Geo Block
37 region presets, soft-block mode, IP allowlist, audit log, "what-if" simulator.
What it does
Built for production from day one.
Per-channel geo-restrictions you can actually understand. Pick from 37 hand-curated region presets (EU, EEA, Schengen, GCC, ANZAC, NATO, OECD, Commonwealth, English-speaking, MENA, ASEAN, Nordic, …) or add countries manually. Soft-block mode for "browse-only" markets. IP allowlist for offices and payment processors. Every block decision is logged for the admin Stats panel.
37 region presets
One-click setups: EU, EEA, EFTA, Schengen, Nordic, DACH, Benelux, Balkans, GCC, MENA, ASEAN, APAC, East Asia, South Asia, LATAM, North America, Caribbean, Oceania, ANZ, G7, G20, BRICS, OECD, NATO, Five Eyes, Commonwealth, English-speaking, and more.
Per-channel rules
Each Vendure channel gets its own rules — perfect for multi-storefront installs (e.g. one UK-only channel, one EU channel).
Soft-block (browse-only)
Mode toggle: full block hides the storefront entirely; soft mode renders it with a banner explaining you don't ship to their country and hiding checkout.
IP allowlist with CIDR
IPs or IPv4 ranges (`203.0.113.0/24`) that bypass every rule. For your office, oncall, monitoring probes, payment processors.
Audit log + stats
Every block decision logged with country, region, IP, UA, channel and reason. Admin Stats tab shows top blocked countries, daily series, and reason breakdown.
"What-if" simulator
Test exactly what your rules will do for a hypothetical visitor — country, UK region, IP — before saving anything to production.
Custom block page
Per-channel message, optional redirect URL and optional logo URL. Or fall back to sensible defaults per block reason.
UK sub-region filter
When GB is allowed, optionally restrict to ENG / WLS / SCT / NIR. Driven from the standard ISO subdivision codes.
Proxy-aware
Reads `cf-ipcountry` / Akamai / Fastly region headers when present. Saves a MaxMind lookup per request.
Scheduled maintenance window
Plugin option for a date-range lockdown — every visitor is blocked (except the IP allowlist) until the window closes.
MySQL, MariaDB & PostgreSQL
The plugin follows whatever database your Vendure `dbConnectionOptions` use — no configuration. Verified against PostgreSQL 17; MySQL/MariaDB installs are unchanged.
Buy & activate from the admin
Start the 14-day free trial, subscribe or buy lifetime from the plugin's admin page — checkout opens in a new tab and the key installs itself within a minute, renewals included. The same card shows your plan, first-charge date and a <strong>Manage billing</strong> link to the Stripe portal (update card, cancel, switch plan). Already have a key? Paste it into the same banner. No `.env` edit, no redeploy; environment keys still take precedence for infrastructure-as-code setups.
One-click in-app updates
When a new version ships, an update banner shows current → latest with a What's-new link to the changelog. "Update now" installs the registry-verified release via your project's own package manager (yarn/npm/pnpm auto-detected) and gracefully restarts under pm2/systemd. Disable with `HULO_SELF_UPDATE=off`.
Install
Four steps, five minutes.
Add the package
Or run the one-line installer that does steps 1–3 for you:
Prefer to do it by hand?
Register it
In your vendure-config.ts:
Compile the admin UI
Add the extension to your compileUiExtensions call so the plugin's page appears in the admin:
Run the migration
The plugin registers its own entities. Generate and run the migration like any other:
That's it. Restart Vendure and the plugin's page is in the admin. Without a key it runs in the free tier; open the page and click Start 14-day free trial to switch everything on — the key installs itself, no .env edit, no redeploy.
Free tier vs licensed
Try the whole thing, keep the core for free.
Install without a key and everything on the left works indefinitely. The 14-day trial switches the right-hand column on with your real traffic; a licence keeps it on.
Free, no key
- Configure regions, rules and allowlists
- "What-if" simulator and audit log in the admin
Trial + licensed
- Live enforcement: the storefront endpoint reports the real decision (free tier always answers enabled: false)
HTTP endpoints
Every route exposed.
/geo-block/site-configPublic: channel rules the storefront polls/geo-block/checkPublic: per-request decision + reason (logs to audit)/geo-block/presetsPublic: the preset catalogue (37 entries)/geo-block/admin/channelsAdmin: list channels with current rules/geo-block/admin/saveAdmin: save a channel's rules/geo-block/admin/statsAdmin: block totals + top countries + daily series/geo-block/admin/simulateAdmin: dry-run a visitor against current rules/geo-block/admin/gcAdmin: prune old audit rows/geo-block/licence/statusAdmin: licence + evaluation + update status/geo-block/licence/activateAdmin: activate a licence key from the admin UI/geo-block/update/runAdmin: one-click in-app update + graceful restartFAQ
Common questions.
How do I get a licence key?
Buy here — Stripe Checkout — monthly, annual (two months free) or lifetime. You'll receive the JWT key by email. Paste it into the plugin's admin settings (Activate) — no redeploy — or set it as HULO_LICENCE_KEY_GEO_BLOCK in your .env if you prefer config-as-code; the env key wins when both are present.
Does it work without a key?
Yes — every subscription starts with a 14-day free trial. Install the plugin, open its admin page and click Start 14-day free trial: a card is required, nothing is charged until day 15, and you can cancel any time before then. The licence installs itself and every premium feature is on for the whole trial with your real traffic.
Which databases are supported?
MySQL, MariaDB and PostgreSQL (verified against PostgreSQL 17). The plugin follows your Vendure dbConnectionOptions automatically — there is nothing to configure.
How do updates work?
The plugin checks the npm registry daily. When a newer version exists, the admin dashboard shows an update banner with a What's-new link to the changelog and an "Update now" button that installs the registry-verified release via your own package manager and gracefully restarts under your process supervisor. Prefer manual control? Copy the install command instead, or set HULO_SELF_UPDATE=off.
Where is data stored?
In your Vendure database. The plugin adds its own tables (created on boot, or via a migration for the plugins that register entities) — your data never leaves your server.
Will it survive a Vendure upgrade?
Tested against Vendure >=3.5.0 <4.0.0 — 3.5, 3.6 and 3.7 are all covered by CI. A boot-time compatibility check emits a non-fatal warning if @vendure/core is outside that range, so upgrades to a future 3.x are safe to try. The 4.0 line will be tested and re-declared once its changelog lands.
Ready to ship?
Install in five minutes, run the trial on real traffic, keep it if it earns its place.