Checking for 404 errors in your logs can reveal more than just broken links, it can also expose files and URLs that attackers are actively scanning for. To track this behavior, we set up hundreds of honeypots and analyzed live web traffic data, giving us insight into which files and URLs are being targeted across the internet.
The table bellow list the top URLs being scanned on WordPress sites. This list of updated daily and shows the top plugins, backdoors and files that attacker are lookin for specifically to WordPress.
| Rank | Scanned URL | Counter |
|---|---|---|
| #1 | /wp-login.php | 612,417 |
| #2 | /wp-json/oembed/1.0/embed | 46,672 |
| #3 | /wp-cron.php | 25,429 |
| #4 | /wordpress | 23,979 |
| #5 | /wp-content/plugins/hellopress/wp_filemanager.php | 22,670 |
| #6 | /wp-admin | 21,760 |
| #7 | /wp | 20,801 |
| #8 | /wp-content/plugins/fix/up.php | 17,698 |
| #9 | /wp.php | 17,371 |
| #10 | /wp-includes/wlwmanifest.xml | 16,742 |
| #11 | /web/wp-includes/wlwmanifest.xml | 14,147 |
| #12 | /wordpress/wp-includes/wlwmanifest.xml | 14,010 |
| #13 | /wp/wp-includes/wlwmanifest.xml | 13,783 |
| #14 | /blog/wp-includes/wlwmanifest.xml | 13,351 |
| #15 | /2019/wp-includes/wlwmanifest.xml | 13,208 |
| #16 | /shop/wp-includes/wlwmanifest.xml | 13,119 |
| #17 | /website/wp-includes/wlwmanifest.xml | 12,428 |
| #18 | /news/wp-includes/wlwmanifest.xml | 12,262 |
| #19 | /wp-admin/css | 10,522 |
| #20 | /wp-plain.php | 10,470 |
| #21 | /wp-json/sfwd-assignment/1 | 8,681 |
| #22 | /wordpress/wp-admin/setup-config.php | 8,594 |
| #23 | /wp-content/index.php | 8,156 |
| #24 | /wp-admin/classwithtostring.php | 8,103 |
| #25 | /wp-sitemap.xml | 8,045 |
| #26 | /appWP/lab/wp-admin/css/colors/blue/blue.php | 7,970 |
| #27 | /wp-content/plugins/woocommerce/includes/gateways/locks.php | 7,910 |
| #28 | /wp-admin/images/moon.php | 7,876 |
| #29 | /wp-content/wp-conflg.php | 7,783 |
| #30 | /wp-admin/setup-config.php | 7,725 |
| #31 | /wp-content/themes/seotheme/db.php | 7,495 |
| #32 | /wp-content/admin.php | 7,081 |
| #33 | /wp-admin/index.php | 7,071 |
| #34 | /wp-content/themes/admin.php | 7,045 |
| #35 | /wp-content/autoload_classmap.php | 6,944 |
| #36 | /2018/wp-includes/wlwmanifest.xml | 6,913 |
| #37 | /wp-admin/css/colors/blue/index.php | 6,786 |
| #38 | /wp-admin/js/index.php | 6,742 |
| #39 | /wp-content/themes/about.php | 6,723 |
| #40 | /wp-content/video | 6,575 |
| #41 | /wp-admin/wp-conflg.php | 6,557 |
| #42 | /wp-api.php | 6,455 |
| #43 | /2020/wp-includes/wlwmanifest.xml | 6,438 |
| #44 | /wp-admin/js/autoload_classmap.php | 6,426 |
| #45 | /wp-setup.php | 6,289 |
| #46 | /wp-includes/fonts/admin.php | 6,257 |
| #47 | /wp-json/mod/v1/check-site | 6,198 |
| #48 | /wp-content/about.php | 5,997 |
| #49 | /wp-admin/maint/about.php | 5,855 |
| #50 | /wp-good.php | 5,693 |
| #51 | /wp-includes/fonts/index.php | 5,685 |
| #52 | /wp-content/style.php | 5,646 |
| #53 | /wp-content | 5,631 |
| #54 | /wp-editor.php | 5,594 |
| #55 | /wp-includes/IXR/autoload_classmap.php | 5,585 |
| #56 | /wp-json/sfwd-lessons/1 | 5,437 |
