Cover image for project: NEXUS EmailRep IN PROGRESS

Technical summary

NEXUS EmailRep scores reputation and risk of emails found in tasks and comments via EmailRep.io, with a 24 h local cache and automatic enrichment through the Intelligence Hub. It detects breaches, disposable emails and spam history, and maps associated social profiles.

Executed scope

  • Plugin registration (registerTab('email_osint','EmailRep','mail',tab.php,'OSINT & Enrichment') + registerDoc) and email_osint_install() creating the email_osint_cache table (email PK, reputation, suspicious, references_count, details JSON, notified, timestamps).
  • 5 API actions: email_osint_stats (totals — cache, suspicious, breaches — and API status), email_osint_lookup (manual query with cache), email_osint_history (latest queries), email_osint_settings_save (key + auto_enrich) and email_osint_delete (clears a cache record).
  • EmailRep.io REST integration (https://emailrep.io/{email}): reputation, suspicious flag, reference count and risk details (credentials_leaked/data_breach); optional key — basic use is free, higher volume requires a key configured in the panel.
  • 24 h TTL local cache: email_osint_get() answers from the DB when fresh and only calls the API on expired cache or forceRefresh; saves requests and works around free-tier rate limits.
  • Enrichment (Intelligence Hub): nx_intel_register_enricher('email-osint', ['email'], 'email_osint_intel_enrich', 51) publishes signals to task.intel/comment.intel with a lookup budget (NX_INTEL_MAX_LIVE_LOOKUPS); legacy read filters disabled (no markdown append).
  • email_osint cronjob (tick, ~5 min internal throttle): email_osint_cron_check() scans pending/in_progress tasks and comments from the last 30 days, refreshes the cache against the API and fires a system notification on breach; allowlisted cli.php triggers the scan manually.
  • UI (tab.php, 448 lines, Alpine emailOsintTab()): API Online badge, stat cards (cached emails, suspicious, latest queries), manual lookup and settings panel.

Stack and tools

  • PHP 8 backend (no framework) + MySQL 8 (email_osint_cache)
  • EmailRep.io REST API (optional key for higher volume)
  • Alpine.js + Tailwind CSS (tab.php)
  • Internal Plugin API (PluginManager tabs/actions + cronjob.json + enricher)

Operational tags

  • EmailRep
  • OSINT
  • Email
  • Reputation
  • Risk
  • Breach
  • Social profiles
  • NEXUS Plugin

Operational result

  • Email OSINT: reputation and risk for any address found in NEXUS, straight from the panel or the task flow.
  • Breach detection: credentials_leaked/data_breach flags feed automatic system notifications.
  • 24 h cache: instant responses on re-checks and minimal free-tier API usage.
  • Automatic enrichment: emails in tasks/comments get security signals via the Intelligence Hub with no manual action.
  • Scheduled scanning: cron keeps checking active tasks and recent comments (~5 min throttle).
  • Social profiles: maps associated digital footprints (GitHub, Twitter, LinkedIn, Instagram, Spotify, etc.).

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

Scores reputation and risk of emails found in tasks and comments via EmailRep.io, with a 24 h local cache and automatic enrichment through the Intelligence Hub; detects breaches, disposable emails and spam history, and maps associated social profiles.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.