Skip to main contentSkip to footer
WordPress Security Plugin · Community Threat Network · Made in Germany

Stop brute-force attacks before they reach WordPress

Every attack on one site in the network protects all the others. Sixteen sensors, a firewall and four ways to do two-factor login, in a plugin that is free and open source. Built and hosted in Germany.

Free and open sourceAll 16 sensors, nothing held backEU-only infrastructure

What ReportedIP does

Someone tries to break into a website in Rotterdam. Ninety seconds later that same attacker is blocked on a site in Lisbon that has never seen them before.

That is the whole idea. When a site running our plugin, a honeypot (a fake site that exists only to record who attacks it) or a firewall gets attacked, it reports the attacking IP address. Every other site on the network gets that address straight away. About 803,000 addresses are known this way, from 7.2 million reports. The more sites join, the earlier each one sees an attacker coming.

You get that knowledge in two shapes: Hive, a plugin that does it for your WordPress site, and the agent, which does it for the Linux server underneath.

  1. A site gets attacked. Someone hammers the login form, floods the comments or scans for a known hole.
  2. The address is reported. Only the attacker’s IP and what it did. No visitor data, no content, nothing about the site itself.
  3. Everyone else is warned. The address gets a score from 0 to 100, how sure the network is that it attacks people, and every connected site can act on it.
  4. Your site blocks it on arrival. Before the login page loads, before the comment form is reached, before anything is tried.

What Hive does on your site

Install the plugin, run the quickstart, and it works. Free forever in Local Shield mode, on as many sites as you like.

Attackers are turned away before the login form loads

The address is checked against what the network has already seen. Someone who was hammering a site in Rotterdam an hour ago never reaches a password prompt here.

Every kind of attack has its own sensor

Failed logins, password spray, comment spam, XML-RPC, scanners and bait paths are each detected separately. An address that keeps trying is blocked for longer every time, instead of being released after a fixed number of attempts.

Two-factor login that also covers the password reset

Authenticator app, e-mail, SMS or a hardware key. The reset link sits behind the same check, so a stolen mailbox is not a way around it.

Get Hive for WordPress

What the agent does on your Linux server

For hosters and admins who run web, mail, FTP and DNS on the same machines. The agent puts the community blocklist into the kernel firewall and reports the attacks it finds in the logs your server already writes. One static binary, one command to install.

The whole list, in your kernel

Thousands of addresses that attacked other servers this morning are dropped in ipset or nftables before their first attempt reaches you. Five sets by service, so an address known for attacking mail servers is blocked on your mail ports and nowhere else.

It reads the logs you already have

Thirteen log sources across web, mail, FTP, DNS and the control panel. The installer finds them itself and writes the configuration. Every local find is reported, so the next operator is spared it.

Nothing about your traffic leaves the machine

A report is an address, a threat category and one generated sentence. No log line, no user name, no request body, no URL. The host starts in log mode, so you read for a week what would have been dropped before anything is.

One server is included from Professional, three with Business. Further servers are a monthly licence, and servers do not count against your domains. View pricing.

Get the Linux agent

Plans for every site

The protection is free forever. Professional covers three WordPress sites and one Linux server, Business fifteen sites and three servers. The full feature comparison is on the pricing page.

Free

Local protection, free forever

Free
  • Full Hive plugin, all 16 sensors and the 2FA suite
  • 1 domain, no server licence
  • 1,000 API checks and 50 reports a day

Business

Agencies, WooCommerce, white-label

32.42 € / monthincl. 19 % VATbilled yearly: 389.00 €
  • 15 domains and 3 Linux servers, bookable 2 to 20 times
  • Every client site in one dashboard, white-label
  • 100,000 API checks and 5,000 reports a day
Get Hive Business

14-day money-back guarantee. Cancel anytime.

View pricing

Includes Contributor and Enterprise tiers plus the full feature comparison table.

The Professional plan works out at 4.97 € per domain per month. Wordfence, Solid Security and WP 2FA charge around 8.30 € for a single domain, and none of them include mail or SMS delivery. See the full comparison.

Just need the data, not a product? The same list is available as a REST API, a blacklist feed and a DNS/RBL zone for mail servers, with 1,000 checks a day for free. See all products.

Check any IP address

Free, no signup required. Find out whether the network has seen this address attacking anyone, how often, and where it comes from.

Check IP Address

Live data, refreshed continuously

Every IP that gets reported is scored, weighted, and made available through the public API and blacklist feed. These numbers update in real time. See the latest WordPress Attack Report for the full quarterly breakdown.