| #57 | /wp-json/sfwd-topic/1 | 5,302 |
| #58 | /wp-admin/edit-tags.php | 5,257 |
| #59 | /wp-content/plugins/WordPressCore/include.php | 5,210 |
| #60 | /wp-content/plugins/wpterm.php | 5,198 |
| #61 | /wp-admin/admin-ajax.php | 5,165 |
| #62 | /wp-trackback.php | 5,050 |
| #63 | /wp-json/custom/v1 | 4,922 |
| #64 | /wp-content/plugins/admin.php | 4,907 |
| #65 | /wp1/wp-includes/wlwmanifest.xml | 4,785 |
| #66 | /wp-admin.php | 4,743 |
| #67 | /wp-admin/js | 4,673 |
| #68 | /wp-admin/includes/index.php | 4,632 |
| #69 | /wp-content/plugins/pwnd/pwnd.php | 4,587 |
| #70 | /wp-admin/style.php | 4,531 |
| #71 | /wp-admin/profile.php | 4,478 |
| #72 | /wp-conflg.php | 4,406 |
| #73 | /wordpress/wp-login.php | 4,391 |
| #74 | /wp-admin/js/widgets/cloud.php | 4,387 |
| #75 | /wp-admin/install.php | 4,304 |
| #76 | /wp-content/themes/style.php | 4,301 |
| #77 | /wp-admin/plugins.php | 4,294 |
| #78 | /wp-admin/file.php | 4,285 |
| #79 | /wp-admin/edit.php | 4,284 |
| #80 | /wp-admin/js/about.php | 4,273 |
| #81 | /wp-admin/includes/colour.php | 4,181 |
| #82 | /wp-admin/css/colors/blue | 4,158 |
| #83 | /wp-json/sfwd-courses | 4,142 |
| #84 | /wp-signin.php | 4,130 |
| #85 | /wp-blog.php | 4,010 |
| #86 | /wp-content/plugins/pwnd/as.php | 4,003 |
| #87 | /wp-admin/css/colors/blue/atomlib.php | 3,954 |
| #88 | /wp-admin/wp-admins.php | 3,916 |
| #89 | /wp-admin/css/about.php | 3,781 |
| #90 | /wp-includes/blocks/about.php | 3,754 |
| #91 | /wp-admin/network/network.php | 3,738 |
| #92 | /wp-admin/wp-login.php | 3,708 |
| #93 | /wp-l0gin.php | 3,699 |
| #94 | /wp-admin/post-new.php | 3,642 |
| #95 | /wp-content/plugins/simple-ajax-chat/includes/sac-check-user.php | 3,616 |
| #96 | /wp-includes/wp-class.php | 3,586 |
| #97 | /wp-content/plugins/about.php | 3,542 |
| #98 | /wp-admin/includes | 3,508 |
| #99 | /wp-admin/js/wp-conflg.php | 3,506 |
| #100 | /wp-content/classwithtostring.php | 3,500 |
| #101 | /wp-content/uploads | 3,480 |
| #102 | /wp-admin/css/colors/ectoplasm/about.php | 3,474 |
| #103 | /wp-admin/css/colors/blue/about.php | 3,470 |
| #104 | /wp-json/oembed | 3,427 |
| #105 | /wp-json/wp | 3,420 |
| #106 | /wp-admin/css/qPyYcxpHKCu.php | 3,410 |
| #107 | /test/wp-includes/wlwmanifest.xml | 3,408 |
| #108 | /wp-json/sfwd-lessons | 3,394 |
| #109 | /wp-aa.php | 3,375 |
| #110 | /wp-json/sfwd-courses/1 | 3,363 |
| #111 | /wp-admin/autoload_classmap.php | 3,356 |
| #112 | /wp-admin/mah.php | 3,348 |
| #113 | /wp-admin/chosen.php | 3,255 |
| #114 | /wp-json/sfwd-topic | 3,254 |
| #115 | /wp-includes/about.php | 3,242 |
| #116 | /wp-config.php.bak | 3,166 |
| #117 | /site/wp-includes/wlwmanifest.xml | 3,162 |
| #118 | /cms/wp-includes/wlwmanifest.xml | 3,145 |
| #119 | /wp-admin/admin.php | 3,096 |
| #120 | /wp-admin/maint | 3,091 |
| #121 | /wp-includes/ID3/index.php | 3,090 |
| #122 | /wp-content/upgrade/index.php | 3,075 |
| #123 | /wp-content/uploads/de_fb_uploads/b.php | 3,074 |
| #124 | /wp-includes/ID3 | 3,033 |
| #125 | /wp-admin/images | 2,985 |
| #126 | /wp-admin/wp.php | 2,974 |
