2 ms·
Solution: add http auth to your /wp-admin directory
by brianshaffer 9y ago
Solution: add http auth to your /wp-admin directory
- ryanlol 9y agoThis will break things. Edit: Why the downvotes? Lots of non-admin stuff lives inside wp-admin, "add http auth" is terrible advice. https://censys.io/ipv4?q=%22wp-admin%2Fadmin-ajax.php%22 https://censys.io/ipv4?q=%22wp-admin%2Fadmin-ajax.php%22 Hundreds of thousands of sites with "wp-admin/admin-ajax.php" on their index should more than prove this.
- brianshaffer 9y agoGood point. There may be some things that are needed publicly, which you could whitelist. I've seen the whole directory behind the auth on a handful of sites though. ex] tether.to/wp-admin