{"id":13466252,"url":"https://github.com/evalphobia/go-ip-fraud-check","last_synced_at":"2026-01-23T12:57:40.613Z","repository":{"id":42175511,"uuid":"420731676","full_name":"evalphobia/go-ip-fraud-check","owner":"evalphobia","description":"To check ip address risk and proxy usage using ip address check services","archived":false,"fork":false,"pushed_at":"2021-10-31T16:42:57.000Z","size":111,"stargazers_count":13,"open_issues_count":0,"forks_count":3,"subscribers_count":2,"default_branch":"main","last_synced_at":"2025-03-25T21:35:56.657Z","etag":null,"topics":["abuseipdb","bigdatacloud","ip2proxy","ipaddress","ipdata","ipify","ipinfo","ipregistry","minfraud","shodan","spur"],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/evalphobia.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2021-10-24T16:09:47.000Z","updated_at":"2025-01-11T06:47:04.000Z","dependencies_parsed_at":"2022-09-19T21:54:22.535Z","dependency_job_id":null,"html_url":"https://github.com/evalphobia/go-ip-fraud-check","commit_stats":null,"previous_names":[],"tags_count":8,"template":false,"template_full_name":null,"purl":"pkg:github/evalphobia/go-ip-fraud-check","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/evalphobia%2Fgo-ip-fraud-check","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/evalphobia%2Fgo-ip-fraud-check/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/evalphobia%2Fgo-ip-fraud-check/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/evalphobia%2Fgo-ip-fraud-check/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/evalphobia","download_url":"https://codeload.github.com/evalphobia/go-ip-fraud-check/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/evalphobia%2Fgo-ip-fraud-check/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28692491,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-23T11:01:27.039Z","status":"ssl_error","status_checked_at":"2026-01-23T11:00:26.909Z","response_time":59,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["abuseipdb","bigdatacloud","ip2proxy","ipaddress","ipdata","ipify","ipinfo","ipregistry","minfraud","shodan","spur"],"created_at":"2024-07-31T15:00:41.540Z","updated_at":"2026-01-23T12:57:40.582Z","avatar_url":"https://github.com/evalphobia.png","language":"Go","funding_links":[],"categories":["Go"],"sub_categories":[],"readme":"go-ip-fraud-check\n----\n\n[![License: MIT][401]][402] [![GoDoc][101]][102] [![Release][103]][104] [![Build Status][201]][202] [![Coveralls Coverage][203]][204] [![Codecov Coverage][205]][206]\n[![Go Report Card][301]][302] [![Code Climate][303]][304] [![BCH compliance][305]][306] [![CodeFactor][307]][308] [![codebeat][309]][310] [![Scrutinizer Code Quality][311]][312] [![FOSSA Status][403]][404]\n\n\n\u003c!-- Basic --\u003e\n\n[101]: https://godoc.org/github.com/evalphobia/go-ip-fraud-check?status.svg\n[102]: https://godoc.org/github.com/evalphobia/go-ip-fraud-check\n[103]: https://img.shields.io/github/release/evalphobia/go-ip-fraud-check.svg\n[104]: https://github.com/evalphobia/go-ip-fraud-check/releases/latest\n[105]: https://img.shields.io/github/downloads/evalphobia/go-ip-fraud-check/total.svg?maxAge=1800\n[106]: https://github.com/evalphobia/go-ip-fraud-check/releases\n[107]: https://img.shields.io/github/stars/evalphobia/go-ip-fraud-check.svg\n[108]: https://github.com/evalphobia/go-ip-fraud-check/stargazers\n\n\n\u003c!