| #127 | /wp-content/plugins/autoload_classmap.php | 2,933 |
| #128 | /wp-config | 2,903 |
| #129 | /wp-json/sfwd-assignment | 2,899 |
| #130 | /wp-admin/js/widgets | 2,891 |
| #131 | /wp-admin/css/colors/light/wp-login.php | 2,887 |
| #132 | /wp-admin/images/admin.php | 2,790 |
| #133 | /wp-includes/html-api/about.php | 2,784 |
| #134 | /wp-content/1.php | 2,752 |
| #135 | /wp-2019.php | 2,726 |
| #136 | /wp-admin/includes/header.php | 2,712 |
| #137 | /wp-content/uploads/index.php | 2,710 |
| #138 | /es/wp-json/oembed/1.0/embed | 2,703 |
| #139 | /wp-includes/style-engine/autoload_classmap.php | 2,660 |
| #140 | /wp-content/plugins/ioxi/ioxi/dropdown.php | 2,632 |
| #141 | /wp-includes/css/autoload_classmap.php | 2,601 |
| #142 | /wp-includes/ALFA_DATA/alfacgiapi/perl.alfa | 2,591 |
| #143 | /wp-admin/includes/about.php | 2,579 |
| #144 | /wp-admin/includes/wp-conflg.php | 2,573 |
| #145 | /wp-content/languages/autoload_classmap.php | 2,551 |
| #146 | /wp-admin/images/index.php | 2,534 |
| #147 | /wp-content/themes/seotheme/mar.php | 2,512 |
| #148 | /wp-content/uploads/json.php | 2,503 |
| #149 | /wp-content/wp.php | 2,497 |
| #150 | /wp-includes/widgets/autoload_classmap.php | 2,494 |
| #151 | /wp-json/wp-block-editor | 2,483 |
| #152 | /wp-logs.php | 2,472 |
| #153 | /wp-json/commerce/paypal/payments/start-trial | 2,456 |
| #154 | /wp-wso.php | 2,455 |
| #155 | /wp-admin/images/about.php | 2,452 |
| #156 | /wp-content/file.php | 2,421 |
| #157 | /wp-setting.php | 2,414 |
| #158 | /wp-content/plugins/up/main.php | 2,413 |
| #159 | /wp-json/commerce/paypal/payments/order | 2,412 |
| #160 | /wp-content/plugin.php | 2,402 |
| #161 | /wp_wrong_datlib.php | 2,401 |
| #162 | /wp-includes/fonts/autoload_classmap.php | 2,399 |
| #163 | /wp-content/plugins/apikey/apikey.php | 2,397 |
| #164 | /wp-content/x.php | 2,374 |
| #165 | /wp-file.php | 2,335 |
| #166 | /wp-json/litespeed/v1/cdn_status | 2,298 |
| #167 | /wp-gr.php | 2,288 |
| #168 | /wp-error.php | 2,284 |
| #169 | /wp-includes/autoload_classmap.php | 2,277 |
| #170 | /wp-includes/pomo/about.php | 2,256 |
| #171 | /wp-content/click.php | 2,249 |
| #172 | /wp-includes/SimplePie/chosen.php | 2,249 |
| #173 | /wp-includes/IXR/chosen.php | 2,245 |
| #174 | /wp-includes | 2,244 |
| #175 | /wp-includes/Requests/about.php | 2,243 |
| #176 | /wp-comments.php | 2,236 |
| #177 | /wp-configs.php | 2,230 |
| #178 | /wp-content/plugins/simple/simple.php | 2,216 |
| #179 | /wp-includes/wp_class_datlib.php | 2,194 |
| #180 | /wp-includes/js/tinymce/langs/about.php | 2,180 |
| #181 | /wp-includes/PHPMailer/file.php | 2,176 |
| #182 | /sanitas-bk/wp-json/metform/v1/forms/views/654 | 2,147 |
| #183 | /wp-content/uploads/chosen.php | 2,134 |
| #184 | /wp-includes/certificates/chosen.php | 2,133 |
| #185 | /wp-content/plugins/apikey/apikey.php.suspected | 2,129 |
| #186 | /wp-includes/ID3/about.php | 2,117 |
| #187 | /wp-includes/css | 2,117 |
| #188 | /wpc.php | 2,110 |
| #189 | /wp-admin/js/widgets/index.php | 2,088 |
| #190 | /wp-content/themes/pridmag/db.php | 2,077 |
