs from the IP country.
* An order note on every order with the buyer's IP country, network and risk.
* Use IPzentra as the WooCommerce geolocation provider, with no MaxMind licence key needed.
* Pages that depend on the visitor's country are excluded from page caching automatically.

= Built to be safe =

* Lockout protection: rules that would block your own login are refused when you save them.
* Always allowed IPs are never blocked, and an emergency switch in wp-config.php turns every rule off.
* If the API cannot be reached, visitors are allowed in by default.
* Each visitor is looked up at most once per cache period (24 hours by default), so lookups stay low.
* An activity log records blocked attempts with shortened IP addresses and deletes old entries automatically.
* Suggested text for your privacy policy is added to the WordPress privacy guide.

= Requirements =

Geo Guard uses the IPzentra IP intelligence API and needs an IPzentra API key. New accounts start with a free trial. Plans and limits are listed at https://ipzentra.com/pricing.

== External services ==

This plugin connects to the IPzentra API at https://api.ipzentra.com, provided by Astrizon Technology Solutions Pvt Ltd, to look up the country, network and risk signals of an IP address.

* What is sent: the IP address being checked and your API key. No other personal data is sent.
* When it is sent: only after you save an API key, and only when a rule you have turned on needs to check a visitor (for example when someone signs in or registers), or when you use the test lookup on the settings screen. If you turn on the WooCommerce geolocation option, visitors that WooCommerce geolocates are looked up too.
* Caching: results are stored on your site for the period you choose, 24 hours by default, so the same address is not sent again during that time.

IPzentra terms of service: https://ipzentra.com/terms
IPzentra privacy policy: https://ipzentra.com/privacy

== Installation ==

1. Install and activate the plugin from the Plugins screen, or upload the plugin folder to /wp-content/plugins/.
2. Create a free IPzentra account at https://app.ipzentra.com/signup and copy your API key.
3. Go to Geo Guard > General, paste the key, click "Add my IP" and save.
4. Use Test lookup to confirm the connection, then set your rules on the Login security tab.

== Frequently Asked Questions ==

= Do I need an API key? =

Yes. Rules stay off until a key is saved. A free trial key is enough to try every feature.

= I locked myself out. What now? =

Add define( 'IPZGG_DISABLE', true ); to wp-config.php to switch every rule off, sign in, fix the rule, then remove the line.

= My site is behind Cloudflare or a proxy. =

Choose the matching option under Visitor IP source on the General tab, so the plugin sees each visitor's real address.

= Will this block search engines? =

No. Login and registration rules only apply when someone signs in or registers.

= How many lookups will my site use? =

One per visitor who triggers a rule, per cache period. Pages that no rule applies to cost nothing.

== Screenshots ==

1. Overview with connection status, blocked attempts and active protection.
2. General settings with the test lookup tool.
3. Login security rules with country and network options.
4. WooCommerce settings: how blocked products appear, the checkout guard and IPzentra geolocation.
5. The Country availability box on a product.

== Changelog ==

= 1.0.0 =
* First release: login and registration rules, WooCommerce product, category and checkout rules, WooCommerce geolocation provider, VPN, proxy, Tor and datacenter blocking, lockout protection, activity log and test lookup.