-- Testing --\u003e\n\n[201]: https://github.com/evalphobia/go-ip-fraud-check/workflows/test/badge.svg\n[202]: https://github.com/evalphobia/go-ip-fraud-check/actions?query=workflow%3Atest\n[203]: https://coveralls.io/repos/evalphobia/go-ip-fraud-check/badge.svg?branch=master\u0026service=github\n[204]: https://coveralls.io/github/evalphobia/go-ip-fraud-check?branch=master\n[205]: https://codecov.io/gh/evalphobia/go-ip-fraud-check/branch/master/graph/badge.svg\n[206]: https://codecov.io/gh/evalphobia/go-ip-fraud-check\n\n\n\u003c!-- Code Quality --\u003e\n\n[301]: https://goreportcard.com/badge/github.com/evalphobia/go-ip-fraud-check\n[302]: https://goreportcard.com/report/github.com/evalphobia/go-ip-fraud-check\n[303]: https://codeclimate.com/github/evalphobia/go-ip-fraud-check/badges/gpa.svg\n[304]: https://codeclimate.com/github/evalphobia/go-ip-fraud-check\n[305]: https://bettercodehub.com/edge/badge/evalphobia/go-ip-fraud-check?branch=master\n[306]: https://bettercodehub.com/\n[307]: https://www.codefactor.io/repository/github/evalphobia/go-ip-fraud-check/badge\n[308]: https://www.codefactor.io/repository/github/evalphobia/go-ip-fraud-check\n[309]: https://codebeat.co/badges/142f5ca7-da37-474f-9264-f708ade08b5c\n[310]: https://codebeat.co/projects/github-com-evalphobia-go-ip-fraud-check-master\n[311]: https://scrutinizer-ci.com/g/evalphobia/go-ip-fraud-check/badges/quality-score.png?b=master\n[312]: https://scrutinizer-ci.com/g/evalphobia/go-ip-fraud-check/?branch=master\n\n\u003c!-- License --\u003e\n[401]: https://img.shields.io/badge/License-MIT-blue.svg\n[402]: LICENSE.md\n[403]: https://app.fossa.com/api/projects/git%2Bgithub.com%2Fevalphobia%2Fgo-ip-fraud-check.svg?type=shield\n[404]: https://app.fossa.com/projects/git%2Bgithub.com%2Fevalphobia%2Fgo-ip-fraud-check?ref=badge_shield\n\n\ngo-ip-fraud-check has a feature to detect fraud from ip addresss.\nit provides both of cli binary and golang API.\n\n# Supported Providers\n\n- [AbuseIPDB](https://www.abuseipdb.com/)\n- [Big Data Cloud](https://www.bigdatacloud.com/)\n- [dbip](https://db-ip.com)\n- [IP2Proxy](https://www.ip2location.com/web-service/ip2proxy)\n- [ip-api.com](https://ip-api.com/)\n- [ipdata](https://ipdata.co/)\n- [ipgeolocation](https://ipgeolocation.io/)\n- [ipify.org](https://www.ipify.org/)\n- [ipinfo.io](https://ipinfo.io/)\n- [IPQualityScore](https://www.ipqualityscore.com/)\n- [Ipregistry](https://ipregistry.co/)\n- [ipstack](https://ipstack.com/)\n- [MaxMind minFraud](https://www.maxmind.com/en/solutions/minfraud-services/)\n- [Shodan](https://shodan.io/)\n- [Spur](https://spur.us/)\n\n\n# Quick Usage for binary\n\n## install\n\nDownload binary from release page, or build from source:\n\n```bash\n$ git clone --depth 1 https://github.com/evalphobia/go-ip-fraud-check.git\n$ cd ./go-ip-fraud-check/cmd\n$ go build -o ./go-ip-fraud-check .\n```\n\n## Subcommands\n\n### root command\n\n```bash\n$ go-ip-fraud-check\nCommands:\n\n  help     show help\n  single   Exec api call of ip address fraud check providers for single ip\n  list     Exec api call of ip address fraud check providers from csv list file\n  providers   Show supported provider types\n```\n\n### single command\n\n`single` command is used to check single ip address.\n\n```bash\n./go-ip-fraud-check single -h\n\nExec api call of ip address fraud check providers for single ip\n\nOptions:\n\n  -h, --help       display help information\n  -p, --provider  *set types of api provider (space separated) --provider='ipdata ipinfo minfraud'\n  -i, --ip         input ip address --ip='8.8.8.8'\n      --route      set if you need route data from IRR --route\n      --debug      set if you need verbose logs --debug\n```\n\nFor example, you can check ip address like below\n\n```bash\n# set auth data\n$ export FRAUD_CHECK_IPDATACO_APIKEY=xxx\n$ export FRAUD_CHECK_IPINFOIO_TOKEN=yyy\n\n# check ip address\n$ ./go-ip-fraud-check single -p 'ipdata ipinfo' -i 8.8.8.8\n\n2021/10/25 00:54:26 [INFO] Use ipdata.co\n2021/10/25 00:54:26 [INFO] Use ipinfo.io\n{\"list\":[{\"service_name\":\"ipdata.co\",\"ip\":\"8.8.8.8\",\"hostname\":\"\",\"isp\":\"Google LLC\",\"organization\":\"\",\"asn\":15169,\"risk_score\":0,\"is_vpn\":false,\"is_hosting\":false,\"is_proxy\":false,\"is_tor\":false,\"is_bot\":false,\"is_bogon\":false,\"has_other_threat\":false,\"threat_comment\":\"\",\"country\":\"US\",\"city\":\"\",\"region\":\"\",\"latitude\":0,\"longitude\":0,\"error\":\"\"},{\"service_name\":\"ipinfo.io\",\"ip\":\"8.8.8.8\",\"hostname\":\"dns.google\",\"isp\":\"\",\"organization\":\"Google LLC\",\"asn\":15169,\"risk_score\":0,\"is_vpn\":false,\"is_hosting\":false,\"is_proxy\":false,\"is_tor\":false,\"is_bot\":false,\"is_bogon\":false,\"has_other_threat\":false,\"threat_comment\":\"\",\"country\":\"US\",\"city\":\"Mountain View\",\"region\":\"California\",\"latitude\":37.4056,\"longitude\":-122.0775,\"error\":\"\"}],\"as_prefix\":null}\n```\n\n### list command\n\n`list` command is used to check multiple ip address from list and save results to output file.\n\n```bash\n./go-ip-fraud-check list -h\n\nExec api call of ip address fraud check providers from csv list file\n\nOptions:\n\n  -h, --help           display help information\n  -p, --provider      *set types of api provider (space separated) --provider='ipdata ipinfo minfraud'\n  -i, --input         *input csv/tsv file path --input='./input.csv'\n  -o, --output        *output tsv file path --output='./output.tsv'\n      --route          set if you need route data from IRR (this might be slow) --route\n      --interval       time interval after a API call to handle rate limit (ms=msec s=sec, m=min) --interval=1.5s\n  -m, --parallel[=2]   parallel number (multiple API calls) --parallel=2\n  -v, --verbose        set if you need detail logs --verbose\n      --debug          set if you use HTTP debug feature --debug\n```\n\nFor example, you can check ip address from csv list like below\n\n```bash\n# set auth data\n$ export FRAUD_CHECK_IPDATACO_APIKEY=xxx\n$ export FRAUD_CHECK_IPINFOIO_TOKEN=yyy\n\n# prepare CSV file\n$ cat input.csv\nip_address\n8.8.8.8\n8.8.4.4\n1.1.1.1\n\n\n# check risk from the CSV file\n$ ./go-ip-fraud-check list -p 'ipdata ipinfo' -i ./input.csv -o ./output.tsv\n2021/10/25 00:58:29 [INFO] Use ipdata.co\n2021/10/25 00:58:29 [INFO] Use ipinfo.io\n2021/10/25 00:58:30 [INFO] exec #: [2]\n2021/10/25 00:58:29 [INFO] exec #: [0]\n2021/10/25 00:58:31 [INFO] exec #: [1]\n\n$ cat output.tsv\nservice\tip_address\thostname\trisk_score\tisp\torganization\tasn\tcountry\tcity\tregion\tlatitude\tlongitude\tis_vpn\tis_hosting\tis_proxy\tis_tor\tis_bot\tis_bogon\thas_other_threat\tthreat_comment\terror\nipdata.co\t8.8.8.8\t\t0.00000\tGoogle LLC\t\t15169\tUS\t\t\t0.00000\t0.00000\tfalse\tfalse\tfalse\tfalse\tfalse\tfalse\tfalse\nipinfo.io\t8.8.8.8\tdns.google\t0.00000\t\tGoogle LLC\t15169\tUS\tMountain View\tCalifornia\t37.40560\t-122.07750\tfalse\tfalse\tfalse\tfalse\tfalse\tfalse\tfalse\nipdata.co\t8.8.4.4\t\t0.00000\tGoogle LLC\t\t15169\tUS\t\t\t0.00000\t0.00000\tfalse\tfalse\tfalse\tfalse\tfalse\tfalse\tfalse\nipinfo.io\t8.8.4.4\tdns.google\t0.00000\t\tGoogle LLC\t15169\tUS\tMountain View\tCalifornia\t37.40560\t-122.07750\tfalse\tfalse\tfalse\tfalse\tfalse\tfalse\tfalse\nipdata.co\t1.1.1.1\t\t0.00000\tCloudflare, Inc.\t\t13335\tAU\t\t\t0.00000\t0.00000\tfalse\tfalse\tfalse\tfalse\tfalse\tfalse\tfalse\nipinfo.io\t1.1.1.1\tone.one.one.one\t0.00000\t\tCloudflare, Inc.