| #191 | /wp-content/themes | 2,058 |
| #192 | /wp-content/languages/index.php | 2,055 |
| #193 | /wp-content/plugins/revslider/includes/external/page/index.php | 2,048 |
| #194 | /wp-json/sfwd-courses/17/groups | 2,037 |
| #195 | /wp-admin/maint/index.php | 2,036 |
| #196 | /wp-content/plugins/index.php | 2,033 |
| #197 | /wp-json/sfwd-courses/17/prerequisites | 2,025 |
| #198 | /wp-json/commerce/paypal/payments/payment-token | 2,019 |
| #199 | /wp-json/intercom/v1/webhook | 2,005 |
| #200 | /wp2/wp-includes/wlwmanifest.xml | 1,991 |
| #201 | /wp-content/admin-header.php | 1,990 |
| #202 | /wp-includes/IXR | 1,975 |
| #203 | /wp-content/plugins/wp-conflg.php | 1,970 |
| #204 | /wp-includes/customize/chosen.php | 1,951 |
| #205 | /wp-activate.php | 1,940 |
| #206 | /wp-includes/Text/about.php | 1,921 |
| #207 | /wp-includes/rest-api | 1,916 |
| #208 | /wp-json/elementor-ai | 1,879 |
| #209 | /wp-json/elementor-pro | 1,866 |
| #210 | /wp-admin/function.php | 1,843 |
| #211 | /wp-links.php | 1,839 |
| #212 | /sito/wp-includes/wlwmanifest.xml | 1,838 |
| #213 | /wp-includes/Text/autoload_classmap.php | 1,831 |
| #214 | /wp-includes/style-engine/about.php | 1,822 |
| #215 | /wp-admin/dropdown.php | 1,800 |
| #216 | /wp-admin/css/index.php | 1,799 |
| #217 | /wp-json/wordfence | 1,790 |
| #218 | /wp-conflg/function.php | 1,790 |
| #219 | /wp-content/plugins/hellopress/wp_mna.php | 1,773 |
| #220 | /wp-content/themes/wp-pridmag/init.php | 1,772 |
| #221 | /wp-signup.php | 1,770 |
| #222 | /wp-includes/rest-api/index.php | 1,762 |
| #223 | /wp-admin/css/colors | 1,756 |
| #224 | /wp-includes/assets/index.php | 1,748 |
| #225 | /wp-json/sure-triggers/v1 | 1,725 |
| #226 | /wp-content/themes/classwithtostring.php | 1,712 |
| #227 | /wp-content/upgrade | 1,699 |
| #228 | /wp-json/commerce/paypal/payments/confirm | 1,688 |
| #229 | /wp-includes/blocks/wp-conflg.php | 1,687 |
| #230 | /wp-includes/fonts | 1,672 |
| #231 | /wp-admin/network/index.php | 1,670 |
| #232 | /wp-includes/SimplePie/about.php | 1,669 |
| #233 | /wp-json/sfwd-assignment/0 | 1,647 |
| #234 | /wp-content/plugins/pwnd-1/pwnd.php | 1,638 |
| #235 | /wp-includes/blocks/calendar/index.php | 1,637 |
| #236 | /wp-content/plugins/core-plugin/include.php | 1,628 |
| #237 | /wp-content/plugins/revslider/includes/external/page | 1,624 |
| #238 | /wp-update.php | 1,612 |
| #239 | /wp-json/wp-site-health | 1,608 |
| #240 | /wp-admin/images/cloud.php | 1,592 |
| #241 | /wp-includes/SimplePie | 1,592 |
| #242 | /wp-json | 1,592 |
| #243 | /wp-json/sure-triggers/v1/automation/action | 1,585 |
| #244 | /wp-includes/block-bindings | 1,582 |
| #245 | /wp-content/themes/twentytwenty/404.php | 1,574 |
| #246 | /wp-includes/customize/about.php | 1,561 |
| #247 | /wp-admin/includes/xmrlpc.php | 1,557 |
| #248 | /wp-includes/images | 1,548 |
| #249 | /wp-json/commerce/paypal/payments/cancel | 1,546 |
| #250 | /wp-admin/css/colors/blue/admin.php | 1,543 |
| #251 | /wp-includes/js/jcrop/Jcrop.php | 1,529 |
| #252 | /wp-includes/Text/Diff/Renderer | 1,522 |
