Skip to main content

Imunify Security is blocking something on my site — what should I do?

Imunify Security occasionally blocks a legitimate request by mistake — a "false positive." When that happens, one page, feature, or app stops working while the rest of your site is fine. Here's how to recognize it and get the request unblocked without removing your protection.

How to recognize an Imunify Security block

A false positive usually shows up as one of these, on a specific request rather than your whole site:

  • "Access denied" or a 403 error — on a page, an image or stylesheet, or an action in wp-admin.

  • "Too many requests" or a 429 error — usually on a plugin, app, or API that sends automated requests, such as an SEO tool or a connection from another service.

If instead your whole site is down or returns 500 or 503 errors everywhere, that's usually a different problem — skip to "When you contact support" below.

Good to know: most blocks come from a single rule catching one request by mistake. Support can adjust that one rule and leave the rest of your protection in place — you rarely need to turn anything off.

If an app or API is rate-limited (429)

Imunify Security includes bot protection that limits automated traffic. If a legitimate tool or API is getting "Too many requests," you can lower the bot-protection level for your site from the Imunify Security section of your WordPress dashboard, or ask support to do it. Log in to your WordPress dashboard first if you aren't already.

If a page or asset is blocked (403)

A 403 is usually a firewall rule catching a legitimate request. Rather than turning protection off, contact support with the details below and ask them to adjust the specific rule. That keeps your site protected while fixing the one request that was blocked.

If your IP is blocked, or you can't reach your site or wp-admin

If you can't reach your site, cPanel, or wp-admin at all — or a specific IP (yours, or one used by an app or API) is being blocked — check whether your IP is blocked using How can I tell if my IP is blocked in your firewall?. If it is, contact support to have it added to the allowlist.

When you contact support

To get a block fixed quickly, open a support ticket from your Client Area and include:

  • the exact address (URL) of the page, asset, or request being blocked;

  • the date and time it happened;

  • the IP address affected (yours, or the app's or server's);

  • the exact error message and code (for example, 403 or 429).

Turning Imunify Security off entirely is a last resort: it removes a layer of protection from your site, and WHC recommends keeping it on. It's safer to have support tune the specific rule than to disable protection.

Did this answer your question?