Inside the ReportedIP Hive Web Application Firewall
How Hive's WordPress firewall inspects every request, ships Ed25519-signed rules from a server feed, and guards against ReDoS, the engine and baseline are free on every plan.
Read moreRelease announcements, threat intelligence updates, and security news from the ReportedIP team.
How Hive's WordPress firewall inspects every request, ships Ed25519-signed rules from a server feed, and guards against ReDoS, the engine and baseline are free on every plan.
Read moreHive 2.1.4 brings a request-inspecting Web Application Firewall, verified-bot detection, disposable-email blocking and a comment honeypot, everything that shipped since 2.0.22.
Read moreFive releases in one roundup: a Hide-Login probe sensor that blocks scans of your old login URL, a complete German interface, and a 2FA login flow that no longer sends codes you never requested.
Read moreGive every web, mail, and edge node in your cluster one shared community blocklist, queried over DNS with a single token, no per-node integration code.
Read moreThe ReportedIP community blacklist is now a live DNS blocklist. Query 11,134 listed IPs as a private RBL zone from Postfix, Rspamd, or any firewall, bookable from PRO.
Read moreHive 2.0.16 unifies every upgrade hint behind one frequency cap, adds relay quota alert mails at 80% and 100%, and fixes a set of Hardening Mode re-arm and relay-backoff bugs.
Read moreA single weekend produced 37,288 attack reports from 15,066 unique IPs. Hacking attempts, brute-force pressure and SSH+WP combo runs dominated; four origin countries account for 18,254 of those IPs. Here is what the community fed us and what shipped in response.
Read moreHive 2.0.15 fixes a silent drop of multi-recipient admin alerts, stops Hardening Mode from re-activating against the same attack pattern every hour, and respects relay 429 backoffs on the client side.
Read moreHive Light landed in the official WordPress.org plugin directory. A focused brute-force protector for wp-login.php: per-IP counter, progressive block ladder, optional community reputation lookup, GPL-2.0+, no account required.
Read moreMinimal data, 30-day retention, 7-day anonymisation, libsodium encryption at rest and offline-by-choice operation, privacy as a design principle.
Read moreWhy one weak sub-site threatens the whole network: the multisite threat model, a 10-point hardening checklist, a WP-CLI audit and network-wide blocking with one shared threat state.
Read moreA managed relay sends OTP mail and SMS through clean infrastructure, with a transparent wp_mail() fallback so the login flow never breaks on a cap.
Read more