This plugin allows you to automatically insert your Project Honeypot links into all of your pages and block IP addresses that are listed on the Http:BL list from Project Honeypot. There is an option to block IP addresses that have been blocked by Spamcop using their blacklist as well.
To prevent bots from using brute force attacks and scanning your site there is an option to block users that fail to login a set number of times or use blocked user names. You can also block IP addresses that generate a large number of 404 errors. This plugin will also prevent WordPress User Enumeration and automatically block anyone attempting it.
- Extract the downloaded Zip file.
- Upload the ‘honeypot-toolkit’ directory to the
- Activate the plugin through the ‘Plugins’ menu in WordPress
- Use the menu item called Honeypot Toolkit to get the plugin set up.
You should set up an account on the project honeypot website at https://www.projecthoneypot.org if you want to use Project Honeypot.
Where do I get the script for my honeypot?
You must sign up for an account on https://www.projecthoneypot.org. Then go to https://www.projecthoneypot.org/manage_honey_pots.php to set up your honeypot and follow the instructions. After the script has been placed on your site enter the url of your script on the Honeypot Toolkit settings page.
Contributors & Developers
“Honeypot Toolkit” is open source software. The following people have contributed to this plugin.Contributors
“Honeypot Toolkit” has been translated into 2 locales. Thank you to the translators for their contributions.
Translate “Honeypot Toolkit” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Fixed typo in 4.4.3. Used _transient_timeout instead of _site_transient_timeout
Changing transients to use site transients for better compatibility with multisite installs
Added check for transients to ensure that they expire rather than living forever
Added check for empty array when no honeypot positions are selected
Added DNS_A argument to dns_get_record calls to only pull A records since that is all the plugin uses.
Made the logic a little more efficient for deciding if a DNS record was returned.
Added check to make sure honeypot link isn’t included in post excerpt if the_content hook is used.
Changed the way activity count is updated to use the primary key so the database table will not get locked.
Fixed missing ajax save function for content honeypot.
Fixed check on settings page to make sure honeypot locations have been saved.
Added options to set the locations where the honeypot will appear.
Fixed PHP warning when checking for a temporary whitelist entry and one doesn’t exist.
Fixed call to explode that was missing the delimiter
Changed how the server variables are handled. The variables can be a comma delimited list.
Added rel=”nofollow” to honeypot links.
Fixed deprecated message for PHP 7.x
Fixed issue on multisite installs where the plugin would check for temporary whitelist entries in a database table prefixed with the current site DB prefix. Changed $wpdb->prefix to $wpdb->base_prefix
Added functionality to temporarily whitelist an IP if it has passed the Project Honeypot and Spamcop blacklist checks. This prevents the same IP being checked multiple times while a user is visiting a site.
Fix for dropdown css on IP list pages.
Added the ability to enter a . in the band username field.
Added functionality to automatically whitelist the web servers IP address so it doesn’t block itself while doing a health check.
Improved input validation and sanatization.
Added a checkbox to the IP lists so all entries can be selected.
Added functionality to submit the search query when the enter key is pressed in the search box.
Changed the way notes are stored so line breaks will not be stripped.
Fixing bug with login monitoring. IP v6 addresses were not properly being blocked.
Added better notes when a user is blocked.
Updating scripts to use my new domain name for documentation links so plugins like wordfence don’t alert users.
Updating readme to reflect compatibility with WP 5.1.
Fixed styling issue with jQuery UI dialog.
Changed IP links in the admin to go to domaintools.com since they can handle IPv6 addresses.
Changed from using wp_get_sites to get_sites to remove a deprecated message and stop using a deprecated function.
Changed functionality when updating the check interval for Project Honeypot and Spamcop lists. Now it will reset the timeout when a new interval is set.
Improved functionality to check blocked IP addresses on the SPamcop and Project Honeypot lists.
Fixed typo to correct DB prefix in activate function
Made change to ensure the activate function is called when a new version is released.
Added support for blocking IPv6 addresses.
Added better support for blocking proxy addresses.
Changed validation functionality to use filter_var for IP addresses.
Added temporary patch for IP v6 addresses.
Fixed bug with transient set and get for blacklist check.
Fixed bug that prevented IPs on the blacklist from being removed if they weren’t on the Spamcop or Project Honeypot lists anymore.
Fixed a bug that moved the dialog box above the top of the screen during an ajax call.
Changed the process to hide usernames so that it processes 100 at a time. This way it doesn’t fail if there is a large number of users.
Hid the option to show IP lists on individual sites from the settings page if the site is not a multisite install.
Forced user nicenames to be md5 hashed when usernames are hidden regardless of whether they match the user login or not.
Added option to change an authors user nicename to an md5 hash to hide their real username.
Changed the plugin to be a network only plugin. Now all IP lists are managed at the network level for multisite installs.
Fixed a bug that left details of the IP list entries escaped for MySQL when displaying them on the admin page.
Fixed a bug that prevents the user from selecting Project Honeypot or Spamcop Entry when editing an entry in the blocked list.
Moved the code to sanitize server variables for use in determining the visitors IP so that it will not throw an undefined index warning.
Added search functionality to search the different IP lists and make it easier to find an entry.
Fixed a bug that stopped the loading indicator from displaying when data was submitted.
Added indicator to show sorting direction in ip lists.
Added tabs to the settings page.
Added options to paging so you can go to any page in the list and change the type of records in the lists.
Added paging to the ip list pages.
Adding sanitization to the server keys used to prevent injection from request headers.
Ensuring that the IP being checked is an IP 4 address.
Fixed typo in the spamcop check function that checked the address of the visitor and not the address on the blocked list.