Block External Request
Every admin page waits for calls you never asked for.
WordPress, plugins and themes phone home constantly: update checks, licence pings, analytics, fonts. On a slow or restricted server each one can add seconds to a page. This plugin blocks the ones you list, lets through the ones you need, and gets out of the way when you ask it to.
Free, GPL-2.0 or later, published under BlackSwan, my own label. The source is the plugin itself, on WordPress.org; there is no separate public repository. Figures from the WordPress.org API, 30 September 2026.
What it does
Three kinds of blocking, each switched on separately for the admin and the front end.
Server-side calls
Requests WordPress makes from PHP, through wp_remote_get and friends, are refused before they leave the server.
Scripts by domain
JavaScript and CSS enqueued from a blocked domain are dequeued. The site's own files are never touched.
Specific files
Block one script or stylesheet by URL, path or file name, local or external, without editing code.
And the rest
Swap a library for a CDN copy, switch off emoji and Gravatar requests, and export or import every setting as one JSON file.
How it blocks
WordPress asks one filter before every outgoing HTTP request. Answer it with an error and the request never happens.
The plugin hooks pre_http_request. Each blocked domain is matched against the full URL; if the URL also matches a whitelist pattern, it goes through. Whitelist wins, so a vendor's update API can stay open while the rest of the vendor is blocked.
A blocked call returns a WP_Error that names the plugin and the URL, so a developer debugging a failed request, in Query Monitor for example, sees at once who stopped it. Settings live in one option with autoload off, so they cost nothing on pages that do not need them.
add_filter('pre_http_request', [$this, 'block_external_request'], 10, 3); function block_external_request($preempt, $args, $url) { foreach ($this->block_url_list as $blocked) { if (strpos($url, $blocked) !== false) { foreach ($this->whitelist_urls as $ok) if (strpos($url, $ok) !== false) return $preempt; return new WP_Error('http_request_block', ...); } } return $preempt; }
Not locking yourself out
A plugin that blocks scripts can block the scripts of its own settings page. Three ways back.
- Pause
- One click stops all blocking and keeps every list, for when something breaks and you need to know if it was this.
- Safe mode
- Add
?bswan-safe=1to any admin URL and nothing is blocked for that page load. - Its own page
- The settings screen skips resource blocking, so it always loads.
Getting started
It ships with a default blacklist and whitelist, so it helps on activation.
Install
Plugins, Add New, search for "BlackSwan Block External Request", then Install and Activate.
Open the settings
Settings, Block External Request. The overview shows what is switched on.
Watch what is blocked
With Query Monitor installed, failed HTTP calls name this plugin as the cause. The settings page can install or activate Query Monitor for you.
Whitelist what you need
Add URL patterns, such as a licence API, that must always go through.
Releases
First published in October 2022 with no settings screen at all. Nine versions in five weeks of 2026 turned it into this.
| Version | Released | What changed |
|---|---|---|
| 2.9.3 | 13 Apr 2026 | Font Awesome, jsDelivr, unpkg, cdnjs, Google Tag Manager and Google Fonts added to the exclude list; translation fixed. |
| 2.9.2 | 13 Apr 2026 | No separate notes. |
| 2.9.1 | 12 Apr 2026 | No separate notes. |
| 2.9.0 | 9 Apr 2026 | Disable All Emoji, which removes the requests to s.w.org. |
| 2.8.0 | 6 Apr 2026 | More than thirty domains added to the default blacklist, mostly licence checks, telemetry and update pings. |
| 2.7.0 | 26 Mar 2026 | All four developer filters documented with examples. |
| 2.6.2 | 9 Mar 2026 | Analytics and payment gateway domains in the defaults; a filter for blocked resources. |
| 2.6.1 | 8 Mar 2026 | No separate notes. |
| 2.6.0 | 7 Mar 2026 | A new settings interface, no external icons or fonts, Query Monitor detection. |
| first release | 27 Oct 2022 | Listed on WordPress.org. |
// open-source/
More open source
The other projects with a page of their own. The rest, 56 in all, are in the explorer, each with its status and where the numbers come from.
- Receipt Uploader for WooCommerce1,000+ installs, rated 5.0 from 14
- upload-url-to-serverOne PHP file, 32 releases since 2020
- Justify It and Lorem SazAdobe XD plugins, 11,015 downloads, archived
- CF7 DatabaseContact Form 7 submissions, kept and exported
- Gravity Forms OTP VerificationA one-time code before the entry is saved
- Block External RequestWordPress's outbound calls, under control
- Slipnet for macOSA Mac client for a DNS-tunnelling VPN
- BDM, BlackSwan Download ManagerSegmented downloads on the Mac, with browser extensions
- Firefox add-onsFive published, 4.6 average rating