| #253 | /wp-content/plugins/dummyyummy/wp-signup.php | 1,519 |
| #254 | /wp-content/plugins | 1,487 |
| #255 | /wp-info.php | 1,485 |
| #256 | /wp-admin/css/colors/ectoplasm | 1,465 |
| #257 | /wp-includes/PHPMailer | 1,462 |
| #258 | /wp-includes/block-supports | 1,453 |
| #259 | /wp-content/languages/about.php | 1,451 |
| #260 | /wp-includes/images/smilies/about.php | 1,451 |
| #261 | /wp-includes/assets | 1,428 |
| #262 | /wp-json/elementor | 1,424 |
| #263 | /wp-includes/widgets/about.php | 1,420 |
| #264 | /blog/wp-login.php | 1,418 |
| #265 | /wp-class.php | 1,415 |
| #266 | /wp-json/google-site-kit | 1,414 |
| #267 | /wp-includes/certificates | 1,401 |
| #268 | /wp-admin/meta | 1,401 |
| #269 | /wp-includes/blocks/site-title/index.php | 1,398 |
| #270 | /wp-includes/IXR/about.php | 1,395 |
| #271 | /wp-admin/css/colors/midnight | 1,390 |
| #272 | /wp-content/plugins/janus/janus.php | 1,385 |
| #273 | /wp-includes/pomo | 1,381 |
| #274 | /wp-admin/css/colors/index.php | 1,376 |
| #275 | /wp-includes/style-engine | 1,370 |
| #276 | /wp-admin/maint/admin.php | 1,338 |
| #277 | /wp-content/cong.php | 1,333 |
| #278 | /wp-json/storychief | 1,332 |
| #279 | /wp-content/backups-dup-lite | 1,332 |
| #280 | /wp-includes/pomo/pomo.php | 1,326 |
| #281 | /wp-includes/js/codemirror/index.php | 1,323 |
| #282 | /wp-includes/sitemaps/providers | 1,321 |
| #283 | /wp-includes/html-api | 1,316 |
| #284 | /features/wordpress-management-tools | 1,311 |
| #285 | /wp-admin/user/xmrlpc.php | 1,309 |
| #286 | /wp-json/v1/u | 1,296 |
| #287 | /wp-content/plugins/wp-automatic/inc/csv.php | 1,292 |
| #288 | /wp-includes/block-patterns/about.php | 1,291 |
| #289 | /wp-json/mod/v1/clients/themes/j6FbdsfF230jtfGKl2WXTwui8jVLt3uR | 1,289 |
| #290 | /wp-includes/Text | 1,286 |
| #291 | /wp-json/mod/v1/clients/plugins/j6FbdsfF230jtfGKl2WXTwui8jVLt3uR | 1,285 |
| #292 | /wp-old | 1,281 |
| #293 | /wp-admin/css/admin.php | 1,275 |
| #294 | /wp-admin/radio.php | 1,269 |
| #295 | /wp-json/aioseo | 1,267 |
| #296 | /wp-content/themes/twentytwentytwo/index.php | 1,262 |
| #297 | /wp-json/webp-converter | 1,260 |
| #298 | /wp-json/code-snippets | 1,258 |
| #299 | /wp-admin/about.php | 1,258 |
| #300 | /wp-content/themes/index.php | 1,258 |
| #301 | /wp-includes/customize | 1,253 |
| #302 | /wp-cron | 1,249 |
| #303 | /wp-json/mod/v1/clients/plugins/jcdaFPpvQo28KCS7T9Aa6BKXzTwHupSJ | 1,244 |
| #304 | /wp-includes/css/index.php | 1,239 |
| #305 | /wp-includes/index.php | 1,234 |
| #306 | /wp-content/languages | 1,233 |
| #307 | /wp-includes/rest-api/about.php | 1,223 |
| #308 | /wp-includes/assets/autoload_classmap.php | 1,220 |
| #309 | /wp-admin/user/chosen.php | 1,216 |
| #310 | /wp-includes/images/about.php | 1,209 |
| #311 | /wp-admin/css/colors/sunrise | 1,208 |
| #312 | /wp-json/mod/v1/clients/themes/jcdaFPpvQo28KCS7T9Aa6BKXzTwHupSJ | 1,205 |
| #313 | /wp-json/buddypress/v1/members | 1,203 |
| #314 | /cgi-bin/wp-login.php | 1,196 |
| #315 | /sanitas-bk/wp-json/metform/v1/forms/views/727 | 1,195 |
| #316 | /wp-admin/alfa.php | 1,183 |
