Cover image for project: NEXUS PhishTank IN PROGRESS

Technical summary

NEXUS plugin that checks URLs against the PhishTank collaborative phishing database via the checkurl endpoint, feeding the Intelligence Hub with severity signals. Queries with a local MySQL cache with a 24h TTL, a dedicated tab with manual lookup, paginated history and API Key settings.

Executed scope

  • Registration: plugin.json v1.0.0, lucide alert-triangle icon, icon_bg #f97316, custom icon.svg; registerTab('phishtank','PhishTank','alert-triangle',tab.php,'Segurança & OSINT') + registerDoc('phishtank','PhishTank','alert-triangle',doc.md); no cronjob.json (on-demand plugin).
  • Dedicated tab (Alpine.js, amber theme): 3 tabs (Check URL / History / Settings); API Online/Offline badge on top; 4 stat cards (Cache Total, Phishing, Safe, Today) with proportional bars; lookup with Confirmed Phishing! / Safe URL / No Confirmation results (colored cards) + cached/checked_at badges + external phish_detail_page link; paginated history (URL/Status/Phish ID/Date) with Previous/Next.
  • Configuration: API Key in DB::setConfig('phishtank_settings'); "How to get the API Key" guide (phishtank.com → checkurl.phishtank.com endpoint); free-tier/rate-limit notice.
  • checkurl API via cURL: POST https://checkurl.phishtank.com/checkurl/ with url + format=json + app_key; NEXUS-PhishTank/1.0 user agent; 4s connect and 10s total timeouts; IPRESOLVE_V4 and SSL enabled; parsing of in_database/verified/valid (booleans with 'y'/'n' fallback); classification: in_database && verified && valid → malicious, in_database && verified && !valid → safe, otherwise unknown.
  • Local MySQL cache: phishtank_cache table (PK url_hash SHA-256; url, status, in_database, verified, valid, phish_id, phish_detail_page, checked_at; status/checked_at indexes) with INSERT ... ON DUPLICATE KEY UPDATE; 24h TTL; install/write failures never break the panel (task_log).
  • Intelligence Hub enricher: nx_intel_register_enricher('phishtank', ['url'], 'pt_intel_enrich', 39) — ok/needs_key/error/skipped signals; without a key → needs_key ("API Key necessária"); budget slice ≤ min(5, max_live_lookups × 2); severity 90 (malicious) / 8 (otherwise); summary "Phishing confirmado [· verificado]" or "Status: X"; data with status/verified/valid/phish_id.
  • Fast Responses: /phishtank <URL> (required argument) → phishtank_check.
  • API with 5 actions: phishtank_stats (cache totals + api_online computed only from the key presence — no ping to avoid rate limits), phishtank_check (24h TTL cache-first), phishtank_history (paginated, limit ≤ 100), phishtank_settings and phishtank_settings_save.
  • Legacy pt_filter_task_read filter disabled in plugin.php (commented) — the "### PhishTank — URLs de Phishing Confirmadas" injection (URL/Verified/Valid/Phish ID table, up to 5 URLs and 3 hits) remains in the code, but the current enrichment path is the Intelligence Hub.

Stack and tools

  • PHP 8 backend (no framework) + cURL (PhishTank checkurl API)
  • Alpine.js + Tailwind CSS (dedicated tab in NEXUS)
  • Internal Plugin API (actions + enricher + fastr.json + MySQL cache + system_settings)

Tags

PhishTank, Phishing, URL, Reputation, OSINT, Intelligence Hub, NEXUS Plugin

Operational result

  • One-click phishing: URLs from tasks/comments become severity-90 signals in the hub.
  • TTL cache: repeated lookups answer from the local cache without spending free-tier quota.
  • No key? No noise: the hub signals "API Key necessária" and the task flow stays intact.
  • Verified confirmation: malicious requires in_database + verified + valid from the collaborative database.
  • Browsable history: paginated cache with status, phish_id and detail link.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

NEXUS plugin that checks URLs against the PhishTank collaborative phishing database via the checkurl endpoint, feeding the Intelligence Hub with severity signals. Queries with a local MySQL cache with a 24h TTL, a dedicated tab with manual lookup, paginated history and API Key settings.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.