Cover image for project: NEXUS IPQualityScore IN PROGRESS

Technical summary

NEXUS plugin that checks the reputation of emails, IPs and URLs against IPQualityScore with a unified 0–100 fraud score, flags (disposable, proxy, VPN, Tor, phishing…) and a 24h local cache — with login and registration blocking by risk threshold and disposable email, automatic enrichment in the Intelligence Hub and full auditing of verifications and API usage.

Executed scope

  • plugin.json: v1.0.0, slug ipqualityscore, "Intelligence" category (OSINT & Enrichment tab, shield-check icon, is_core: false).
  • Settings (DB::getConfig('plugin.ipqualityscore')): api_key, block_disposable_emails (false), min_fraud_score (75, clamped 0–100), verify_on_register (true); the key is normalized on save (removes clipboard whitespace/control chars).
  • Operational blocking — before_login and before_register hooks (priority 20): resolve the email when logging in by username, verify email + IP (ipqs_check_user) and deny auth with a PT message on disposable email (when enabled) or score ≥ threshold.
  • Unified user score — round(email_score * 0.6 + ip_score * 0.4), or email-only when no IP; separate email/ip flags in the result.
  • Lookups (email|ip|url) — FILTER_VALIDATE_* validation (scheme-less URLs get https://); 24h cache in ipqs_cache (ON DUPLICATE KEY UPDATE); cURL (20s/8s, SSL verify, NEXUS-IPQS/1.0 UA) at https://ipqualityscore.com/api/json/{type}/{key}/{value} with per-endpoint params and required_any.
  • Malicious URL — unsafe, phishing or malware forces score ≥ 85, regardless of the returned risk_score.
  • Dual auditing — ipqs_verifications (score, risk_level, JSON flags, blocked, source, user, IP, full result) and ipqs_api_requests (success, cached, billable, http_code, error_message, request_id).
  • risk_level — critical ≥ 90, high ≥ 75, medium ≥ 50, low; blocking starts at the configured threshold.
  • ipqs_api_online — validates the Private Key at /api/json/account/{key} without spending credit; accounts out of credits still count as online (insufficient credits).
  • Intelligence Hub — ipqs_intel_enrich enricher for email/ip/url (priority 49): Fraud score X/100 · risk signals, severity = score, ok/error/needs_key/skipped status and a lookup budget (max_live_lookups); legacy task_read/comment_read filters disabled.
  • Migrations — 4 files: base tables, request audit, failed-request backfill and billable marking.
  • API: 7 actions (ipqs_check with email/ip/url/user type, ipqs_stats, ipqs_history, ipqs_request_history, ipqs_get_config with ••••+last-4 masked key, ipqs_save_config with validation and api_online return, ipqs_clear_cache).
  • Alpine.js UI (tab.php, 587 lines) — blue theme (blue-600), OSINT & Enrichment tab; header with API Online/Offline badge (green/red/amber pulse + Configure shortcut); 4 stat cards with progress bars; 3 sub-tab toolbar (Verify, History, Settings); Verify tab with email/IP/URL/user types (+ optional IP), risk-colored score /100 result (rose ≥ 75, amber ≥ 50, green < 50), 24h Cache badge and flag pills; History with verification and API usage audit tables (cached/success/error status); Settings with masked API key, toggles and score threshold.
  • Fastr: /ipqs-email, /ipqs-ip, /ipqs-url.
  • Empty cron (jobs: [], on-demand) and own modal (modals.php).
  • No i18n (Portuguese texts) and no lang.json.

Stack and tools

  • PHP 8 (no framework)
  • MySQL 8 (ipqs_cache, ipqs_verifications, ipqs_api_requests)
  • Alpine.js + Tailwind CSS (premium light, blue)
  • cURL (20s lookups, 8s health-check, SSL verify)
  • IPQualityScore API (/api/json/email|ip|url/{key}/{value}, /api/json/account/{key})
  • NEXUS plugin system (PluginManager: tabs, filters, API actions, Fastr, modals, migrations)

Operational tags

  • IPQualityScore
  • Anti-Fraude
  • Fraud Score
  • Email Verification
  • IP Reputation
  • URL Scanner
  • OSINT
  • Plugin NEXUS

Operational result

  • Proactive signup protection: login and registration deny access based on fraud score and disposable emails — with a clear message to the user.
  • 3 targets + user coverage: email, IP and URL checked individually or as a unified per-user score.
  • Credit savings: 24h local cache and a credit-free health-check; malicious URL flags force a high score.
  • Full traceability: verifications and API usage audited (billable, failures, request_id) — KPIs and history in the panel.
  • Integrated intelligence: IPQualityScore signals in the task/comment Intelligence Hub with severity = score.
  • Key privacy: the Private Key is never exposed to the frontend (only the •••• mask).
  • /ipqs-email, /ipqs-ip and /ipqs-url chat commands.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

IP address reputation and fraud detection engine integrated with IPQualityScore. Identifies proxies, malicious VPNs, Tor exit nodes, and active botnets, computing risk and fraud scores to prevent automated attacks.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.