Allow Formitor through a host or server firewall


Updated August 2, 2026 · also available in the in-app Help center

Some blocks happen before a request ever reaches WordPress: a firewall at your hosting company, a server tool like fail2ban or CSF, or a security service we could not identify. Monitoring keeps working in protected mode, since the plugin reports out on its own. Allowing our IP addresses unlocks instant rechecks, real browser checks, and one click plugin updates.

The addresses to allow

Add both. The second one is our backup server, which takes over automatically if the primary is ever down.

  • 185.147.157.155
  • 152.53.90.187

Where to add them

  • Managed WordPress hosts (Kinsta, WP Engine, SiteGround, Cloudways and similar): open a support chat and ask them to allow the two IP addresses above. This usually takes a few minutes.
  • MalCare / BlogVault: log in to their dashboard, pick the site, open the Firewall section and add each address to the IP allowlist. Their support chat can also add them for you.
  • Plesk: go to Tools & Settings, then Firewall, and add an allow rule for each address. If Fail2Ban is active, also add them under Tools & Settings, then IP Address Banning, in the trusted list.
  • cPanel with CSF: in WHM, open ConfigServer Security & Firewall and add each address to the allow list, or ask your host to do it.
  • Security plugins: if the site runs a security plugin with its own firewall (Wordfence, Sucuri, CleanTalk and similar), check its allowlist settings too. We have separate guides for the common ones.

Check that it worked

Back in the Formitor dashboard, open the site and press the recheck button, or use the test again button if you still have the connection window open. The protected badge clears as soon as our checks get through.

Allow by User-Agent

Formitor's checks identify themselves with the User-Agent Formitor/1.0 (+https://formitor.com). If your firewall or anti-spam tool supports allow rules by User-Agent, allowing that exact string is the most reliable option: it keeps working even when our server addresses change.

Questions the docs didn't answer?

The in-app assistant knows your own sites, or reach us directly.