Skip to main contentSkip to footer
ReportedIP Threat Reports

WordPress & server attack data, straight from the network

The ReportedIP Threat Report is a quarterly analysis of live attack data from the ReportedIP community network — honeypots and Hive-protected WordPress sites reporting real attacks as they happen. Every number is measured, not estimated, and free to cite under CC BY 4.0.

290k+
IP addresses tracked
5.3M+
community reports
30
threat categories
Live data as of July 25, 2026 EU-hosted, GDPR-compliant CC BY 4.0 for citations

Published reports

Every report is a self-contained analysis with charts, methodology and reusable numbers. New editions appear here each quarter.

How is the data collected?

Three stages, fully automated — no manual curation, no vendor estimates.

Detect. Honeypot servers imitating common CMS endpoints and production sites running the Hive plugin observe real attack traffic: login brute-force, XML-RPC abuse, scanner probes, firewall hits.

Report. Each event is submitted to the community API as an anonymised report — attacker IP, threat category and timestamp. No user agents by default, no personal data of site visitors, reporter identity never published.

Aggregate. The reputation engine deduplicates bursts, weights reports by recency and reporter diversity, and computes a 0–100 % confidence score per IP. Reports read from this scored dataset.

For journalists and researchers

The report series exists to be cited. Here is what you can do with it.

Reuse freely, with attribution

All published figures and charts are licensed under CC BY 4.0. Quote them in articles, papers or talks — a link to reportedip.de is the only requirement.

Request custom data

Need a specific time window, a country split or numbers on a breaking incident? We can usually pull custom aggregates from the live dataset within a day. Write to [email protected].

Get quotes and background

Patrick Schlesinger (Munich, Germany) runs the ReportedIP network and is available for technical background on WordPress attack trends, IP reputation and honeypot operations — in English or German.

The plugin behind the data

Much of this dataset is produced — and acted on — by ReportedIP Hive, our WordPress security plugin.

The protection engine is free on every plan: 16 attack sensors, the Web Application Firewall with its baseline ruleset, IP blocking and the complete 2FA suite never sit behind a paywall. When a report documents an attack wave, the sites contributing that data were also the ones blocking it.

Hive PRO adds rule depth and freshness on top: extended PL2 firewall signatures — including the webshell and upload-abuse group that covers the post-exploitation stage of attacks like wp2shell — delivered through a daily, Ed25519-signed rule sync. Free installs receive new rules with plugin releases; PRO installs receive them as they ship.

Threat report FAQ

What is the ReportedIP Threat Report?

The ReportedIP Threat Report is a quarterly analysis of live attack data collected by the ReportedIP community network: honeypot servers and WordPress sites running the Hive security plugin report attacking IP addresses in real time. Each report breaks down attack volumes, techniques and notable incidents from the preceding quarter.

Where does the data come from?

Two sources feed the dataset: a fleet of honeypot servers that imitate WordPress, Drupal and Joomla endpoints, and production WordPress sites whose Hive plugin shares anonymised attack reports (attacker IP, threat category, timestamp) with the community network. Reports are aggregated, weighted by recency and reporter diversity, and scored into a 0–100 confidence value.

Can I reuse the numbers and charts?

Yes. All figures and charts published in the report series may be reused under the Creative Commons Attribution 4.0 licence (CC BY 4.0) — including in news articles, research papers and presentations — with a link to reportedip.de as attribution. For raw data, custom time windows or comment, contact us.

How often is a new report published?

Quarterly. Between reports, the underlying counters update continuously — the live figures on this page and the community blacklist refresh daily or faster.

Contribute to the next report

Every Hive install and honeypot makes the dataset sharper. Join the network — free, no credit card.

Security focused GDPR compliant Made in Germany