3 ms·
They talk about detection methods a little in their FAQ: https://w3techs.com/faq https://w3techs.com/faq PHP probably gets a lot of extra hits in places it mi
by bguebert 4y ago
They talk about detection methods a little in their FAQ:
https://w3techs.com/faq https://w3techs.com/faq
PHP probably gets a lot of extra hits in places it might not be used a whole lot. For a long time web host providers had it pre-installed by default. Plus wordpress is used a lot and they can detect that from the admin/edit page.
- EGreg 4y agoHow does Wordpress know it's powering 40% of all sites in the world? Where does it get the stats
- bguebert 4y agoI'm not for sure about how wordpress would get their stats, but I imagine it's something like scan the internet and put "/wp-admin" behind the base url. If it comes back with the wordpress login page, then count it. At least that's how it seems like hackers find out if you have wordpress from my http server logs. Also someone posted this thing a while back that does some detection like this to find out what tech is powering the website you are on: https://www.wappalyzer.com/ https://www.wappalyzer.com/ I'm not related to them in any way and I don't know how accurate it is but it was interesting.
- dawnerd 4y agoWordPress is pretty easy to detect even when wp-admin is hidden. People seem to not know theres a json api that exposes a lot of information. It's a good idea to disable showing authors since this can give an attacker information they can use to exploit in a few different ways. We had to do this for a high profile client a while back and wrote a little helpful plugin I bet they are undercounting a bit since the large content sites will keep their WordPress install outside of public view completely and the site is just headless. [0] https://github.com/firstandthird/wp-disable-authors https://github.com/firstandthird/wp-disable-authors