| #317 | /wp-admin/x.php | 1,178 |
| #318 | /wp-mail.php | 1,176 |
| #319 | /wp-json/commerce/paypal/payments/setup-token | 1,175 |
| #320 | /wp-includes/js/crop | 1,169 |
| #321 | /wp-content/content.php | 1,165 |
| #322 | /wp-json/wp/v2/users | 1,157 |
| #323 | /wp-content/plugins/linkpreview/db.php | 1,152 |
| #324 | /wp-admin/network | 1,150 |
| #325 | /wp-content/plugins/xt | 1,149 |
| #326 | /wp-includes/Text/wp-conflg.php | 1,138 |
| #327 | /wp-json/sfwd-courses/[]/users | 1,136 |
| #328 | /wp-blog-header.php | 1,127 |
| #329 | /wp-includes/rest-api/fields | 1,125 |
| #330 | /wp-admin/network/chosen.php | 1,121 |
| #331 | /wp/wp-login.php | 1,121 |
| #332 | /wp-includes/fonts/about.php | 1,117 |
| #333 | /wp-content/mu-plugins-old | 1,117 |
| #334 | /2021/wp-includes/wlwmanifest.xml | 1,113 |
| #335 | /wp-22.php | 1,103 |
| #336 | /wp-content/upgrade-temp-backup/about.php | 1,095 |
| #337 | /wp-json/akismet | 1,090 |
| #338 | /wp-admin/css/colors/about.php | 1,089 |
| #339 | /wp-admin/user | 1,079 |
| #340 | /wp-admin/js/js/cache.php | 1,078 |
| #341 | /wp-admin/css/css/cache.php | 1,078 |
| #342 | /wp-admin/images/images/cache.php | 1,076 |
| #343 | /wp-user.php | 1,076 |
| #344 | /wp-includes/SimplePie/index.php | 1,075 |
| #345 | /wp-includes/images/wp-login.php | 1,073 |
| #346 | /wp-includes/install.php | 1,066 |
| #347 | /wp-admin/css/colors/ocean | 1,064 |
| #348 | /wp-includes/widgets | 1,051 |
| #349 | /wp-includes/sitemaps/autoload_classmap.php | 1,050 |
| #350 | /wp-files.php | 1,048 |
| #351 | /wp-content/plugins/yanierin/akcc.php | 1,044 |
| #352 | /wp-admin/images/file.php | 1,041 |
| #353 | /wp-content/postnews.php | 1,028 |
| #354 | /wp-includes/wp-includes_function.php | 1,026 |
| #355 | /wp-json/commerce/paypal/payments/capture | 1,020 |
| #356 | /wp-content/themes/twentytwentytwo | 1,020 |
| #357 | /wp-admin/js/widgets/about.php | 1,015 |
| #358 | /wp-admin/network/admin.php | 1,014 |
| #359 | /sim.php/wp-includes/certificates/plugins.php | 1,011 |
| #360 | /wp-content/plugins/janusv5/janus.php | 1,010 |
| #361 | /wp-config.php | 1,002 |
| #362 | /wp-mn.php | 1,000 |
| #363 | /wp-admin/users.php | 999 |
| #364 | /wp-includes/sitemaps | 999 |
| #365 | /wp-admin/includes/cloud.php | 995 |
| #366 | /wp-admin/user/wp-login.php | 988 |
| #367 | /wp-admin/css/colors/midnight/colors.php | 986 |
| #368 | /wp-includes/js/codemirror | 986 |
| #369 | /wpls.php | 980 |
| #370 | /wp-admin/css/colors/blue/xboom.php | 974 |
| #371 | /wp-content/plugins/Cache/Cache.php | 973 |
| #372 | /wp-admin/postnews.php | 972 |
| #373 | /wp-content/plugins/seoplugins/db.php | 967 |
| #374 | /wp-admin/images/xmrlpc.php | 967 |
| #375 | /wp-json/vimeography | 965 |
| #376 | /wp-config-sample.php | 963 |
| #377 | /wp-content/themes/twentyfive/include.php | 963 |
| #378 | /revendedor/wp-login.php | 959 |
| #379 | /wp-json/mod/v1/clients/plugins/iHNBUuF2wAFhhJ1LTSZnjkZre9wu6lm8 | 958 |
| #380 | /wp-json/wccom-site | 956 |
| #381 | /wp-json/mod/v1/clients/themes/iHNBUuF2wAFhhJ1LTSZnjkZre9wu6lm8 | 955 |
