Skip to main contentSkip to footer
Offene Threat Intelligence-Plattform für IP-Netzwerke

IP-Threat Intelligence-Produkte für WordPress, E-Mail und DNS

Eine von der Community betriebene Reputationsdatenbank, die auf sechs verschiedene Arten bereitgestellt wird – als WordPress-Plugin, als REST API, als herunterladbare Blacklist, als Live-DNS / RBL Zone, als DNS Checker und als Honeypot. Nutzen Sie ein einzelnes Produkt oder kombinieren Sie mehrere; jedes Produkt verfügt über eine Free tier und wird auf einer Infrastruktur in der EU betrieben.

311k+
Verfolgte IP-Adressen
5,5M+
Community Reports
30
Threat Categories
Free tier in allen Bereichen Hosting in der EU, GDPR Compliant Open Source, soweit möglich

Ein Datensatz, vielfältige Nutzungsmöglichkeiten

Jedes Produkt liest aus derselben Reputations-Engine (und speist diese). Sie arbeiten zusammen, sind jedoch nie voneinander abhängig – wählen Sie das Bereitstellungsformat, das zu Ihrer Infrastruktur passt.

Erkennen und melden. Das Hive-Plugin und der Honeypot überwachen den tatsächlichen Datenverkehr und übermitteln die IP-Adressen der Angreifer an das Netzwerk.

Bewertung und Speicherung. Die Reputations-Engine gewichtet jeden Report nach Aktualität, Vielfalt und Schweregrad zu einem einzigen Confidence Score (0–100 %).

Überall nutzen. Rufen Sie die Daten über die API, den Blacklist Feed oder die DNS / RBL Zone ab – in WordPress, Ihrer Firewall oder Ihrem Mailserver.

Trends erkennen. Jedes Quartal erstellen wir aus demselben Datensatz einen WordPress Attack Report – mit gemessenen Angriffsvolumina, den häufigsten Techniken und bemerkenswerten Vorfällen, der unter CC BY 4.0 Free zitiert werden darf.

Sechs Produkte, eine Mission

Von einer schlüsselfertigen WordPress-Installation über eine programmatische API bis hin zu einer DNSBL für Mailserver.

WordPress Plugin · Free

ReportedIP Hive

Real-time WordPress security with 16 detection sensors, a Web Application Firewall, four 2FA methods and an opt-in community threat network. Free and open source forever.

REST Threat Intelligence · Free tier

Public API

The reputation engine behind everything. Query IPs, submit reports, pull the blacklist and run bulk operations from any language — fail2ban, SIEM, firewalls, hosting panels.

Downloadable Feed · Free

Community Blacklist Feed

Community-driven blacklist, automatically scored from real-time reports. Plain text, JSON and CSV — ready for fail2ban, iptables, nginx or any blocklist consumer.

Live DNSBL Add-on · from PRO

DNS / RBL Zone

Query the community blacklist as a live DNSBL straight from your mail server or firewall. Token-authenticated zone, 127.0.0.x return codes — no imports, always fresh.

DNS Diagnostics · Free

DNS Checker

Domain health diagnostics from 76 resolvers across 6 continents. Validate SPF, DKIM, DMARC and DNSSEC, run DNSBL lookups and track propagation during migrations.

Standalone PHP App · Free

Honeypot Server

A standalone app that pretends to be WordPress, Drupal or Joomla. 36 threat analyzers detect SQLi, XSS, brute force and exploits, then feed clean intel back into the network.

In Kürze

Weitere Integrationen

Drupal- und Joomla-Adapter sowie Cloudflare-Edge-Integrationen sind in Planung. Möchten Sie Prioritäten mitgestalten oder einen CMS-Adapter sponsern?

Welches Produkt benötigen Sie?

Gehen Sie von der Aufgabe aus, die Sie erledigen möchten.

Ihr ZielVerwendung
Protect a WordPress site ReportedIP Hive
Block IPs at your mail server (SMTP) DNS / RBL Zone
Reputation checks in fail2ban, SIEM or a firewall Public API
Drop a static blocklist into iptables / nginx Blacklist Feed
Diagnose SPF / DKIM / DMARC / DNS DNS Checker
Generate first-party attacker intelligence Honeypot Server

WordPress Plugin · Free

ReportedIP Hive

A turnkey WordPress security plugin. Install it, run the 10-step wizard, and your site blocks brute-force, spam, scanner and injection traffic in minutes — either fully offline (Local Shield) or wired into the community threat network.

