Amirhossein Hosseinpouramirhp
CV
Active WordPress plugin · Performance

Block External Request

Every admin page waits for calls you never asked for.

WordPress, plugins and themes phone home constantly: update checks, licence pings, analytics, fonts. On a slow or restricted server each one can add seconds to a page. This plugin blocks the ones you list, lets through the ones you need, and gets out of the way when you ask it to.

Get it on WordPress.org Changelog

Free, GPL-2.0 or later, published under BlackSwan, my own label. The source is the plugin itself, on WordPress.org; there is no separate public repository. Figures from the WordPress.org API, 30 September 2026.

On WordPress.org2022 to today

What it does

Three kinds of blocking, each switched on separately for the admin and the front end.

Server-side calls

Requests WordPress makes from PHP, through wp_remote_get and friends, are refused before they leave the server.

Scripts by domain

JavaScript and CSS enqueued from a blocked domain are dequeued. The site's own files are never touched.

Specific files

Block one script or stylesheet by URL, path or file name, local or external, without editing code.

And the rest

Swap a library for a CDN copy, switch off emoji and Gravatar requests, and export or import every setting as one JSON file.

How it blocks

WordPress asks one filter before every outgoing HTTP request. Answer it with an error and the request never happens.

The plugin hooks pre_http_request. Each blocked domain is matched against the full URL; if the URL also matches a whitelist pattern, it goes through. Whitelist wins, so a vendor's update API can stay open while the rest of the vendor is blocked.

A blocked call returns a WP_Error that names the plugin and the URL, so a developer debugging a failed request, in Query Monitor for example, sees at once who stopped it. Settings live in one option with autoload off, so they cost nothing on pages that do not need them.

add_filter('pre_http_request', [$this, 'block_external_request'], 10, 3);

function block_external_request($preempt, $args, $url) {
  foreach ($this->block_url_list as $blocked) {
    if (strpos($url, $blocked) !== false) {
      foreach ($this->whitelist_urls as $ok)
        if (strpos($url, $ok) !== false) return $preempt;
      return new WP_Error('http_request_block', ...);
    }
  }
  return $preempt;
}
From blackswan-block-external-request.php, version 2.9.3, lightly trimmed.

Not locking yourself out

A plugin that blocks scripts can block the scripts of its own settings page. Three ways back.

Pause
One click stops all blocking and keeps every list, for when something breaks and you need to know if it was this.
Safe mode
Add ?bswan-safe=1 to any admin URL and nothing is blocked for that page load.
Its own page
The settings screen skips resource blocking, so it always loads.

Getting started

It ships with a default blacklist and whitelist, so it helps on activation.

  1. Install

    Plugins, Add New, search for "BlackSwan Block External Request", then Install and Activate.

  2. Open the settings

    Settings, Block External Request. The overview shows what is switched on.

  3. Watch what is blocked

    With Query Monitor installed, failed HTTP calls name this plugin as the cause. The settings page can install or activate Query Monitor for you.

  4. Whitelist what you need

    Add URL patterns, such as a licence API, that must always go through.

Releases

First published in October 2022 with no settings screen at all. Nine versions in five weeks of 2026 turned it into this.

VersionReleasedWhat changed
2.9.313 Apr 2026Font Awesome, jsDelivr, unpkg, cdnjs, Google Tag Manager and Google Fonts added to the exclude list; translation fixed.
2.9.213 Apr 2026No separate notes.
2.9.112 Apr 2026No separate notes.
2.9.09 Apr 2026Disable All Emoji, which removes the requests to s.w.org.
2.8.06 Apr 2026More than thirty domains added to the default blacklist, mostly licence checks, telemetry and update pings.
2.7.026 Mar 2026All four developer filters documented with examples.
2.6.29 Mar 2026Analytics and payment gateway domains in the defaults; a filter for blocked resources.
2.6.18 Mar 2026No separate notes.
2.6.07 Mar 2026A new settings interface, no external icons or fonts, Query Monitor detection.
first release27 Oct 2022Listed on WordPress.org.
branch main 6 active projects ↑ 113 releases open-source/block-external-request.md Sari --:-- UTC+3:30 its@amirhp.com