Skip to main contentSkip to footer
Open IP Threat Intelligence Platform

Block attackers your site has never seen before

Every attack on one site in the network protects all the others. Free for WordPress through the Hive plugin, and free as an API, blacklist or DNS lookup for everything else. Built and hosted in Germany, GDPR compliant.

No signup for the basic check1,000 free API checks / dayEU-only infrastructure

What ReportedIP does

Someone tries to break into a website in Rotterdam. Ninety seconds later that same attacker is blocked on a site in Lisbon that has never seen them before.

That is the whole idea. When a site running our plugin, a honeypot (a fake site that exists only to record who attacks it) or a firewall gets attacked, it reports the attacking IP address. Every other site on the network gets that address straight away. About 723,000 addresses are known this way, from 6.6 million reports. The more sites join, the earlier each one sees an attacker coming.

You can use that knowledge in whatever shape fits your setup: as a WordPress plugin that does it for you, as an API you call yourself, as a list you drop into your firewall, or as a DNS lookup for your mail server.

  1. A site gets attacked. Someone hammers the login form, floods the comments or scans for a known hole.
  2. The address is reported. Only the attacker’s IP and what it did. No visitor data, no content, nothing about the site itself.
  3. Everyone else is warned. The address gets a score from 0 to 100, how sure the network is that it attacks people, and every connected site can act on it.
  4. Your site blocks it on arrival. Before the login page loads, before the comment form is reached, before anything is tried.

Check any IP address

Free, no signup required. Find out whether the network has seen this address attacking anyone, how often, and where it comes from.

Check IP Address

Live data, refreshed continuously

Every IP that gets reported is scored, weighted, and made available through the public API and blacklist feed. These numbers update in real time. See the latest WordPress Attack Report for the full quarterly breakdown.

ReportedIP Statistics

723,384
Total IPs
6,608,654
Total Reports
96,086
Active Threats
23,582
Reports last 24h

Four ways to get it

The plugin if you run WordPress, the API if you write your own code, the blacklist if you would rather feed a firewall, the DNS zone if it is your mail server that needs it. Same data behind all four, plus two free tools that use it.

WordPress Security Plugin · Free + PRO

ReportedIP Hive

Real-time WordPress security from the hive. Pick the Full Edition (GitHub) for sixteen sensors, each watching one way in such as the login form or the comment box, plus a firewall that drops requests shaped like an attack, four-method 2FA with official YubiKey hardware-key support, and multisite, or grab the Light Edition from WordPress.org for focused brute-force protection. Free and open source either way. Professional sites upgrade to Hive PRO for our EU mail and SMS servers, so two-factor codes actually arrive (25 SMS and 500 e-mails a month included, no Twilio account) and one licence covering three domains.

  • Full: 16 attack sensors incl. WAF + four-method 2FA + multisite
  • Light: brute-force login protection, zero-config, on wp.org
  • Both: progressive block ladder, community threat lookup, and Local Shield mode, which runs offline so nothing leaves your site
  • PRO: managed EU 2FA relay (SMS + e-mail), one licence for 3 domains

Public REST API · Free Tier

Public API

The reputation engine behind everything. Query individual IPs, submit reports, pull the community blacklist, run bulk operations from any language or system, fail2ban, SIEM, custom firewalls, hosting panels.

  • 1,000 free checks per day, 50 reports per day
  • 30 threat categories, decay-weighted scoring
  • Bulk operations & analytics on Pro+

Community Blacklist · Free Tier

Blacklist Feed

Community-driven blacklist, automatically scored from real-time reports. Plain text, JSON, and CSV, ready to drop into fail2ban, iptables, nginx, Postfix, or any blocklist consumer.

  • Confidence ≥ 75 % threshold, 48 h false-positive cool-down
  • TXT, JSON, CSV, plus 9 thematic lists (spam, brute-force, …)
  • Git mirror, daily refresh, diff-friendly commit history

DNS Blocklist (RBL) · Paid add-on

DNS / RBL Zone

Ask a DNS question instead of downloading a list: your mail server or firewall looks each address up live, the same way it already queries Spamhaus. A private, token-authenticated zone (bl.reportedip.de) answers reverse-IP lookups with 127.0.0.x codes, no API client, no integration code.

  • RFC 5782 compliant: IPv4 and IPv6, Postfix / Rspamd / BIND RPZ
  • 100,000 queries/day per token, answers cached for 30 minutes
  • Category sub-zones (spam, brute-force, web-attacks, …)

DNS Diagnostics · Free

DNS Checker

Domain health diagnostics from 76 DNS servers across 6 continents. Validate SPF, DKIM, DMARC, and DNSSEC, run DNSBL lookups, and track DNS propagation during migrations.

