# Using Wordfence IP blockings (Wordpress WAF) for Crowdsec decisions

**URL:** <https://discourse.crowdsec.net/t/using-wordfence-ip-blockings-wordpress-waf-for-crowdsec-decisions/1921>\
**Category:** crowdsec\
**Created:** [July 13, 2024, 8:28am UTC](https://discourse.crowdsec.net/t/using-wordfence-ip-blockings-wordpress-waf-for-crowdsec-decisions/1921 "2024-07-13T08:28:17Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cyrille37](https://avatars.discourse-cdn.com/v4/letter/c/90db22/32.png) [@Cyrille37](https://discourse.crowdsec.net/u/Cyrille37)\
**Post date:** [July 13, 2024, 8:28am UTC](https://discourse.crowdsec.net/t/using-wordfence-ip-blockings-wordpress-waf-for-crowdsec-decisions/1921/1 "2024-07-13T08:28:17Z")

</div>

Hi,

Wordfence is a great Wordpress WAF with many options for blocking IP on some unwanted behaviors. I did not find any thing on Internet about Crowdsec scenario using Wordfence blockings to take decision.

I would like to use Wordfence IP blockings to trigger Crowdsec decision on firewall-bouncer to avoid CPU overload by PHP (Wordpress/Wordfence) processing.

So I’m writing a [Wordpress plugin](https://github.com/Cyrille37/wordfence-blockings-log) to log in a file all Wordfence IP blockings. Then I’ve to write a parser and a scenario to trigger decision for crowdsec.

At the moment the log looks like :

```auto
[date] [ip] [blocking duration] [action] [reason]

```

```auto
[12/Jul/2024:18:50:53 +0000] [188.246.233.180] [600] [block] [Blocked by Wordfence Security Network]
[12/Jul/2024:21:17:13 +0000] [66.23.225.60] [300] [block] [Blocked by login security setting]
[12/Jul/2024:22:53:35 +0000] [34.124.177.101] [600] [block] [Blocked by Wordfence Security Network]
[12/Jul/2024:23:48:00 +0000] [144.91.97.25] [600] [block] [Blocked by Wordfence Security Network]
[13/Jul/2024:02:23:16 +0000] [188.164.196.16] [600] [block] [Blocked by Wordfence Security Network]
[13/Jul/2024:04:53:19 +0000] [51.210.113.223] [600] [block] [Blocked by Wordfence Security Network]
[13/Jul/2024:06:41:45 +0000] [43.248.141.170] [60] [throttle] [Exceeded the maximum global requests per minute for crawlers or humans.]
[13/Jul/2024:06:41:46 +0000] [43.248.141.170] [59] [block] [Exceeded the maximum global requests per minute for crawlers or humans.]
[13/Jul/2024:06:41:46 +0000] [43.248.141.170] [59] [block] [Exceeded the maximum global requests per minute for crawlers or humans.]

```

Before continuing with this work, I’m coming to you to make sure that something doesn’t already exist 🙂

Thanks for your contribution.

---

<div class="post-metadata">

**Author:** ![Cyrille37](https://avatars.discourse-cdn.com/v4/letter/c/90db22/32.png) [@Cyrille37](https://discourse.crowdsec.net/u/Cyrille37)\
**Post date:** [April 27, 2026, 1:33pm UTC](https://discourse.crowdsec.net/t/using-wordfence-ip-blockings-wordpress-waf-for-crowdsec-decisions/1921/2 "2026-04-27T13:33:37Z")

</div>

Hi. So, it seems that nothing similar exists …  
Now I’ve to write a parser to trigger decisions for this log … 😉

---

<div class="post-metadata">

**Author:** ![Cyrille37](https://avatars.discourse-cdn.com/v4/letter/c/90db22/32.png) [@Cyrille37](https://discourse.crowdsec.net/u/Cyrille37)\
**Post date:** [June 17, 2026, 5:38am UTC](https://discourse.crowdsec.net/t/using-wordfence-ip-blockings-wordpress-waf-for-crowdsec-decisions/1921/3 "2026-06-17T05:38:37Z")

</div>

Here is a Wordpress plugin which is logging Wordfence events in a file and it’s Crowdsec parsers and scenario: [GitHub - Cyrille37/wordfence-blockings-log: Wordpress Wordfence blockings log · GitHub](https://github.com/Cyrille37/wordfence-blockings-log)