ReportedIP Statistics

803,618
Total IPs
7,218,214
Total Reports
123,926
Active Threats
29,966
Reports last 24h

Frequently asked questions

Common questions about the plugin, the agent and the platform. Plugin-specific questions live on the plugin page; the full FAQ is at /docs/support/faq/.

Is the ReportedIP Hive WordPress plugin free, and what does PRO add?

The Hive WordPress security plugin is free and open source under GPL-2.0, with all 16 attack sensors, the Web Application Firewall and four-method two-factor authentication. Hive PRO is an optional subscription on top: it connects your sites to the managed, EU-hosted 2FA relay for SMS and e-mail codes, no Twilio account, no API keys, with 25 SMS and 500 e-mails per month included, and one licence covers three domains and one Linux server. Agencies and shops with more sites take Business, which covers fifteen domains and three servers. The plugin itself stays free; the paid plans only add the managed services. See the pricing page for current plans.

How is Hive different from Wordfence?

Three differences. First, nothing is held back: all 16 sensors, the firewall engine and the full 2FA suite are free in every mode, while Wordfence delays new firewall rules for free users by 30 days. Second, two-factor codes by e-mail and SMS are delivered through our EU relay with its own SPF, DKIM and DMARC reputation, so a code arrives even when your shared host’s mail does not, and no Twilio account is needed. Third, the whole service is built and hosted in Germany under EU data-protection law, with a data-processing agreement on offer. Wordfence remains the better answer if you need malware scanning of your files, which Hive does not do. See the full Wordfence comparison.

What does the agent do on my Linux server?

The ReportedIP Agent is a single static binary for Linux servers. It downloads the community blocklist and keeps it in your kernel firewall as ipset or nftables sets, split by service, so an address known for attacking mail servers is dropped on your mail ports only. At the same time it watches the logs your server already writes, thirteen source types across web, mail, FTP, DNS and the control panel, and reports the attacks it finds, so the next operator is spared them. It sends the address, the threat category and one generated sentence, never a log line, a user name or a URL. One server is included from Professional, three with Business; further servers are a monthly licence. The host starts in log mode, so you can read for a week what would have been blocked before anything is.

Is the data and infrastructure EU-hosted?

Yes. ReportedIP is operated by a German company (CMS ADMINS, Munich) and all processing runs on German infrastructure under EU data-protection law (GDPR). Every sub-processor is EU-based: the managed reportedIP mail / SMS relay, Stripe Payments Europe (Ireland) for billing, and sevDesk (Germany) for invoicing. No personal data leaves the EU, and a data-processing agreement is available for business customers. IP addresses in reports are handled as the minimum necessary for the security purpose and aged out over time. For teams with a compliance requirement to keep threat-intelligence data inside the EU, this is the core reason they pick ReportedIP over US-hosted alternatives.

How is an IP’s confidence score calculated?

Every IP carries a confidence score from 0 to 100 that estimates how likely it is to be malicious. Five weighted components feed it: the number of reports, reporter diversity (independent sources count for more than one noisy reporter), recency (reports under 24 hours old weigh most), the severity of the threat category, and a bonus for reports confirmed by verified honeypots. Reports decay exponentially on a 30-day half-life, after 30 days a report carries half its weight, after 60 days a quarter, so an IP that stops attacking is delisted automatically. An IP needs at least five reports to exceed 50 and ten to pass 75. Add verbose=true to any check to see the full breakdown.

Do I need an account to check an IP?

No. The IP check on this page is open to everyone and needs no signup; it is rate-limited to 100 lookups per IP per day to keep it free and abuse-resistant. That is enough for occasional manual checks when you spot a suspicious address in your logs. For programmatic access, scripting, automated ban actions, bulk work or anything that runs on a schedule, create a free account, which raises the limit to 1,000 checks and 50 reports per day and gives you an API key plus a usage dashboard. Higher tiers lift the quotas further and add bulk endpoints and multi-site management.

Get started: free forever

Get Hive for your WordPress site, get the agent for your Linux servers, or create a free account for the API. No credit card, no commitment.

Security focusedGDPR compliantMade in GermanyOpen source where possible

Where attacks come from

Aggregated, anonymised attack origins from honeypots, sensors, and contributors worldwide. Refreshed every 30 minutes.

Loading attack map...

Latest from the blog

Release notes, threat-intelligence reports, and practical security guidance from the team that runs the network.