Skip to Content
Website Traffic Control | Visitor Analytics, Threat Detection & IP Blocking icon

Website Traffic Control | Visitor Analytics, Threat Detection & IP Blocking

See who visits your Odoo website and backend, from where, spot hostile visitors and block them: login brute-force protection, block and allow lists, dashboard and reports.

Website Traffic Control | Visitor Analytics, Threat Detection & IP Blocking banner
Odoo Community

Website Traffic Control

See who visits your Odoo website and backend, from where, spot hostile visitors — and block them.

Every request that reaches Odoo is logged with its country, device and result. Explainable rules give each IP address a threat score. Login brute force is blocked automatically; everything else waits for your approval. One dashboard, 10 analyses, 3 PDF reports.

Request LogGeoIPThreat ScoreLogin ProtectionBlock & Allow ListsDashboard
Built for

Website Owners

Odoo Administrators

Security Officers

Marketing & Analytics

Odoo Partners & Hosts

Three roles: Viewer, Analyst and Manager. Only Managers can block or unblock.
Website Traffic Control banner
Every Request
Website, backend, login and API
16 Threat Rules
Editable, explainable, no black box
Auto Login Block
Brute force and password spraying
13 Reports
10 analyses and 3 PDFs

Why This Module

Odoo tells you what your customers bought, not who knocked on the door. A standard installation keeps no usable record of which addresses hit your login page ten thousand times last night, or which country your traffic comes from.

Odoo's own login cooldown lives in the memory of each worker process. With several workers an attacker simply gets several times the attempts, and nothing is recorded. Here the counters live in the database: one count for the whole server, and a block that survives a restart.

Nothing is decided by a black box. An IP is judged by named rules you can read, switch off and re-weight, each hit is stored with its evidence, and blocking anything but login brute force needs a human to approve it.

Traffic Control dashboard with alerts, quick actions, KPI tiles, live requests per minute and requests by class

The dashboard — six tabs, 13 KPI tiles, live charts, an alert board and role-aware Quick Actions. Every tile opens the records behind it.

Request Log

Every request that reaches Odoo: time, IP, method, path, status, duration, size, referrer, browser, website, user and visitor. Split into Website Requests and Web Requests, each with a plain-words description such as “Contact: list records”.

Geolocation

Country, region, city, coordinates and timezone per IP, through Odoo's built-in GeoIP (MaxMind GeoLite2). ISP and ASN when you supply the ASN database. A clear “GeoIP not configured” notice instead of wrong data.

IP Profiles

One profile per address: first and last seen, requests, pages, 404s, failed logins, threat score and status (normal, watch, suspicious, blocked, allowed), with its events, login attempts, rules and a chatter.

Threat Scoring

16 rules: probes for foreign software, path traversal, SQL injection and XSS patterns, scanner tools, 404 bursts, path enumeration, high request rate, fake search bots and a honeypot. Scores decay with a 24-hour half-life.

Block Suggestions

A score above 60 raises a suggestion with its reason and evidence. Block for a chosen time, Watch, Allow-list or Dismiss — one by one, in bulk, or in one click from the dashboard. Every decision is logged.

Login Protection

Every attempt recorded, on the login form and on XML-RPC, JSON-RPC and API keys. 10 failures or 5 different logins in 10 minutes block the IP, escalating 15 min → 1 h → 24 h. Passwords are never stored.

Block & Allow Lists

By IP, CIDR range, country, user-agent pattern or path. Block (403), throttle (429) or log only; whole site, login only, website only or backend only; with start, expiry and reason. The allow list always wins.

Backend Usage

Which app, action, model and record each internal user opens. The backend is a single-page app, so a small web-client service reports each navigation that server logs alone cannot see.

Privacy Built In

IP masking or keyed hashing, sanitised query strings, optional hashed logins, retention per data type with batched cleanup, and a “Forget this IP” tool for data-subject requests.

How You Actually Use It — Step by Step

Ten jobs, in the order you meet them: two to set up, eight you come back to.

1

Set it up — once

Configuration → Settings. Sensible defaults ship with the module, so five minutes is enough.

