About Firewall IPs

A community-reported IP blacklist and firewall integration platform — servers and websites report attackers, and get a shared blocklist back in return.

How it works

Firewall IPs sits between individual firewalls and a shared, consolidated blacklist. When a participating server or site blocks an attacking IP, it reports that IP here. The platform deduplicates reports, applies netblock consolidation and expiry rules, and redistributes the current blocklist back to every participant — so an attacker blocked on one server gets blocked everywhere else, usually within minutes.

Server / CSF integration

For servers running ConfigServer Security & Firewall. One install script wires CSF's block events straight into the shared blacklist — both reporting outbound and blocking inbound.

Setup docs

WordPress plugin

Detects brute-force logins, XML-RPC abuse, user enumeration, and vulnerability scans against your WordPress site, and blocks known-bad IPs from the shared WordPress blocklist automatically.

Plugin details on request

Free tools

Frequently asked questions

FirewallIPs.com is a community threat-intelligence platform. Participating servers and WordPress sites report the IP addresses attacking them, and in return receive a consolidated blocklist built from everyone else's reports — so one server blocking an attacker helps every other participant block it too.

The IP Location lookup, the blacklist check on the homepage, and the CSF configuration optimizer are free for anyone to use, no account required. Reporting IPs and downloading the full blocklist via the API requires a free API key from an administrator.

A server running CSF runs a one-line install script that wires CSF's BLOCK_REPORT hook to automatically report every IP CSF blocks, and subscribes the server to the shared blacklist so it also blocks IPs reported by other participating servers.

Yes. The FirewallIPs Security WordPress plugin detects brute-force login attempts, XML-RPC abuse, user enumeration, and vulnerability scanning against a site, reports the offending IPs, and blocks visitors from the shared WordPress-specific blocklist.

They're tracked separately by default — CSF reports feed the general blacklist, WordPress reports feed a WordPress-specific blocklist — but an IP reported by both ecosystems appears in both exports.

No. The blacklist check on the homepage and the IP Location tool are both open to use without signing up.

Want to integrate a server or site? See the API documentation for setup instructions and endpoint reference.