Install where you need protection
Choose the Linux package or the plugin for your application. Each has a setup guide with its requirements and configuration steps.
Linux servers · WordPress · Matomo
Repeated login attempts, unwanted bots, suspicious requests. Witen helps you spot the source, block it locally, and review what happened.
Free plan for one connected site or server. Create an account.
Witen Warden
Detect SSH login attacks and suspicious web requests. Block IPs through the host firewall and review active blocks from the server.
Requires administrator access to Linux.
Explore Linux serversWiten Blocker
Limit login attempts, manage bot rules, and scan suspicious files from your WordPress dashboard.
Works on shared hosting. No root access needed.
Explore WordPressWiten for Matomo
Manage IP rules, bot policies, login limits, and file checks for your self-hosted Matomo server.
Protects Matomo itself, not the websites it tracks.
Explore MatomoChoose the Linux package or the plugin for your application. Each has a setup guide with its requirements and configuration steps.
Check trusted addresses, login limits, and bot policies before using them on live traffic. Warden’s setup guide explains how to evaluate detections without changing your firewall.
Enroll a site or server to receive Witen’s IP blocklists and view its reports in your account. Plans set the number of connected assets and how current the shared data is.
See which address was blocked and the activity behind it. Check the rule, allow a trusted address, or remove a block that needs correcting.
Warden’s temporary firewall blocks expire automatically. Local rules keep working when the Witen website is unavailable.
The example shows a temporary Warden block. WordPress and Matomo provide their own activity pages and controls inside the application.
Read the Warden setup guidedec_7f31a9Temporary host block
This example shows repeated login failures and web probes from one address. A configured login threshold triggers a temporary host block.
app-01web-01host-02Automatic expiry is active
An address trying passwords on one server may be probing another. Witen uses reports from participating systems to build shared IP reputation and blocklists. Your site can use that information alongside its own rules.
Your local policy decides what to block. Review a feed, keep trusted addresses allowed, and choose whether to share security events.
Login limits, IP rules, and bot policies run on your server or inside the plugin.
A connected account adds blocklist updates and reports from your enrolled sites and servers. Free and paid plans offer different update coverage.
Compare addresses, networks, and events across connected assets on plans that include correlation. Where available, JA4 TLS fingerprints help group clients that change IP addresses.
Choose a product, read its setup guide, and try the controls on a system you know.