Run Odoo behind your reverse proxy with proxy_mode on, so the real visitor address is seen. The status block tells you whether it is.

Point geoip_city_db / geoip_country_db at the GeoLite2 files and press Test GeoIP.

Choose what to log, how long to keep it, and whether to mask or hash IP addresses.

Thresholds, login limits, escalation durations, block-page text and notifications are all on this one page.

Traffic Control settings page with status, logging, privacy, detection, login protection, enforcement and notifications

Every policy on one page

2

Give each person a role

Settings → Users. Viewer, Analyst or Manager — each includes the one before.

Viewer: dashboard and summary reports, no individual IP.

Analyst: requests, IP profiles, login attempts, events; can mark a suggestion Watch or Dismiss.

Manager: blocks, unblocks, allow-lists, edits rules and settings.

3

Read the dashboard

Open Traffic Control. The Overview tab puts what needs you first, then the figures.

Alerts: suggestions to review, automatic blocks, suspicious IPs, failed logins, server errors and configuration problems.

13 KPI tiles with the change against the previous period; a LIVE tile and a live requests-per-minute chart.

Filter by period, website and traffic class; include or exclude bots. Auto-refresh every 60 seconds, pausable.

Dashboard traffic tab with requests over time by visitor type, device types, top countries and sources

Traffic tab: visitor types, devices, countries, referrers, browsers, systems and bots

Dashboard content tab with top pages, entry pages, exit pages, 404 paths and slowest pages

Content tab: top, entry and exit pages, 404s and slowest pages

4

Look at the requests

Monitoring → Website Requests and Web Requests.

The Request column says what was asked in plain words; the technical path sits beside it.

Blocked lines are red, suspicious ones orange, errors grey. Duration is in seconds.

Filter by blocked, suspicious, errors, 404, class; group by IP, path, status, user or day.

Website requests list with date, IP, country, request description, path, status and duration

Website Requests

Web requests list showing backend calls described in plain words

Web Requests: backend, login and API calls

5

Open an IP profile

Monitoring → IP Profiles. Everything about one address on one page.

Location, ISP, activity totals, threat score and status.

Tabs for its threat events, login attempts and rules; a chatter for notes and automatic-block messages.

Buttons: Block, Unblock, Watch, Refresh Location, Forget this IP — and a printable Security Incident Report.

IP profiles list coloured by status

IP Profiles, coloured by status

IP profile form with location, network, activity and threat sections

One IP profile

6

Decide the suggestions

Security → Suggestions. The module proposes; you decide.

Each suggestion carries its score, the rules that fired and the evidence.

Block for 15 minutes up to permanent, on the whole site or one part of it; or Watch, Allow-list, Dismiss.

Tick several and decide them together. The decision is written in the chatter.

Block suggestions list with score and reason

Suggestions waiting for a decision

Dashboard security tab with threat levels, events by rule, failed logins, top threat IPs, automatic blocks and pending suggestions

Security tab: decide in one click

7

Block an IP, a range or a country

Security → Block an IP, Range or Country.

Choose the action (403, 429 or log only), the scope and the duration.

Your own IP is shown; blocking it needs an explicit confirmation.

Rules that expire are archived automatically, so the history stays.

Block wizard with match type, action, scope and duration

The Block window

Block and allow list with match type, action, scope, source, expiry and hit count

Block & Allow List with hit counts

8

Let login protection work

Nothing to do: it is on from installation.

Unknown logins and wrong passwords both count, on every channel.

The block is login-only by default, so the public website stays reachable.

Managers are notified, and after the last escalation step a permanent block is suggested rather than applied.

Login attempts list with result and failure reason

Every login attempt, never the password

9

Import and export lists

Security → Import IP List / Export Block List.

Import one IP or CIDR range per line from a text or CSV file; duplicates and invalid lines are reported.

Export as an nginx deny snippet, a plain list or CSV, to stop the traffic before it reaches Odoo.

10

Analyse and report

Reporting, or the dashboard's Reports tab.

Ten pivot / graph analyses reading pre-computed aggregates, so they stay fast after months of data.

Standard spreadsheet export from every pivot; raw log export by period.

Daily and weekly summary PDFs; the weekly one can be e-mailed to a group.

