5,233 GPL Products · Updated DailyPRO Versions Available · Instant Download
ReportedIP Hive Light 1.3.8 – WordPress Plugin

ReportedIP Hive Light

v1.3.8 Updated 3 days ago Live Demo ↗
Download ReportedIP Hive Light 1.3.8
Free download · version 1.3.8

Description

At a glance

ReportedIP Hive Light v1.3.8 — free WordPress plugin download. Key facts: updated September 29, 2026 · requires WordPress 6.1+ & PHP 8.1+.

ReportedIP Hive Light protects WordPress logins against brute-force and password-spray attacks. It is intentionally focused: a per-IP attempt counter, a progressive block ladder, and an optional community lookup. No bloat, no dashboards, no nag screens.

Two operating modes

  • Local Shield (default). Counts failed logins per IP and blocks attackers based on configurable thresholds. The plugin makes zero outbound network requests in this mode — all data stays on your server.
  • Community Network (optional). When you enter a free Community Access Key from reportedip.com, the plugin additionally checks the source IP against the reportedip.com community database during login attempts and shares blocked IPs back to the community. Both calls are clearly disclosed in the settings UI.

How it works

  • wp_login_failed increments a per-IP counter using an atomic upsert (no race conditions under concurrent attacks).
  • When the counter exceeds your threshold, the IP is blocked for a duration drawn from a progressive ladder (5 min 15 min 30 min 24 h 48 h 7 days).
  • wp_authenticate_user short-circuits known-bad IPs before the WordPress core authentication runs.
  • Cache plugins (WP Rocket, W3 Total Cache, WP Super Cache, LiteSpeed) are honoured via the HTTP 403 status plus explicit Cache-Control: no-store, no-cache, must-revalidate, max-age=0 and Pragma: no-cache headers on the block page.

Privacy

  • IP addresses are processed for the legitimate purpose of network security (GDPR Art. 6(1)(f)).
  • Usernames are stored locally only as a SHA-256 hash, salted with wp_salt(). Usernames are never transmitted, neither in plain text nor hashed.
  • In Local Shield mode, no data leaves your server. In Community Network mode, a report carries only the IP address, an integer category ID for the event type and a short comment such as “5 failed logins in 15 minutes”. No username, no domain, no contact details, no traffic data.

For developers

  • Filters: reportedip_hive_is_whitelisted, reportedip_hive_get_client_ip, reportedip_hive_event_category_map, reportedip_hive_api_endpoint.
  • Actions: reportedip_hive_log, reportedip_hive_ip_blocked, reportedip_hive_report_queued.

A free Community Access Key is available at reportedip.com. The plugin works without one in Local Shield mode.

Looking for more? ReportedIP Hive Full Edition and Hive PRO

Hive Light is complete on its own and stays free — nothing in this plugin is locked or crippled. If you need more than login protection, the separate Full Edition — also free and GPL-2.0, distributed via GitHub — adds 16 attack sensors including a Web Application Firewall, four 2FA methods (authenticator app, e-mail, SMS, passkeys) and multisite support. The optional Hive PRO subscription on top of the Full Edition connects your sites to a managed, EU-hosted 2FA relay for SMS and e-mail codes (no Twilio account needed) and covers three domains with one licence.

External services

This plugin can connect to the ReportedIP API at https://reportedip.com. All
external requests are opt-in only — they are made exclusively when (a) a
“Community Access Key” has been entered in the plugin settings and (b) the
“Operation Mode” is set to “Community Network”. The default mode is “Local
Shield”, which performs zero external requests.

Endpoint 1: IP-reputation lookup

  • URL: https://reportedip.com/wp-json/reportedip/v2/check?ip={ip}
  • HTTP verb: GET
  • Auth header: X-Key: {your-access-key}
  • Trigger: a login attempt reaches wp_authenticate_user
  • Timeout: 2 seconds (fail-open — login proceeds when the API does not respond)
  • Data sent: only the source IP address of the current login attempt
  • Data NOT sent: usernames, passwords, cookies, server identifiers, domain name

Endpoint 2: Blocked-IP report

  • URL: https://reportedip.com/wp-json/reportedip/v2/report
  • HTTP verb: POST (JSON body)
  • Auth header: X-Key: {your-access-key}
  • Trigger: a brute-force / spray threshold has been exceeded; the report is
    queued in the database and dispatched by a 15-minute cron job
  • Data sent: the offending IP, an integer category ID for the threat type,
    and a short human-readable comment (e.g. “5 failed logins in 15 minutes”)
  • Data NOT sent: usernames in plain text, passwords, full request bodies,
    domain name, contact information

Endpoint 3: Access-key verification

  • URL: https://reportedip.com/wp-json/reportedip/v2/verify-key
  • HTTP verb: GET
  • Auth header: X-Key: {entered-key}
  • Trigger: an administrator clicks “Test connection” in the plugin settings
  • Data sent: only the access key under verification

Hashing of submitted usernames

When a brute-force attempt is detected and the failing username is recorded
locally, the plugin stores sha256( username + wp_salt() ) only, never the
plain text. The hash stays on your server; reports do not contain it.

Service provider

You can switch back to Local Shield mode at any time in Settings ReportedIP
Hive Connection
. Doing so stops all external traffic immediately.

