IN PROGRESS
Technical summary
NEXUS plugin that checks the reputation of emails, IPs and URLs against IPQualityScore with a unified 0–100 fraud score, flags (disposable, proxy, VPN, Tor, phishing…) and a 24h local cache — with login and registration blocking by risk threshold and disposable email, automatic enrichment in the Intelligence Hub and full auditing of verifications and API usage.
Executed scope
plugin.json: v1.0.0, slugipqualityscore, "Intelligence" category (OSINT & Enrichment tab,shield-checkicon,is_core: false).- Settings (
DB::getConfig('plugin.ipqualityscore')):api_key,block_disposable_emails(false),min_fraud_score(75, clamped 0–100),verify_on_register(true); the key is normalized on save (removes clipboard whitespace/control chars). - Operational blocking —
before_loginandbefore_registerhooks (priority 20): resolve the email when logging in by username, verify email + IP (ipqs_check_user) and deny auth with a PT message on disposable email (when enabled) or score ≥ threshold. - Unified user score —
round(email_score * 0.6 + ip_score * 0.4), or email-only when no IP; separate email/ip flags in the result. - Lookups (
email|ip|url) —FILTER_VALIDATE_*validation (scheme-less URLs gethttps://); 24h cache inipqs_cache(ON DUPLICATE KEY UPDATE); cURL (20s/8s, SSL verify,NEXUS-IPQS/1.0UA) athttps://ipqualityscore.com/api/json/{type}/{key}/{value}with per-endpoint params andrequired_any. - Malicious URL —
unsafe,phishingormalwareforces score ≥ 85, regardless of the returnedrisk_score. - Dual auditing —
ipqs_verifications(score,risk_level, JSON flags,blocked, source, user, IP, full result) andipqs_api_requests(success,cached,billable,http_code,error_message,request_id). risk_level—critical≥ 90,high≥ 75,medium≥ 50,low; blocking starts at the configured threshold.ipqs_api_online— validates the Private Key at/api/json/account/{key}without spending credit; accounts out of credits still count as online (insufficient credits).- Intelligence Hub —
ipqs_intel_enrichenricher foremail/ip/url(priority 49):Fraud score X/100 · risksignals,severity = score,ok/error/needs_key/skippedstatus and a lookup budget (max_live_lookups); legacytask_read/comment_readfilters disabled. - Migrations — 4 files: base tables, request audit, failed-request backfill and billable marking.
- API: 7 actions (
ipqs_checkwith email/ip/url/usertype,ipqs_stats,ipqs_history,ipqs_request_history,ipqs_get_configwith••••+last-4masked key,ipqs_save_configwith validation andapi_onlinereturn,ipqs_clear_cache). - Alpine.js UI (
tab.php, 587 lines) — blue theme (blue-600), OSINT & Enrichment tab; header with API Online/Offline badge (green/red/amber pulse + Configure shortcut); 4 stat cards with progress bars; 3 sub-tab toolbar (Verify, History, Settings); Verify tab with email/IP/URL/user types (+ optional IP), risk-colored score /100 result (rose ≥ 75, amber ≥ 50, green < 50), 24h Cache badge and flag pills; History with verification and API usage audit tables (cached/success/error status); Settings with masked API key, toggles and score threshold. - Fastr:
/ipqs-email,/ipqs-ip,/ipqs-url. - Empty cron (
jobs: [], on-demand) and own modal (modals.php). - No i18n (Portuguese texts) and no
lang.json.
Stack and tools
- PHP 8 (no framework)
- MySQL 8 (
ipqs_cache,ipqs_verifications,ipqs_api_requests) - Alpine.js + Tailwind CSS (premium light, blue)
- cURL (20s lookups, 8s health-check, SSL verify)
- IPQualityScore API (
/api/json/email|ip|url/{key}/{value},/api/json/account/{key}) - NEXUS plugin system (PluginManager: tabs, filters, API actions, Fastr, modals, migrations)
Operational tags
- IPQualityScore
- Anti-Fraude
- Fraud Score
- Email Verification
- IP Reputation
- URL Scanner
- OSINT
- Plugin NEXUS
Operational result
- Proactive signup protection: login and registration deny access based on fraud score and disposable emails — with a clear message to the user.
- 3 targets + user coverage: email, IP and URL checked individually or as a unified per-user score.
- Credit savings: 24h local cache and a credit-free health-check; malicious URL flags force a high score.
- Full traceability: verifications and API usage audited (billable, failures, request_id) — KPIs and history in the panel.
- Integrated intelligence: IPQualityScore signals in the task/comment Intelligence Hub with severity = score.
- Key privacy: the Private Key is never exposed to the frontend (only the
••••mask). /ipqs-email,/ipqs-ipand/ipqs-urlchat commands.
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
IP address reputation and fraud detection engine integrated with IPQualityScore. Identifies proxies, malicious VPNs, Tor exit nodes, and active botnets, computing risk and fraud scores to prevent automated attacks.
Architecture and organization
- PHP 8
- MySQL 8
- Alpine.js
- Tailwind CSS
- cURL
- IPQualityScore API
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.