Search by

arraypress / wp-abuseipdb

arraypress

A PHP library for integrating with the AbuseIPDB Check API in WordPress, providing community-sourced IP abuse confidence scores (0-100) and report counts. Free tier supports ~1k checks/day. Built around WordPress's HTTP API with transient caching.

Package info

github.com/arraypress/wp-abuseipdb

Homepage

pkg:composer/arraypress/wp-abuseipdb

Statistics

Installs: 1

Dependents: 1

Suggesters: 0

Stars: 0

Open Issues: 0

v1.0.0 2026-08-25 20:59 UTC

This package is auto-updated.

Last update: 2026-09-26 08:48:00 UTC


README

Ask AbuseIPDB whether an IP address has been reported for abuse, and cache the answer.

What it does

AbuseIPDB collects abuse reports from thousands of sites and gives an IP a confidence score out of 100. This calls the Check endpoint, hands back a response object instead of a raw array, and remembers the answer so a busy checkout does not make the same request twice.

Failures are cached too, briefly — when the API is down or the key is wrong, the alternative is hammering it once per request.

Features

  • Get an abuse confidence score for an IP, 0 to 100
  • See how many reports it has and how many distinct sites filed them
  • Tell whether it is a Tor exit node or on AbuseIPDB's own allowlist
  • Know how recently it was last reported, so an old score can be discounted
  • Cache both answers and failures, with the lifetime you choose
  • Read fields by name rather than digging through a decoded array

Installation

composer require arraypress/wp-abuseipdb

Quick start

Hold a checkout for review when the address has a bad reputation:

use ArrayPress\AbuseIPDB\Client;

$client = new Client( $api_key );
$check  = $client->check_ip( $ip );

if ( is_wp_error( $check ) ) {
	return; // Let it through rather than failing closed on an API error.
}

if ( $check->get_confidence_score() >= 75 ) {
	$order->flag_for_review( sprintf(
		'%d reports from %d sites',
		$check->get_total_reports(),
		$check->get_distinct_reporters()
	) );
}

A score is a reputation, not a verdict. Treat a high one as a reason to look closer, not to block outright — the address may be a shared NAT or a mobile carrier.

Requirements

  • PHP 8.3 or later
  • WordPress 7.1 or later
  • An AbuseIPDB API key

License

GPL-2.0-or-later