New 24/7 monitoring and daily cloud backups now included in every Shield Pro plan.

Help Centre

BugShield Knowledge Base

Guides, walkthroughs, and answers for getting the most out of your account.

Blocking Visitors

Repeated login attempts, scraping, spam and unusually heavy requests can affect a website. Before blocking traffic, use hosting, firewall or application logs to identify the request pattern, source and time.

Choose a proportionate response

  • Challenge: ask suspicious automated traffic to prove it is a real browser.
  • Rate limit: slow or reject repeated requests to a sensitive path such as login.
  • IP or network block: stop a confirmed source for a suitable period.
  • Country rule: restrict a region only when the business does not need legitimate visitors from it.
  • Application controls: reduce comment, form or login abuse close to the affected feature.

Apply and review the rule

  1. Confirm that the source is not a trusted service, team member or shared proxy.
  2. Use the narrowest rule that addresses the activity.
  3. Keep another way to access the host or firewall in case the rule affects your own connection.
  4. Test the public site, admin area and any integrations after applying it.
  5. Review temporary blocks later instead of allowing old rules to accumulate.

When the traffic is part of a security incident

Blocking one address does not remove malware or secure a compromised account. If you see unknown administrators, changed files or redirects, continue with Website Hacking and Malware. If you need developer help, submit a Fix Request.

Common questions

Frequently Asked Questions

Should I permanently block every suspicious IP address?

Not always. Addresses can change or be shared, and automated attacks often move between networks. Rate limits and managed challenges can be more effective for repeated patterns.

Can blocking a country affect legitimate services?

Yes. Customers, search crawlers, payment callbacks, monitoring or remote team members may use infrastructure in that region. Review the site's dependencies first.

Why can I still see requests from a blocked visitor?

The rule may apply at a different layer, the visitor may be using another address, or logs may record a proxy rather than the original source. Check how the site receives and records traffic.

Will blocking an attacker clean a hacked website?

No. A block can reduce traffic from one source, but compromised files, users or credentials need a separate security investigation and recovery process.

Still need help?

Can’t find what you need? Our team is here to help.

Contact us