WordPress sites that publicly leak usernames via the REST API or author archives, making brute-force attacks easier.
/wp-json/wp/v2/users) or the author archive redirect (/?author=1). Knowing a valid username is the first half of a brute-force attack. It can be mitigated with a security plugin or by blocking these endpoints.
| Domain | WP Version | Theme | Headers | Other Issues | Last Scanned |
|---|---|---|---|---|---|
| h*u*a*x.com 🔒 | 5.9.13 | betheme | D | — | Jun 7, 2026 |
| s*m*j*i*a*s*m*a*.com 🔒 | Unknown | Unknown | F | — | Jun 7, 2026 |
| t*m*o*a*d*s*o*t*o*.net 🔒 | 6.9.4 | daniela | F | — | Jun 7, 2026 |
| c*t*p*e*i*m.com 🔒 | Unknown | Divi | F | — | Jun 7, 2026 |
| b*g*a*y*a*d.com 🔒 | 7.0 | astra | F | — | Jun 7, 2026 |
| b*g*a*t*s*p*l*.com 🔒 | Unknown | flatsome | F | — | Jun 7, 2026 |
| b*g*a*l*g*e*s*e*t*.com 🔒 | 7.0 | Avada | F | — | Jun 7, 2026 |
| b*g*a*b*b*.com 🔒 | 7.0 | woodmart | F | — | Jun 7, 2026 |
| h*w*o*e*c*e*p*i*l*n*t*c*e*s.net 🔒 | 6.9.4 | traveler-blog-lite | F | — | Jun 7, 2026 |
| b*g*u*p*t*r.com 🔒 | 7.0 | generatepress | F | — | Jun 7, 2026 |
| b*g*u*p*d*s*o*a*.com 🔒 | 7.0 | hello-elementor | F | — | Jun 7, 2026 |
| b*g*u*b*o*i*.com 🔒 | Unknown | Unknown | F | — | Jun 7, 2026 |
| b*g*u*b*o*s*e*s*o*c*s*.com 🔒 | Unknown | promoter | F | — | Jun 7, 2026 |
| b*g*u*b*s*.com 🔒 | 7.0 | ona | F | — | Jun 7, 2026 |
| b*g*u*k*a*v*s*l*g.com 🔒 | Unknown | blockbase-premium | F | — | Jun 7, 2026 |
| b*g*u*f*s*i*a*.com 🔒 | 7.0 | hello-elementor | F | — | Jun 7, 2026 |
| t*a*e*.n*k*.com 🔒 | 7.0 | third-style | F | — | Jun 7, 2026 |
| g*n*a*o*y.n*k*.com 🔒 | 7.0 | twentyten | F | — | Jun 7, 2026 |
| e*s.it 🔒 | Unknown | Unknown | C | — | Jun 7, 2026 |
| i*o*a*p*a*t*e*o*a.it 🔒 | 5.8.13 | transportex | F | — | Jun 7, 2026 |
| p*o*t*p*i*o*o*i.it 🔒 | Unknown | hexabet | C | — | Jun 7, 2026 |
| l*g*c*.a*t*n*l*a*r*m*w*r*.com 🔒 | 7.0 | Impreza | F | — | Jun 7, 2026 |
| p*a*p*d*a*t.ch 🔒 | 6.2 | playpodcastch | F | — | Jun 7, 2026 |
| l*s*e*x*r*n*f*r*e*.ch 🔒 | 7.0 | lesyeuxgrandfermes | F | — | Jun 7, 2026 |
| a*l*s*n*i*d*.co 🔒 | Unknown | Divi | F | — | Jun 7, 2026 |
| e*i*i*m*n*i*i.com 🔒 | 7.0 | solace | F | — | Jun 7, 2026 |
| n*w.e*r*u.ch 🔒 | 7.0 | kadence | F | — | Jun 7, 2026 |
| f*a*.u*a*.ro 🔒 | 7.0 | hello-elementor | F | — | Jun 7, 2026 |
| s*o*-*e*n*n*.cn | Unknown | justnews4 | F | — | Jun 7, 2026 |
| t*t*2.fr 🔒 | 4.8.28 | virtue | F | — | Jun 7, 2026 |
| i*o*e*a*d*b*a*h.org 🔒 | 7.0 | themify-ultra | F | — | Jun 7, 2026 |
| g*a*a*g*e*n*b*.org 🔒 | Unknown | indigotree-theme-2025 | F | — | Jun 7, 2026 |
| n*u*o*e*e*i*.c*m.ar 🔒 | 7.0 | astra | F | — | Jun 7, 2026 |
| g*n*h*n.s*i*t*i*.com 🔒 | Unknown | cocoon-master | F | — | Jun 7, 2026 |
| h*r*r*u*-*e*r*a*s.de 🔒 | 6.9.4 | salient | F | — | Jun 7, 2026 |
| c*n*e*t*-*i*a*v*.de 🔒 | Unknown | Divi | F | — | Jun 7, 2026 |
| o*l*n*k*r*-*a*u*a*t*r.de 🔒 | 7.0 | thrive-theme | F | — | Jun 7, 2026 |
| b*t*5*3.ec 🔒 | Unknown | brand-site | F | — | Jun 7, 2026 |
| w*d.a*l.m*b*u*h*s*.me 🔒 | 6.9.4 | astra | F | — | Jun 7, 2026 |
| d*u*s*h*r*u*d*i*c*b*n*.de 🔒 | 7.0 | palm-beach-child | D | — | Jun 7, 2026 |
| k*g*j*n*.de 🔒 | Unknown | personal-cv-resume | F | — | Jun 7, 2026 |
| m*s*k*a*a*s.ch 🔒 | Unknown | flexi-wpauto | D | — | Jun 7, 2026 |
| t*l*f*d*h*m*d*f*e*.com 🔒 | 7.0 | blocksy | F | — | Jun 7, 2026 |
| m*r*a*-*e*g*r.de 🔒 | Unknown | Divi | F | — | Jun 7, 2026 |
| a*v*n*-*e*l*n*.de 🔒 | Unknown | Divi | F | — | Jun 7, 2026 |
| x*-*h*b*m*e*b*h*-*l*.de 🔒 | Unknown | Divi | F | — | Jun 7, 2026 |
| k*i*t*n*j*n*k.de 🔒 | Unknown | oshin | D | — | Jun 7, 2026 |
| s*h*a*.org 🔒 | 7.0 | twentyseventeen | F | — | Jun 7, 2026 |
| l*k*s*e*i*z.a*t.pl 🔒 | 7.0 | obelisk | F | — | Jun 7, 2026 |
| s*u*l*y*a*.com 🔒 | 7.0 | kadence | D | — | Jun 7, 2026 |