IN PROGRESS
Technical summary
NEXUS HaveIBeenPwned checks emails and passwords against known public breaches: emails via the breached accounts API (paid key) and passwords via k-Anonymity (first 5 hex of SHA-1, 100% free and never exposing the password). It ships a local cache, false-positive blacklist and automatic enrichment through the Intelligence Hub.
Executed scope
- Plugin registration (
registerTab('haveibeenpwned','HaveIBeenPwned','key',tab.php,'OSINT & Enrichment')+registerDoc) andhibp_install()creating thehibp_emails(email PK, breaches_count, breaches_list) andhibp_passwords(SHA-1 hash PK, appearances) tables. - 4 API actions:
hibp_stats(totals of checked emails/passwords + API status),hibp_query(manual query by email or password),hibp_delete(removes a cache record by type/key) andhibp_settings_save(key + auto-enrich). - Email integration: HaveIBeenPwned API v3 (
/api/v3/breachedaccount/{email}?truncateResponse=false) returns breach count and list (e.g., Adobe, Canva); requires a paid subscription (Pwned 1/Pwned 2 plans) with a 32-char hex key. - Password integration with k-Anonymity privacy:
hibp_api_query_password()computes SHA-1 locally and only sends the 5-hex prefix toapi.pwnedpasswords.com/range/{prefix}; suffix matching is done offline in the backend — free and no key needed. - Local cache:
hibp_emails/hibp_passwordsstore valid queries with timestamps, saving requests and working around API rate limits. - Enrichment (Intelligence Hub):
nx_intel_register_enricher('haveibeenpwned', ['email', 'hash', '_text'], 'hibp_intel_enrich', 45)publishes structured signals tointel;hibp_credential_blacklist()andhibp_is_false_positive_credential()filter false positives (bearer/basic/admin/password/…) andhibp_classify_credential()splitstest_hash/http_token/password. - On-demand only: empty
cronjob.json(no periodic routines — nothing safe or needed to schedule); no CLI. - Fast Responses:
fastr.jsonmanifest with/hibp <email or domain>(required arg),hibp_queryaction. - UI (
tab.php, 488 lines, AlpinehaveIBeenPwnedTab()): API Online badge, stat cards (cached emails/passwords, latest queries) and a Local Cache tab with Emails/Passwords sub-tabs.
Stack and tools
- PHP 8 backend (no framework) + MySQL 8 (
hibp_emails,hibp_passwords) - HaveIBeenPwned API v3 (breached accounts) + Pwned Passwords API (k-Anonymity)
- Alpine.js + Tailwind CSS (
tab.php) - Internal Plugin API (PluginManager tabs/actions +
fastr.json+ enricher)
Operational tags
- HaveIBeenPwned
- Breach
- Leak
- Password
- k-Anonymity
- SHA-1
- NEXUS Plugin
Operational result
- Breach checking: any email found in NEXUS can be checked against known public breaches (Adobe, Canva, etc.).
- k-Anonymity privacy: passwords never leave the server complete — only the 5-hex SHA-1 prefix is sent; zero cost and no key required.
- False-positive filtering: blacklist and classification avoid alerting on HTTP tokens, placeholders and sample credentials.
- Automatic enrichment: emails, hashes and texts in tasks/comments get breach signals via the Intelligence Hub with no manual action.
- Local cache: reusable queries cut paid API usage and dodge rate limits.
- On-demand: no scheduled cron — checks happen when requested (panel, API or
/hibpslash).
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
Checks emails and passwords against known public breaches: emails via the breached accounts API (paid key) and passwords via k-Anonymity (first 5 hex of SHA-1, 100% free and never exposing the password); ships a local cache, false-positive blacklist and automatic enrichment through the Intelligence Hub.
Architecture and organization
- PHP 8
- MySQL 8
- HaveIBeenPwned API v3
- Pwned Passwords
- Alpine.js
- Tailwind CSS
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.