Dashboard report center listing analyses and PDFs in four groups

Report Center

Traffic analysis as a chart

Traffic analysis

Security analysis pivot per rule and severity

Security analysis

Three Roles — Only Managers Block

Access is declared on the access rights themselves. Public and portal users have no access at all to these models; the request pipeline writes with its own privileges on its own cursor.

Viewer
Dashboard and aggregate reports. Never sees an individual IP address.
Analyst
Raw requests, IP profiles, threat events, login attempts and suggestions. Marks a suggestion Watch or Dismiss and leaves notes.
Manager
Everything: blocks and unblocks, allow-lists, threat rules, imports and exports, purge, forget an IP, and settings.

13 Reports in Four Groups

Analyses open as pivot tables and graphs you can filter, group and export. They read hourly and daily aggregates built every 15 minutes, never the raw log.

Traffic (4)

Traffic analysis (hour, website, class, country, device), page analysis (views, entries, exits), geo analysis (country, region, city), bot report (verified or not).

Quality (3)

Error report (status and path), performance report (average, maximum and p95 response time), backend app usage (user, app, model).

Security (3)

Security report (rule, severity, country), login attempt analysis (IP, login, result), visitor / IP analysis per day.

Printable PDF (3)

Daily and weekly traffic summary, block list snapshot — plus a security incident report for any one IP.

Exports (4)

Spreadsheet export from every pivot, raw log CSV by period, block list as nginx snippet, plain list or CSV.

By e-mail (1)

The weekly summary PDF, sent to the group you choose.

Backend Activity — What Your Own Team Uses

The Backend tab ranks the apps, actions and models your internal users open, and activity per user. Each row drills into the Backend App Usage analysis.

Dashboard backend tab with top apps, actions, models and activity by user

Printed Documents

Four PDFs, from the Reporting menu or the Print menu of a record.

Daily Traffic Summary
Key figures of the last 24 hours against the 24 before, top countries, pages, 404 paths and threat rules.
Weekly Traffic Summary
The same over 7 days. Can be e-mailed every week.
Security Incident Report
One IP: profile, threat events, login attempts and the actions taken.
Block List Snapshot
Every block and allow rule in force, with scope, source, expiry and hit count.

Your Policy, Not Ours

Score thresholds and half-life, each rule's points and action, login limits and escalation, block scope, sampling, retention and anonymisation — all settings and editable records, not code.

Hard to Lock Yourself Out

The allow list is checked first. Private and loopback addresses are never blocked unless you ask. Blocking your own IP needs a confirmation. One system parameter switches all enforcement off from the shell.

Light on the Server

Block decisions are made in memory from cached rules. Log rows are one raw insert on a separate short transaction, with optional buffering and sampling. Counters live in an unlogged table shared by all workers.

Built on Odoo, Not Beside It

Uses Odoo's own GeoIP reader and the Website app's visitors instead of duplicating them. Standard list, pivot and graph views everywhere, so filters, favourites and exports behave as you expect.

Built to Fit Your Odoo

Edition:
Odoo Community
Dependencies:
Website, Discuss
Category:
Website
License:
OPL-1

No Enterprise module is required. For locations, install the free MaxMind GeoLite2 databases and set geoip_city_db / geoip_country_db; no database is shipped with the module. Run Odoo behind a reverse proxy with proxy_mode = True, otherwise every visitor has the address of the proxy. A beginner's user manual (PDF) is included in the doc folder.

Deliberately not included: network-level DDoS protection (Odoo only sees traffic that passed the proxy — use the nginx export for that layer), logging of static files that the proxy serves directly, paid threat-intelligence feeds, and a world map (Odoo Community has no map widget; countries are shown as a ranked table with flags).

IP addresses are personal data under GDPR and similar laws. The module gives you anonymisation, retention and erasure tools; choosing settings that meet your own legal obligations remains your responsibility.

Support & Developer Details

For installation help, customization, extra threat rules, custom reports or implementation support, contact the maintainer.

Name:
Abdullah Al Arafat
Mobile/Whatsapp:
+8801712192445
Email:
imbipul9@gmail.com