Reputation on the attempt
login_view, login_attempt and login_failed events carry the risk score and reasons, including the malicious-IP signal backed by FindIP threat feeds that cover credential stuffing and brute force.
Credential stuffing is thousands of login attempts that each look ordinary. FindIP Shield records login views, attempts and failures with the network behind them, including IPs reported in the FindIP malicious-IP feeds that cover credential stuffing and brute force, so the pattern is visible on the login form rather than in a log file a week later.
Free Preview · 10,000 events per site per day · No credit card · Terms apply
A lockout after five failures stops a naive script and locks out the real owner of a targeted account. A credential-stuffing run spreads its attempts across a proxy pool so each IP fails only once or twice.
What the attempts share is the network: hosting ranges, proxies, Tor, and IPs already reported in malicious-IP feeds for credential stuffing and brute force. That is visible per attempt, before any lockout logic runs.
Shield reports it on login_attempt and login_failed events, lets you add a Turnstile check to the login form for the risky cases only, and gives your server a way to verify the session before issuing a token.
login_view, login_attempt and login_failed events carry the risk score and reasons, including the malicious-IP signal backed by FindIP threat feeds that cover credential stuffing and brute force.
A session whose IP or ASN changes between the login page and the submit is recorded with the reason. Combined with a hosting signal it is a strong indicator of automation.
Add a Turnstile challenge to the login form for high scores, and verify the session from your server with your secret key before you issue a session. The browser response is friction; the server check is the boundary.
For applications with their own login form. The npm package fits bundled apps; the script tag fits server-rendered pages. Pair either with the server verification endpoint.
Sign in, add the domain you control, and pick a privacy mode. You get a public site key; nothing connects until it is on a page.
Paste one script tag before the closing body tag, or run npm install @findip/shield and call init() with your site key. Auto page and form tracking is on by default.
Submit a test on your own form. The event, its risk score and the reasons behind it appear on the site dashboard moments later.
Prefer another route? Want the same reputation data in your backend directly? Use the IP reputation API.
Create a free Shield site, install it, and look at the first real event before you decide on any response.
Try Shield on my loginFree Preview · Informational risk signals · You control enforcement