4 ms·
I'm not for sure about how wordpress would get their stats, but I imagine it's something like scan the internet and put "/wp-admin" behind the base url. If it c
by bguebert 4y ago
I'm not for sure about how wordpress would get their stats, but I imagine it's something like scan the internet and put "/wp-admin" behind the base url. If it comes back with the wordpress login page, then count it. At least that's how it seems like hackers find out if you have wordpress from my http server logs.
Also someone posted this thing a while back that does some detection like this to find out what tech is powering the website you are on:
https://www.wappalyzer.com/ https://www.wappalyzer.com/
I'm not related to them in any way and I don't know how accurate it is but it was interesting.
- dawnerd 4y agoWordPress is pretty easy to detect even when wp-admin is hidden. People seem to not know theres a json api that exposes a lot of information. It's a good idea to disable showing authors since this can give an attacker information they can use to exploit in a few different ways. We had to do this for a high profile client a while back and wrote a little helpful plugin I bet they are undercounting a bit since the large content sites will keep their WordPress install outside of public view completely and the site is just headless. [0] https://github.com/firstandthird/wp-disable-authors https://github.com/firstandthird/wp-disable-authors