  • 16 attack sensors: failed logins, password spray, comment spam, XML-RPC, scanner and decoy bait-paths
  • Web Application Firewall, verified-bot detection, disposable-email blocking and a comment honeypot — free on every plan
  • Four 2FA methods — TOTP, e-mail, SMS and WebAuthn / passkeys
  • Local Shield mode runs 100 % offline — no account, zero outbound calls
  • Community Network mode adds live reputation lookups and Priority-Sync firewall rules via a free key
  • WooCommerce front-end 2FA, multisite, coordinated-attack hardening and a Business audit event trail

Für wen ist es gedacht?

Anyone running one or many WordPress sites who wants managed protection without a SaaS lock-in.

Preise

Free · GPL-2.0+ · paid plans from 14,90 €/mo for managed 2FA relay & higher quotas

REST Threat Intelligence · Free tier

Public API

A clean REST API over the same community reputation database. Check a single IP, report attackers, or pull the whole blacklist — from any stack, in any language.

  • 1,000 free checks/day and 50 reports/day on the free tier
  • 30 threat categories with decay-weighted confidence scoring
  • Bulk check & report plus analytics on Professional and above
  • Simple key auth; JSON responses; documented rate limits
  • Drop-in for fail2ban actions, SIEM enrichment and custom firewalls

Für wen ist es gedacht?

Developers and ops teams integrating reputation checks into existing tooling.

Preise

Free tier · higher quotas on PRO (25k checks/day) and Business (100k/day)

Downloadable Feed · Free

Community Blacklist Feed

The high-confidence subset of the community dataset, published as a static feed you import on your own schedule. No mapping, no scoring on your side — just a clean list.

  • Confidence ≥ 75 % threshold with a 48 h false-positive cool-down
  • TXT, JSON and CSV exports, plus 9 thematic sub-lists
  • Daily Git mirror with a diff-friendly commit history
  • Pull on demand through the API or as a flat file

Für wen ist es gedacht?

Admins who prefer importing a list into iptables, nginx, CrowdSec or a WAF.

Preise

Free to read; access scales with your API plan

Live DNSBL Add-on · from PRO

DNS / RBL Zone

The same blacklist served over DNS as a private RBL zone. Add one string to Postfix, Rspamd or BIND RPZ and reject connecting attackers in real time — the way mail servers expect.

  • Private zone string <token>.bl.reportedip.de with 127.0.0.2/3 return codes
  • Drop-in for Postfix, Rspamd, BIND RPZ and any RBL-capable software
  • Per-category sub-zones (spam, brute-force, malware …)
  • 100,000 DNS queries/day per token; resolver caching keeps it fast
  • Refreshed from the community blacklist every few minutes

Für wen ist es gedacht?

Mail and hosting operators filtering SMTP traffic at the connection layer.

Preise

7,90 € / month or 79 € / year (incl. VAT) — bookable from the PRO plan

DNS Diagnostics · Free

DNS Checker

A free, no-login tool to debug mail and DNS configuration: global propagation, e-mail authentication records and blocklist status in one place.

  • Global propagation check from 76 resolvers worldwide
  • SPF / DKIM / DMARC / DNSSEC validation
  • DNSBL lookup across 60+ public blocklists
  • Migration mode to watch records flip live

Für wen ist es gedacht?

Anyone debugging deliverability, a DNS migration or a new mail setup.

Preise

Free, no account required

Standalone PHP App · Free

Honeypot Server

Run a decoy to generate first-party attacker intelligence. It looks like a vulnerable CMS, scores every request, and batches verified reports to the API.

  • Docker Compose ready — PHP 8.2 + SQLite, no external database
  • 36 severity-scored threat analyzers
  • Mimics WordPress, Drupal and Joomla endpoints
  • Reports auto-batched to the ReportedIP API

Für wen ist es gedacht?

Operators and researchers who want to contribute (and see) fresh attack data.

Preise

Free · open source

Tarife & Preise

Kostenloser lokaler Schutz auf Dauer. Sie zahlen nur für verwaltete Server, höhere Kontingente und Add-ons.

Pläne für jeden Standort

Das Hive-Plugin ist dauerhaft kostenlos und Open Source. Die kostenpflichtigen Tarife umfassen einen verwalteten 2FA-Mail- und SMS Relay-Dienst, die Verwaltung mehrerer Websites sowie höhere API-Kontingente.