| #382 | /wp-includes/block-supports/index.php | 952 |
| #383 | /wp-json/wc/v3/customers | 949 |
| #384 | /wp-sigunq.php | 948 |
| #385 | /wp-confiq.php | 941 |
| #386 | /wp-json/mod/v1/clients/themes/wHHMLaOxt4Hcl2lbCkfy8HStyJaThms0 | 937 |
| #387 | /wp-login | 933 |
| #388 | /wp-includes/Requests | 932 |
| #389 | /wp-json/mod/v1/clients/plugins/wHHMLaOxt4Hcl2lbCkfy8HStyJaThms0 | 929 |
| #390 | /wp-content/plugins/seoplugins/mar.php | 928 |
| #391 | /wp-content/themes/alera/alpha.php | 927 |
| #392 | /wp-json/bbp-api/v1/users | 923 |
| #393 | /wp-admin/css/colors/light | 923 |
| #394 | /wp-cli.php | 918 |
| #395 | /wp-content/uploads/admin.php | 915 |
| #396 | /wp-admin/maint/siteone.php | 912 |
| #397 | /wp-admin/maint/wp-login.php | 912 |
| #398 | /wp-includes/theme-compat | 910 |
| #399 | /wp-json/whm | 908 |
| #400 | /wp-head.php | 908 |
| #401 | /wp-includes/Text/Diff/Engine/about.php | 908 |
| #402 | /wp-load.php | 906 |
| #403 | /wp-includes/images/media | 905 |
| #404 | /wp-includes/images/smilies | 888 |
| #405 | /media/wp-includes/wlwmanifest.xml | 887 |
| #406 | /wp-includes/Requests/Response | 882 |
| #407 | /wp-admin/js/let.php | 879 |
| #408 | /wp-includes/customize/index.php | 876 |
| #409 | /wp-admin/css/colors/light/browser.php | 872 |
| #410 | /wp-includes/block-patterns | 872 |
| #411 | /wp-includes/pomo/index.php | 869 |
| #412 | /wp-content/uploads/wp-conflg.php | 868 |
| #413 | /wp-json/commerce/paypal/onboarding/access_token | 866 |
| #414 | /wp-json/mod/v1/clients/themes/d2Gr3fzrGMfqzG0cE8SasxjVd0dg81MH | 864 |
| #415 | /wp-admin/maint/techl.php | 863 |
| #416 | /wp-json/mod/v1/clients/plugins/d2Gr3fzrGMfqzG0cE8SasxjVd0dg81MH | 861 |
| #417 | /wp-includes/Requests/Cookie | 861 |
| #418 | /wp-includes/SimplePie/autoload_classmap.php | 859 |
| #419 | /wp-content/themes/travel/issue.php | 853 |
| #420 | /wp-admin/css/colors/blue/uploader.php | 851 |
| #421 | /wp-admin/js/wp-login.php | 849 |
| #422 | /wp/wp-admin/includes | 847 |
| #423 | /wp-admin/network/xmrlpc.php | 846 |
| #424 | /wp-content/radio.php | 844 |
| #425 | /wp-admin/css/wp-admins.php | 841 |
| #426 | /wp-admin/images/lightspped.php | 840 |
| #427 | /wp-json/ldlms/v2/users | 837 |
| #428 | /wp-admin/css/colors/coffee | 833 |
| #429 | /wp-admin/css/colors/ectoplasm/wp-login.php | 828 |
| #430 | /wp-admin/network/cloud.php | 826 |
| #431 | /wp-json/publishpress-authors | 824 |
| #432 | /wp-includes/blocks | 822 |
| #433 | /wp-json/mod/v1/clients/themes/dfH6fTJpNKPXFmf72OBbcx9a6kb73dAu | 819 |
| #434 | /wp-admin/css/wp-conflg.php | 817 |
| #435 | /wp-json/wp-mail-smtp | 812 |
| #436 | /wp-links-opml.php | 809 |
| #437 | /wp-admin/maint/maint.php | 809 |
| #438 | /wp-includes/IXR/admin.php | 808 |
| #439 | /wp-content/uploads/2025 | 804 |
| #440 | /wp-admin/css/colors/modern | 804 |
| #441 | /wp-json/commerce/paypal/payments/cards | 799 |
| #442 | /wp-includes/admin.php | 799 |
| #443 | /wp-content/worksec.php | 798 |
| #444 | /wp-admin/maint/fie.php | 797 |
| #445 | /wp-fmfile.php | 797 |
| #446 | /wp-content/uploads/autoload_classmap.php | 797 |