Bundled assets

This plugin ships every stylesheet and script it needs inside the plugin
folder. No CDN, no Google Fonts, no remote stylesheets, no remote scripts
are loaded
— every asset URL begins with the plugin’s own
wp-content/plugins/reportedip-hive/ path.

The full list of bundled, locally-served assets:

  • assets/css/design-system.css — design tokens and components used on
    every plugin admin page.
  • assets/css/admin.css — admin-page overrides on top of the design
    system.
  • assets/css/wizard.css — standalone styles for the first-run setup
    wizard.
  • assets/js/admin.js — handles tab switching and the AJAX
    “Test connection” button. Its only network call is fetch() against
    WordPress’ own admin-ajax.php (same origin); no third-party endpoint
    is contacted.
  • Inline SVG icons (the shield logo, the menu icon, and trust-badge
    glyphs) are emitted from PHP via wp_kses() with an explicit allow-list
    — no <img> element points at an external host.

The complete list of files distributed in the WordPress.org ZIP is
visible at Plugins Plugin File Editor once the plugin is installed.

Third-party services and licences

  • GPLv2 (or later) licence text is bundled with the plugin in the
    LICENSE file at the plugin root and is also referenced from the
    plugin header (License URI: https://www.gnu.org/licenses/gpl-2.0.html).
  • No third-party PHP, JavaScript, or CSS libraries are bundled with
    the plugin. There is no Composer vendor/ directory, no jQuery copy,
    no minified third-party bundle. WordPress itself supplies any global
    scripts (jquery, wp-list-table, etc.) and the plugin only depends
    on WordPress core APIs.
  • The only external HTTP service the plugin can talk to is the
    https://reportedip.com/wp-json/reportedip/v2/ API, and only when the
    administrator has explicitly enabled Community Network mode — see
    the “External services” section above for the full data flow.

Privacy

  • IP addresses are processed under GDPR Art. 6(1)(f) (legitimate interest in network security).
  • Usernames are stored locally as a salted SHA-256 hash and are never transmitted, neither in plain text nor hashed.
  • In Local Shield mode (default) no data leaves your server.
  • In Community Network mode the data listed above is sent to reportedip.com.
  • Data retention is configurable in Settings Privacy. The default attempt window is 15 minutes; the API queue retention is 7 days.
  • Activate “Delete all data on uninstall” in Settings Privacy to remove all plugin tables and options when the plugin is deleted.

Disclaimer

ReportedIP Hive Light is provided “as is”, without warranty of any kind, express or
implied, including but not limited to warranties of merchantability, fitness
for a particular purpose, and non-infringement. The author shall not be liable
for any claim, damages, or other liability arising from the use of this
software (this is the standard GPLv2-or-later disclaimer; see the LICENSE
file for the full text).

The plugin provides defense-in-depth against brute-force and password-spray
login attacks. It does not replace strong passwords, two-factor
authentication, server-level firewalls, or web-application firewalls. No
single security measure offers a 100 % guarantee against compromise. You
remain responsible for the overall security posture of your WordPress site.

The optional Community Network mode forwards data to the third-party service
operated at https://reportedip.com — see the “External services” section
above for the full data flow. Site operators that enable Community Network
mode are responsible for assessing the lawful basis under their applicable
data-protection regime (in the EU, GDPR Art. 6(1)(f) — legitimate interest
in network security — typically applies) and for updating their own privacy
policy accordingly.

Frequently asked questions

What do I get when I download ReportedIP Hive Light?

ReportedIP Hive Light 1.3.8 is the latest version. It is a WordPress plugin you can download here free of charge under the GPL license, with the complete feature set included and no trial limitations.

Does ReportedIP Hive Light cost anything?

No. ReportedIP Hive Light 1.3.8 is 100% free — the full GPL version, not a trial or demo. There are no download limits, no accounts to create, and no upsells during the download.

How do I install ReportedIP Hive Light 1.3.8?

Download the ZIP file from this page, then in your WordPress dashboard go to Plugins → Add New → Upload Plugin, choose the file, click Install Now, then Activate. The plugin works immediately after activation — no license key or extra setup is required for the core features.

What are the requirements for ReportedIP Hive Light?

ReportedIP Hive Light 1.3.8 requires WordPress 6.1 or higher and PHP 8.1 or higher. Most modern WordPress hosts already meet these versions. Running older versions may cause features to break, so update WordPress and PHP first if your site is behind.

When was ReportedIP Hive Light last updated?

Version 1.3.8 was last updated on September 29, 2026. This page is refreshed automatically, so the download here always matches the newest version we have verified.

Is the ReportedIP Hive Light download safe?

The file is sourced directly from the official WordPress.org repository — the same file the developer published. It is served unmodified, so what you install here is byte-identical to the official release.

Version: 1.3.8
Updated: October 1, 2026

Technical details

Version1.3.8
Last updatedSeptember 29, 2026
Requires WordPress6.1 or higher
Requires PHP8.1 or higher
AuthorPatrick Schlesinger
Tagsbrute-force, firewall, ip-blocking, login, security
Demo ReportedIP Hive Light

Download ReportedIP Hive Light

Download ReportedIP Hive Light WP Plugin

Official Page ↗

Note: if the download does not start, disable your ad blocker and try again.

Leave a Comment