IN PROGRESS
Technical summary
NEXUS plugin that checks URLs against the PhishTank collaborative phishing database via the checkurl endpoint, feeding the Intelligence Hub with severity signals. Queries with a local MySQL cache with a 24h TTL, a dedicated tab with manual lookup, paginated history and API Key settings.
Executed scope
- Registration:
plugin.jsonv1.0.0, lucidealert-triangleicon,icon_bg #f97316, customicon.svg;registerTab('phishtank','PhishTank','alert-triangle',tab.php,'Segurança & OSINT')+registerDoc('phishtank','PhishTank','alert-triangle',doc.md); nocronjob.json(on-demand plugin). - Dedicated tab (Alpine.js, amber theme): 3 tabs (Check URL / History / Settings); API Online/Offline badge on top; 4 stat cards (Cache Total, Phishing, Safe, Today) with proportional bars; lookup with Confirmed Phishing! / Safe URL / No Confirmation results (colored cards) +
cached/checked_atbadges + externalphish_detail_pagelink; paginated history (URL/Status/Phish ID/Date) with Previous/Next. - Configuration: API Key in
DB::setConfig('phishtank_settings'); "How to get the API Key" guide (phishtank.com →checkurl.phishtank.comendpoint); free-tier/rate-limit notice. - checkurl API via cURL: POST
https://checkurl.phishtank.com/checkurl/withurl+format=json+app_key;NEXUS-PhishTank/1.0user agent; 4s connect and 10s total timeouts;IPRESOLVE_V4and SSL enabled; parsing ofin_database/verified/valid(booleans with'y'/'n'fallback); classification:in_database && verified && valid→ malicious,in_database && verified && !valid→ safe, otherwise unknown. - Local MySQL cache:
phishtank_cachetable (PKurl_hashSHA-256;url,status,in_database,verified,valid,phish_id,phish_detail_page,checked_at;status/checked_atindexes) withINSERT ... ON DUPLICATE KEY UPDATE; 24h TTL; install/write failures never break the panel (task_log). - Intelligence Hub enricher:
nx_intel_register_enricher('phishtank', ['url'], 'pt_intel_enrich', 39)—ok/needs_key/error/skippedsignals; without a key →needs_key("API Key necessária"); budgetslice ≤ min(5, max_live_lookups × 2); severity 90 (malicious) / 8 (otherwise); summary "Phishing confirmado [· verificado]" or "Status: X";datawithstatus/verified/valid/phish_id. - Fast Responses:
/phishtank <URL>(required argument) →phishtank_check. - API with 5 actions:
phishtank_stats(cache totals +api_onlinecomputed only from the key presence — no ping to avoid rate limits),phishtank_check(24h TTL cache-first),phishtank_history(paginated, limit ≤ 100),phishtank_settingsandphishtank_settings_save. - Legacy
pt_filter_task_readfilter disabled inplugin.php(commented) — the "### PhishTank — URLs de Phishing Confirmadas" injection (URL/Verified/Valid/Phish ID table, up to 5 URLs and 3 hits) remains in the code, but the current enrichment path is the Intelligence Hub.
Stack and tools
- PHP 8 backend (no framework) + cURL (PhishTank checkurl API)
- Alpine.js + Tailwind CSS (dedicated tab in NEXUS)
- Internal Plugin API (actions + enricher +
fastr.json+ MySQL cache +system_settings)
Tags
PhishTank, Phishing, URL, Reputation, OSINT, Intelligence Hub, NEXUS Plugin
Operational result
- One-click phishing: URLs from tasks/comments become severity-90 signals in the hub.
- TTL cache: repeated lookups answer from the local cache without spending free-tier quota.
- No key? No noise: the hub signals "API Key necessária" and the task flow stays intact.
- Verified confirmation:
maliciousrequiresin_database + verified + validfrom the collaborative database. - Browsable history: paginated cache with status, phish_id and detail link.
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
NEXUS plugin that checks URLs against the PhishTank collaborative phishing database via the checkurl endpoint, feeding the Intelligence Hub with severity signals. Queries with a local MySQL cache with a 24h TTL, a dedicated tab with manual lookup, paginated history and API Key settings.
Architecture and organization
- PHP 8
- cURL
- PhishTank API
- Alpine.js
- Tailwind CSS
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.