| #447 | /wp-includes/sitemaps/rz.php | 793 |
| #448 | /wp-admin/includes/port.php | 790 |
| #449 | /wp-includes/IXR/index.php | 790 |
| #450 | /wp-content/themes/twenty/twenty.php | 789 |
| #451 | /wp-content/languages/chosen.php | 787 |
| #452 | /wp-json/penci | 786 |
| #453 | /wp-includes/Text/Diff/Renderer/about.php | 786 |
| #454 | /wp-json/buddyboss-app/v1/signup/form | 785 |
| #455 | /wp-admin/maint/akcc.php | 784 |
| #456 | /wp-content/upgrade/about.php | 782 |
| #457 | /wordpress-vs-html | 776 |
| #458 | /wp-includes/ID3/autoload_classmap.php | 776 |
| #459 | /.well-known/pki-validation/wp-login.php | 774 |
| #460 | /wp-includes/style.php | 773 |
| #461 | /wp-content/themes/aahana/json.php | 772 |
| #462 | /wp-json/mod/v1/clients/plugins/dfH6fTJpNKPXFmf72OBbcx9a6kb73dAu | 772 |
| #463 | /wp-includes/images/crystal | 771 |
| #464 | /wp-includes/images/smilies/index.php | 769 |
| #465 | /wp-admin/includes/rk2.php | 767 |
| #466 | /wp-admin/css/colors/coffee/index.php | 766 |
| #467 | /wp-content/plugins/WordPressCore | 760 |
| #468 | /wp-includes/Text/Diff/Engine | 759 |
| #469 | /wp-json/wc/v2/products | 755 |
| #470 | /wp-admin/admin-post.php | 754 |
| #471 | /wp-admin/js/widgets/about.php7 | 753 |
| #472 | /wp-content/install.php | 752 |
| #473 | /wp-includes/php-compat | 748 |
| #474 | /wp-admin/css/colors/light/about.php | 746 |
| #475 | /wp-content/plugins/wp-help/admin/wp-fclass.php | 746 |
| #476 | /wp-includes/class-wp-network-cron.php | 740 |
| #477 | /wp-admin/user/index.php | 739 |
| #478 | /wp-seo.php | 732 |
| #479 | /wp-includes/sodium_compat | 731 |
| #480 | /wp-admin/css/colors/blue/wp-login.php | 727 |
| #481 | /wp-includes/js/tinymce/skins/lightgray/img/index.php | 727 |
| #482 | /wp-json/mod/v1/clients/plugins/dyWekFLDnqyfJipUzKAffzSwMelqeVvg | 725 |
| #483 | /wp-admin/user/about.php | 721 |
| #484 | /wp-json/mod/v1/clients/themes/dyWekFLDnqyfJipUzKAffzSwMelqeVvg | 716 |
| #485 | /wp-index.php | 715 |
| #486 | /wp-content/themes/file.php | 715 |
| #487 | /wp-includes/ID3/el.php | 713 |
| #488 | /wp-content/plugins/newsletters-lite/newsletters-lite-ajax.php | 713 |
| #489 | /wp-content/cache/index.php | 712 |
| #490 | /wp-json/profile | 710 |
| #491 | /wp-includes/html-api/wp-login.php | 709 |
| #492 | /wp-includes/style-engine/index.php | 704 |
| #493 | /wp-admin/remote | 703 |
| #494 | /wp-json/gravity-pdf | 702 |
| #495 | /wp-includes/images/wlw | 701 |
| #496 | /wp-json/gwiz | 700 |
| #497 | /wp-includes/we2.php | 698 |
| #498 | /wp-includes/x.php | 696 |
| #499 | /wp-content/themes/astra/inc/ki1k.php | 696 |
| #500 | /wp-content/plugins/elementor/assets/js/undefined | 695 |
Data was last updated on: Jan 31, 2026
We love logs. In this section we will share some of the data we are parsing from our logs and honeypots we have live.
Logging for fun and a good night of sleep.
Latest log-based threat analysis added.
Do you have an idea for a research that is not here? See something wrong? Contact us at support@noc.org
14 days free trial. No credit card required.