Skip to content

Linux servers · WordPress · Matomo

Block abusive traffic on your sites and servers.

Repeated login attempts, unwanted bots, suspicious requests. Witen helps you spot the source, block it locally, and review what happened.

Free plan for one connected site or server. Create an account.

What do you want to protect?

From installation to your first block

1

Install where you need protection

Choose the Linux package or the plugin for your application. Each has a setup guide with its requirements and configuration steps.

2

Review the local rules

Check trusted addresses, login limits, and bot policies before using them on live traffic. Warden’s setup guide explains how to evaluate detections without changing your firewall.

3

Connect shared intelligence if you need it

Enroll a site or server to receive Witen’s IP blocklists and view its reports in your account. Plans set the number of connected assets and how current the shared data is.

Review the reason for a block

See which address was blocked and the activity behind it. Check the rule, allow a trusted address, or remove a block that needs correcting.

Warden’s temporary firewall blocks expire automatically. Local rules keep working when the Witen website is unavailable.

The example shows a temporary Warden block. WordPress and Matomo provide their own activity pages and controls inside the application.

Read the Warden setup guide
Example: temporary block
dec_7f31a9

Temporary host block

198.51.100.24

This example shows repeated login failures and web probes from one address. A configured login threshold triggers a temporary host block.

Reason
Login failures
Enforced by
nftables
Scope
This host
Expires
18 minutes

Why Witen acted

3 sources
  • WordPress · 14 failed administrator logins
  • Web server · 3 probes for vulnerable PHP paths
  • SSH · 6 authentication failures across 2 hosts

Automatic expiry is active

AllowUndo Explained

Learn from attacks seen elsewhere

An address trying passwords on one server may be probing another. Witen uses reports from participating systems to build shared IP reputation and blocklists. Your site can use that information alongside its own rules.

Your local policy decides what to block. Review a feed, keep trusted addresses allowed, and choose whether to share security events.

Local protection

Login limits, IP rules, and bot policies run on your server or inside the plugin.

Shared intelligence

A connected account adds blocklist updates and reports from your enrolled sites and servers. Free and paid plans offer different update coverage.

Investigate related activity

Compare addresses, networks, and events across connected assets on plans that include correlation. Where available, JA4 TLS fingerprints help group clients that change IP addresses.

Common questions

Which Witen product do I need?
Use Warden for a Linux server you administer. Use the WordPress plugin for a WordPress site, including shared hosting. Use the Matomo plugin for a self-hosted Matomo installation. You can combine a plugin with Warden when you control the host.
What is free?
The downloads are free. The hosted Free plan covers one connected asset with a top-50 IP blocklist, updated daily with a 14-day delay on new threats. Local plugin rules work without a paid plan. Compare the plans for current shared data and more connected assets.
Do I have to move my website or change DNS?
No. Warden runs on your Linux host, and the plugins run inside WordPress or Matomo. Witen does not require you to route your site through another proxy.
Does the Matomo plugin protect the websites I track?
It protects requests to the Matomo server, including login and tracking endpoints. A website tracked by Matomo needs its own protection.

Start with one site or server

Choose a product, read its setup guide, and try the controls on a system you know.