\t13335\tUS\tSan Francisco\tCalifornia37.76210\t-122.39710\tfalse\ttrue\tfalse\tfalse\tfalse\tfalse\tfalse\n\n\n\n# if provider has a rate limit, then use --interval and --parallel option.\n$ ./go-ip-fraud-check list -p 'shodan' -i ./input.csv -o ./output.tsv --interval=1.2s --parallel=1\n```\n\n\n### providers command\n\n`providers` command is used to see supported providers.\n\n```bash\n$ ./go-ip-fraud-check providers\n[bigdatacloud ip2proxy ipdata ipgeolocation ipinfo ipqualityscore ipregistry minfraud shodan]\n```\n\n# Quick Usage for API\n\n```go\npackage main\n\nimport (\n\t\"fmt\"\n\n\t\"github.com/evalphobia/go-ip-fraud-check/ipfraudcheck\"\n\t\"github.com/evalphobia/go-ip-fraud-check/provider\"\n\t\"github.com/evalphobia/go-ip-fraud-check/provider/ipdataco\"\n\t\"github.com/evalphobia/go-ip-fraud-check/provider/ipinfoio\"\n)\n\nfunc main() {\n\tconf := ipfraudcheck.Config{\n        // you can set auth values to config directly, otherwise used from environment variables.\n\t\tIPdatacoAPIKey:  \"\u003cyour ipdata.co API key\u003e\",\n\t\tIPinfoioToken:  \"\u003cyour ipinfo.io API token\u003e\",\n\t\tUseRoute:   true,\n\t\tDebug:      false,\n\t}\n\n\tsvc, err := ipfraudcheck.New(conf, []provider.Provider{\n\t\t\u0026ipdataco.IPdatacoProvider{},\n\t\t\u0026ipinfo.IPinfoioProvider{},\n\t})\n\tif err != nil {\n\t\tpanic(err)\n\t}\n\n\t// execute score API\n\tresp, err := svc.CheckIP(\"8.8.8.8\")\n\tif err != nil {\n\t\tpanic(err)\n\t}\n\n\tfor _, r := range resp.List {\n\t\t// just print response in json format\n\t\tb, _ := json.Marshal(r)\n\t\tfmt.Printf(\"%s\", string(b))\n\t}\n}\n```\n\nsee example dir for more examples.\n\n\n# Environment variables\n\n| Name | Description |\n|:--|:--|\n| `FRAUD_CHECK_ABUSEIPDB_APIKEY` | [AbuseIPDB API Key](https://docs.abuseipdb.com/). |\n| `BIGDATACLOUD_APIKEY` | [Big Data Cloud API Key](https://www.bigdatacloud.com/sdk). |\n| `FRAUD_CHECK_DBIP_APIKEY` | [dbip API key](https://db-ip.com/api/doc.php). |\n| `FRAUD_CHECK_IP2PROXY_APIKEY` | [ip2proxy API key](https://www.ip2location.com/web-service/ip2proxy/). |\n| `FRAUD_CHECK_IP2PROXY_PACKAGE` | [ip2proxy package parameter](https://www.ip2location.com/web-service/ip2proxy/). |\n| `FRAUD_CHECK_IPDATACO_APIKEY` | [ipdata.co API key](https://docs.ipdata.co/). |\n| `FRAUD_CHECK_IPGEOLOCATION_APIKEY` | [ipgeolocation API key](https://ipgeolocation.io/documentation.html). |\n| `FRAUD_CHECK_IPIFY_APIKEY` | [ipify API key](https://geo.ipify.org/docs). |\n| `FRAUD_CHECK_IPINFOIO_TOKEN` | [ipinfo.io API token](https://ipinfo.io/developers). |\n| `IPQS_APIKEY` | [IPQualityScore API Key](https://www.ipqualityscore.com/documentation/overview). |\n| `FRAUD_CHECK_IPSTACK_APIKEY` | [ipstack API key](https://ipstack.com/documentation). |\n| `IPREGISTRY_APIKEY` | [Ipregistry API Key](https://ipregistry.co/docs/authentication). |\n| `MINFRAUD_ACCOUNT_ID` | [MaxMind Account ID](https://support.maxmind.com/account-faq/license-keys/how-do-i-generate-a-license-key/). |\n| `MINFRAUD_LICENSE_KEY` | [MaxMind License Key](https://support.maxmind.com/account-faq/license-keys/how-do-i-generate-a-license-key/). |\n| `FRAUD_CHECK_SHODAN_APIKEY` | [Shodan API Key](https://developer.shodan.io/api/requirements). |\n| `FRAUD_CHECK_SPUR_TOKEN` | [spur API token](https://spur.us/products/context-api). |\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fevalphobia%2Fgo-ip-fraud-check","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fevalphobia%2Fgo-ip-fraud-check","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fevalphobia%2Fgo-ip-fraud-check/lists"}