Title: Traffic Origin Guard
Author: jasond727
Published: <strong>19 чэрвеня, 2026</strong>
Last modified: 19 чэрвеня, 2026

---

Пошук плагінаў

![](https://s.w.org/plugins/geopattern-icon/traffic-origin-guard.svg)

# Traffic Origin Guard

 Аўтар: [jasond727](https://profiles.wordpress.org/jasond727/)

[Спампаваць](https://downloads.wordpress.org/plugin/traffic-origin-guard.1.0.0.zip)

 * [Падрабязнасці](https://bel.wordpress.org/plugins/traffic-origin-guard/#description)
 * [Водгукі](https://bel.wordpress.org/plugins/traffic-origin-guard/#reviews)
 *  [Ўсталёўка](https://bel.wordpress.org/plugins/traffic-origin-guard/#installation)
 * [Распрацоўка](https://bel.wordpress.org/plugins/traffic-origin-guard/#developers)

 [Падтрымка](https://wordpress.org/support/plugin/traffic-origin-guard/)

## Апісанне

Traffic Origin Guard helps protect your origin server from direct traffic by requiring
a secret header value on every request.

Use case:
 – Your site is behind Cloudflare or another reverse proxy. – You want
only proxy-originated requests to reach WordPress. – You want automatic Apache rule
management.

How it works:
 – You set one token in plugin settings. – The plugin writes Apache
rules into .htaccess using a managed block. – Requests missing the expected X-Origin-
Secret header are blocked with HTTP 403.

Features:
 – Apache .htaccess rule writer with managed BEGIN/END markers. – Header
validation status visibility on the settings page. – One-click token utilities in
admin (generate, copy, and “Use as token”). – In-page Cloudflare setup guide with
step-by-step instructions. – Lockout recovery instructions displayed directly in
the settings page. – View details link on the Plugins list page. – Automatic cleanup
on plugin deactivation and uninstall.

## Ўсталёўка

 1. Upload the plugin folder to /wp-content/plugins/traffic-origin-guard/.
 2. Activate Traffic Origin Guard from Plugins in WordPress admin.
 3. Go to Settings -> Traffic Origin Guard.
 4. Generate a token using the generator on the settings page.
 5. In Cloudflare, go to Rules -> Transform Rules -> Modify Request Header and add 
    a rule setting X-Origin-Secret to your token on all requests. Do this BEFORE saving
    the token to avoid locking yourself out.
 6. Paste the token into the token field and click Save Token. Confirm the Active server
    rules block appears on the page.
 7. Verify direct origin access without the header returns 403.

## Часта задаваныя пытанні

### Will this lock me out of wp-admin?

Yes, it can if misconfigured. This plugin enforces access at Apache level, so a 
wrong token/header setup can block wp-admin access.

To recover: connect to your server via FTP, SFTP, or your host’s file manager and
open .htaccess in your WordPress root. Find and delete the entire block between (
and including) the lines “# BEGIN Traffic Origin Guard” and “# END Traffic Origin
Guard”. Save the file — your site will be accessible immediately. Then set up your
Cloudflare Transform Rule first before re-entering the token.

### Which servers are supported?

This plugin manages Apache .htaccess rules directly.

### What if .htaccess is not writable?

The plugin cannot enforce protection until .htaccess is writable. Fix permissions/
ownership and save settings again.

### What header name does the plugin check?

X-Origin-Secret

## Водгукі

На гэты плагін няма водгукаў.

## Удзельнікі і распрацоўшчыкі

“Traffic Origin Guard” is open source software. The following people have contributed
to this plugin.

Удзельнікі

 *   [ jasond727 ](https://profiles.wordpress.org/jasond727/)

[Перакласці “Traffic Origin Guard” на вашу мову.](https://translate.wordpress.org/projects/wp-plugins/traffic-origin-guard)

### Зацікаўлены ў распрацоўцы?

[Праглядзіце код](https://plugins.trac.wordpress.org/browser/traffic-origin-guard/),
праверце [SVN рэпазітарый](https://plugins.svn.wordpress.org/traffic-origin-guard/),
або падпішыцеся на [журнал распрацоўкі](https://plugins.trac.wordpress.org/log/traffic-origin-guard/)
па [RSS](https://plugins.trac.wordpress.org/log/traffic-origin-guard/?limit=100&mode=stop_on_copy&format=rss).

## Мета

 *  Версія **1.0.0**
 *  Апошняе абнаўленне **1 месяц таму**
 *  Актыўных установак **Менш за 10**
 *  Версія WordPress ** 7.0 або вышэй **
 *  Правераны да версіі **7.0.2**
 *  Версія PHP ** 8.3 або вышэй **
 *  Мова
 * [English (US)](https://wordpress.org/plugins/traffic-origin-guard/)
 * Тэгі
 * [Apache](https://bel.wordpress.org/plugins/tags/apache/)[cloudflare](https://bel.wordpress.org/plugins/tags/cloudflare/)
   [hardening](https://bel.wordpress.org/plugins/tags/hardening/)[headers](https://bel.wordpress.org/plugins/tags/headers/)
   [security](https://bel.wordpress.org/plugins/tags/security/)
 *  [Пашыраны прагляд](https://bel.wordpress.org/plugins/traffic-origin-guard/advanced/)

## Ацэнкі

Пакуль яшчэ няма водгукаў.

[Your review](https://wordpress.org/support/plugin/traffic-origin-guard/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/traffic-origin-guard/reviews/)

## Удзельнікі

 *   [ jasond727 ](https://profiles.wordpress.org/jasond727/)

## Падтрымка

Ёсць што сказаць? Патрэбна дапамога?

 [Перайсці да форуму падтрымкі](https://wordpress.org/support/plugin/traffic-origin-guard/)