WordPress Plugin
The IPAbuse WordPress plugin checks visitor IPs against the IPAbuse reputation API and blocks malicious requests before they execute any WordPress code.
Requirements
- WordPress 6.0 or later
- PHP 8.1 or later
- IPAbuse API key
Install
Via WordPress Admin
- Go to Plugins → Add New.
- Search for IPAbuse Firewall.
- Click Install Now then Activate.
Via WP-CLI
cURL
wp plugin install ipabuse-firewall --activateConfigure
- Go to Settings → IPAbuse Firewall.
- Enter your API key.
- Set the risk threshold (default: 50 — block IPs scoring below this).
- Choose which categories to act on.
- Click Save Settings.
How it works
The plugin hooks into init (the earliest WordPress action) and checks $_SERVER['REMOTE_ADDR'] against IPAbuse. Results are cached in a WordPress transient for the duration of your configured TTL to minimise API calls.