  • Global propagation check from 76 resolvers
  • SPF / DKIM / DMARC / DNSSEC validation
  • DNSBL lookup against 15 major blocklists

Standalone PHP App · Free

Honeypot Server

A standalone PHP application that pretends to be WordPress, Drupal, or Joomla. 36 built-in threat analyzers detect SQLi, XSS, brute force, credential stuffing, plugin exploits, and feed clean data back into the network.

  • Docker Compose ready, PHP 8.2 + SQLite
  • 36 threat analyzers, severity-scored
  • Reports auto-batched to ReportedIP API

See all products →

Built for the people protecting the internet

Whatever your role, we have a free entry point. Use one product or chain several together.

WordPress site owners

Install Hive in 5 minutes, up to 16 attack sensors, a Web Application Firewall and four-method 2FA, free and open source in both editions. Hive PRO adds the managed EU 2FA relay and covers three domains with a single licence.

Compare editions →

Hosting providers

Bulk-check incoming IPs via the API before they hit your customers. Pull the community blacklist into your edge firewall daily. Higher quotas on Pro+.

API reference →

Sysadmins & DevOps

Drop the blacklist into fail2ban, iptables, nginx, or Postfix. Plain text, JSON, hourly refresh. Free tier covers most use cases out of the box.

Blacklist docs →

Security researchers

Run our standalone PHP honeypot on any VPS: 36 threat analyzers, all detections feed back into the public reputation engine. You contribute, the whole community benefits.

Honeypot docs →

Plans for every site

The Hive plugin is free and open source forever, and the free tier already includes the public API with 1,000 checks a day. Paid plans add managed 2FA mail and SMS relay, multi-site management, and higher API quotas.

Free

Local protection, free forever

Free
  • Full local Hive plugin, all 16 attack sensors
  • Web Application Firewall (engine + OWASP-Top-10 baseline ruleset)
  • Verified-bot detection, disposable-email blocking & comment honeypot
  • Basic security headers + protection & hardening score
  • Block-page reference codes & MainWP integration
  • Complete 2FA suite (TOTP, Email, WebAuthn incl. one YubiKey / security key per account)
  • 1,000 API checks / day
  • 50 reports / day
  • 1 domain
  • Community support

Business

Agencies, WooCommerce, white-label

32.42 € / monthincl. 19 % VATbilled yearly: 389.00 €
  • Everything in Professional
  • Covers 15 client sites on one licence 2.60 € per site per month, bundle it into your care plan
  • Book 2 to 20 licences on one bill Quota, 2FA mail, SMS and domains all multiply, up to 15 % volume discount, 20 licences means 300 sites
  • Run every client site from one dashboard One settings policy, per-site overrides, one-click push and drift detection
  • Your brand, not ours White-label setup wizard, 2FA pages and mail templates
  • 100,000 API checks and 5,000 reports a day 2,500 2FA mails and 75 SMS a month included
  • WooCommerce end to end White-label templates plus Subscriptions and Memberships audit
  • Proof for your compliance questions Append-only audit trail of logins, password resets and role changes with CSV and JSON export, plus GDPR export tool
  • Backup security keys per user Multiple WebAuthn keys, model detection, key-lifecycle alerts
  • Priority support, 12 h SLA
Get Hive Business

14-day money-back guarantee. Cancel anytime.

View pricing

Includes Contributor and Enterprise tiers plus the full feature comparison table.

Frequently asked questions

Common questions about the API, blacklist, and the platform as a whole. Plugin-specific questions live on the plugin page; the full FAQ is at /docs/support/faq/.

How do I integrate the API into fail2ban or iptables?

Two paths, depending on how fresh you need the data. For broad coverage, pull the community blacklist feed directly, an hourly-refreshed text file you can drop into an ipset with a single cron job, no API key required. For per-IP scoring at the moment of a request, for example inside a fail2ban action or a custom firewall rule, call the REST API with a free account (1,000 checks per day). We publish working fail2ban filter examples and a ready-to-run iptables ipset script in the documentation, plus nginx and Postfix snippets. Most operators combine both: the feed for bulk blocking, the API for real-time decisions on traffic that is not yet on the list.

How is an IP’s confidence score calculated?

Every IP carries a confidence score from 0 to 100 that estimates how likely it is to be malicious. Five weighted components feed it: the number of reports, reporter diversity (independent sources count for more than one noisy reporter), recency (reports under 24 hours old weigh most), the severity of the threat category, and a bonus for reports confirmed by verified honeypots. Reports decay exponentially on a 30-day half-life, after 30 days a report carries half its weight, after 60 days a quarter, so an IP that stops attacking is delisted automatically. An IP needs at least five reports to exceed 50 and ten to pass 75. Add verbose=true to any check to see the full breakdown.

Where can I download the blacklist?

