Plugins
One-click integrations that connect your existing software to IPAbuse. Plugins check incoming IPs against our reputation database and block requests that exceed your configured risk threshold — with no code changes required.
cPanel / WHMStable
Auto-block abusive IPs at the server level. Integrates with CSF firewall and WHM interface.
Read guide →WordPressStable
Block malicious IPs before they reach your WordPress install. WP-Admin panel included.
Read guide →DrupalBeta
Drupal 10/11 module with per-IP access control and configurable risk thresholds.
Read guide →WHMCSStable
Protect your WHMCS billing portal. Auto-blocks malicious IPs and reports failed logins to IPAbuse.
Read guide →How plugins work
- The plugin reads the incoming request's source IP address.
- It calls
GET /v1/ip/{ip}/reputationusing your configured API key. - If the reputation score is below your threshold, the request is blocked (HTTP 403).
- Optionally, the IP is added to a local deny list for a configurable TTL to reduce API calls.
Plugin requirements
- An IPAbuse API key (free tier works for low-traffic sites).
- Outbound HTTPS access from your server to
api.ipabuse.org. - Platform-specific requirements are listed in each plugin's guide.