Free

Lokaler Schutz, dauerhaft Free

Free
  • Vollständiges lokales Hive-Plugin – alle 16 Attack Sensors
  • Web Application Firewall (Engine + OWASP-Top-10-Basisregelsatz)
  • Verified Bot Detection, Disposable-Email Blocking und Comment Honeypot
  • Grundlegende Security Headers + Protection & Hardening Score
  • Block-Seiten-Referenzcodes und MainWP Integration
  • Umfassendes 2FA-Paket (TOTP, E-Mail, WebAuthn, einschließlich eines YubiKeys bzw. Sicherheitsschlüssels pro Konto)
  • 1.000 API-Abfragen pro Tag
  • 50 Reports pro Tag
  • 1 Domain
  • Unterstützung durch die Gemeinschaft

Business

Agenturen, WooCommerce, White-label

389,00 € / Jahrinkl. 19 % MwSt.32,42 € / Monat, jährliche Abrechnung
  • Alle Funktionen der Professional-Version
  • 100.000 API-Abfragen pro Tag
  • 5.000 Reports pro Tag
  • 2.500 2FA-E-Mails pro Monat sind enthalten
  • 75 2FA-SMS pro Monat inklusive
  • Bis zu 15 Domains pro Lizenz
  • Benötigen Sie mehr Kapazität? Buchen Sie 2×–20× Business – das gesamte Paket (API-Kontingent, 2FA per E-Mail/SMS, Domains) wird entsprechend vervielfacht, wobei automatisch ein Mengenrabatt gewährt wird.
  • White-label Setup Wizard, 2FA-Seiten, E-Mail-Vorlagen
  • Vollständige WooCommerce-Integration (White-label-Vorlagen, Überprüfung von Abonnements und Mitgliedschaften)
  • Audit Event Trail: Nur-Anhang-Protokoll zum Benutzerlebenszyklus (Logins, Passwortzurücksetzungen, Rollenänderungen einschließlich stellvertretender Benutzer) mit CSV-/JSON-Export
  • Erweiterte Sicherheitsschlüssel: mehrere WebAuthn-Schlüssel pro Benutzer (YubiKey als Backup), automatische Modellerkennung, Benachrichtigungen zum Lebenszyklus der Schlüssel
  • GDPR Export Tool
  • Priority Support, 12-Stunden-SLA
Free Testversion starten

14-tägige Geld-zurück-Garantie. Sie können jederzeit kündigen.

Alle Tarife vergleichen

Enthält die Stufen „Contributor“ und „Enterprise“ sowie die vollständige Vergleichstabelle der Funktionen.

Neueste Beiträge aus dem Blog

Versionshinweise, Threat Intelligence-Reports und Sicherheitsnachrichten – stöbern Sie nach „Veröffentlichungen“, „Threat Intelligence“, „Sicherheitsnachrichten“ oder „Ankündigungen“.

Häufig gestellte Fragen

Is ReportedIP free?

Yes. Every product has a free tier: the Hive plugin is free and open source, the API gives 1,000 checks/day for free, the blacklist feed and DNS Checker are free to use. Paid plans and add-ons unlock higher quotas, managed 2FA relay and the DNS/RBL Zone.

Do I need an account?

Not for the Hive plugin in Local Shield mode or for the DNS Checker. The API, the community network and paid add-ons require a free account and an access key.

Which product should I use to protect a WordPress site?

Install ReportedIP Hive. It bundles attack detection, IP blocking and 2FA, and works offline out of the box.

How do I block bad IPs at my mail server?

Use the DNS / RBL Zone add-on. You add one zone string to Postfix, Rspamd or BIND RPZ and connecting attackers are rejected in real time.

What runs self-hosted versus on your servers?

The Hive plugin and the Honeypot Server run on your infrastructure. The API, the blacklist feed, the DNS Checker and the DNS/RBL Zone are hosted by us on EU infrastructure.

Is it GDPR-compliant?

Yes. We minimise data collection (no user agents by default), anonymise older records, and run on EU infrastructure under GDPR. Subprocessors are covered by data-processing agreements.

Is the data open source?

The Hive plugin and Honeypot Server are open source on GitHub, and the community blacklist is published as a daily Git mirror. The reputation engine and API are operated as a managed service.

How is the confidence score calculated?

Each report is weighted by recency, reporter diversity, threat severity and honeypot trust, then decayed over time. An IP is only listed on the public blacklist at a confidence of 75 % or higher.

Getting Started – dauerhaft kostenlos

Wählen Sie ein Produkt aus, stöbern Sie in den Docs oder holen Sie sich einen Free API Key. Keine Kreditkarte erforderlich.

Security Focused, GDPR Compliant, „Made in Germany“, wo möglich Open Source