Plain-text and JSON exports are served from /wp-json/reportedip/v2/blacklist; add ?format=txt for one IP per line or ?format=csv for spreadsheets and SIEM imports. The same data is mirrored to Git at github.com/reportedip/reportedip-blacklist with a diff-friendly commit history, so you can track exactly which IPs were added or removed each day and pin a specific revision if you need reproducible builds. The feed is free for any use and attribution is appreciated. Entries are scored by the same confidence engine as the API, so a single threshold keeps your block list both current and low on false positives.

Can I query the blacklist over DNS (RBL/DNSBL)?

Yes. The DNS / RBL Zone add-on gives you a private, token-authenticated zone, <token>.bl.reportedip.de that any mail server, firewall or spam filter can query exactly like Spamhaus or any other DNSBL. It follows RFC 5782, covers both IPv4 and IPv6, and returns the usual 127.0.0.x response codes so existing Postfix, Exim or rspamd configurations work without custom glue. Because lookups happen over DNS they are cached by your resolver and add almost no latency to mail flow. The zone is rebuilt from the same scored dataset as the public feed, and each token has its own daily query quota.

Is the data and infrastructure EU-hosted?

Yes. ReportedIP is operated by a German company (CMS ADMINS, Munich) and all processing runs on German infrastructure under EU data-protection law (GDPR). Every sub-processor is EU-based: the managed reportedIP mail / SMS relay, Stripe Payments Europe (Ireland) for billing, and sevDesk (Germany) for invoicing. No personal data leaves the EU, and a data-processing agreement is available for business customers. IP addresses in reports are handled as the minimum necessary for the security purpose and aged out over time. For teams with a compliance requirement to keep threat-intelligence data inside the EU, this is the core reason they pick ReportedIP over US-hosted alternatives.

Do I need an account to check an IP?

No. The IP check at the top of this page is open to everyone and needs no signup; it is rate-limited to 100 lookups per IP per day to keep it free and abuse-resistant. That is enough for occasional manual checks when you spot a suspicious address in your logs. For programmatic access, scripting, fail2ban actions, bulk work or anything that runs on a schedule, create a free account, which raises the limit to 1,000 checks and 50 reports per day and gives you an API key plus a usage dashboard. Higher tiers lift the quotas further and add bulk endpoints and multi-site management.

How is this different from AbuseIPDB or Spamhaus?

Three concrete differences. First, ReportedIP is EU-hosted with explicit GDPR compliance and EU-only sub-processors, with a data-processing agreement on offer. Second, the scoring is fully transparent: add verbose=true to any check and you see every component of the confidence score, report count, diversity, recency, severity, honeypot bonus, rather than an opaque number. Third, the clients are open source where they can be: the WordPress plugins (Hive and Hive Light), the honeypot server and the DNS checker are GPL-2.0 and auditable on GitHub or wp.org. Scoring is time-decayed on a 30-day half-life with a configurable honeypot weighting, so dormant attackers fall off automatically and synthetic intel stays trustworthy. See the full ReportedIP vs. AbuseIPDB comparison.

Can I contribute data without running a honeypot?

Yes. Any system can submit reports via POST /reportedip/v2/report with a free API key, a fail2ban-style automated reporter running on your own server is exactly the kind of contribution the network is built on. Honeypot operators get a special badge and their reports carry extra weight, because honeypot traffic is unsolicited and therefore high-signal, but you do not need one to take part. Reporter diversity is itself a scoring factor, so every independent source you add makes the whole dataset more reliable. Just register a free account, generate a key, and point your existing log-watching tooling at the report endpoint.

Is the ReportedIP Hive WordPress plugin free, and what does PRO add?

Both editions of the Hive WordPress security plugin are free and open source under GPL-2.0: the Full Edition on GitHub with 16 attack sensors incl. a Web Application Firewall and four-method two-factor authentication, and the Light Edition on WordPress.org for focused brute-force protection. Hive PRO is an optional subscription on top of the Full Edition: it connects your sites to the managed, EU-hosted 2FA relay for SMS and e-mail codes, no Twilio account, no API keys, with 25 SMS and 500 e-mails per month included, and one licence covers three domains. Agencies and shops with more sites take Business, which covers fifteen. The plugin itself stays free; the paid plans only add the managed services. See the pricing page for current plans.

Get started: free forever

Pick your entry point: create a free account for API access, get Hive for your WordPress site, or read the documentation first. No credit card, no commitment.

Security focusedGDPR compliantMade in GermanyOpen source where possible

Where attacks come from

Aggregated, anonymised attack origins from honeypots, sensors, and contributors worldwide. Refreshed every 30 minutes.

Loading attack map...

Latest from the blog

Release notes, threat-intelligence reports, and practical security guidance from the team that runs the network.