WordPress sites that publicly leak usernames via the REST API or author archives, making brute-force attacks easier.
/wp-json/wp/v2/users) or the author archive redirect (/?author=1). Knowing a valid username is the first half of a brute-force attack. It can be mitigated with a security plugin or by blocking these endpoints.
| Domain | WP Version | Theme | Headers | Other Issues | Last Scanned |
|---|---|---|---|---|---|
| d*r*i*o*i*t*m*c*.c*m.br 🔒 | 7.0 | hello-elementor | F | — | Jun 7, 2026 |
| p*r*a*.t*l*r*s*r.com 🔒 | 7.0 | bam | D | — | Jun 7, 2026 |
| c*n*r*c*o*c*v*r.c*m.au 🔒 | 6.9.4 | hello-theme-child-master | F | — | Jun 7, 2026 |
| e*t*e*g*o*p.c*m.au 🔒 | Unknown | pro | C | — | Jun 7, 2026 |
| b*i*g*t*n*o.com 🔒 | 7.0 | kadence | F | — | Jun 7, 2026 |
| b*i*e*u*i*e*h.com 🔒 | 7.0 | securitech | F | — | Jun 7, 2026 |
| b*i*s.com 🔒 | Unknown | dara | D | — | Jun 7, 2026 |
| b*i*b*a*.com 🔒 | 7.0 | hello-elementor | F | — | Jun 7, 2026 |
| b*i*o*d*o*s*.com 🔒 | Unknown | graceful | F | — | Jun 7, 2026 |
| b*i*w*e*l.com 🔒 | 7.0 | wiib | F | — | Jun 7, 2026 |
| b*i*i*i.com 🔒 | Unknown | justnews1 | F | — | Jun 7, 2026 |
| b*i*i*m.com 🔒 | 7.0 | blacksilver | F | — | Jun 7, 2026 |
| b*i*p*.com 🔒 | Unknown | plain_text | F | — | Jun 7, 2026 |
| b*i*y*.com 🔒 | 6.9.4 | astra | F | — | Jun 7, 2026 |
| b*i*-*c*n*m*c*.com 🔒 | Unknown | iotix | F | — | Jun 7, 2026 |
| b*i*m*d*a.com 🔒 | 6.9.4 | twentynineteen | F | — | Jun 7, 2026 |
| b*i*p*r*s.com 🔒 | 6.9.4 | hello-elementor | F | — | Jun 7, 2026 |
| b*i*d.com 🔒 | 7.0 | vikinger | F | — | Jun 7, 2026 |
| o*i*n*d*n*a*.com 🔒 | 4.9.29 | genova_tpl | F | — | Jun 7, 2026 |
| t*s*a*d.vn 🔒 | 6.7.4 | flatsome | F | — | Jun 7, 2026 |
| i*p*r*u*-*o*n.com 🔒 | Unknown | mts_best | D | — | Jun 7, 2026 |
| q*c*r*u*.com 🔒 | 6.7.5 | hello-elementor | F | — | Jun 7, 2026 |
| a*o*s.ru 🔒 | 7.0 | oceanwp | F | Jun 7, 2026 | |
| m*v*g*l*h*n*.de 🔒 | 6.9.4 | Avada | F | — | Jun 7, 2026 |
| y*s*i*h.fr 🔒 | Unknown | Avada | F | — | Jun 7, 2026 |
| e*l*p*e*g*.fr 🔒 | 7.0 | bridge | F | — | Jun 7, 2026 |
| n*w*l*m*u*h*a*i*.c*.nz 🔒 | 6.9.4 | astra | F | — | Jun 7, 2026 |
| h*b.o*r*u*e.eu 🔒 | 5.9.13 | astra | F | — | Jun 7, 2026 |
| s*n*i*a*.com 🔒 | 7.0 | flatsome | F | — | Jun 7, 2026 |
| r*d*o*m*.c*m.mx 🔒 | 7.0 | flatsome | F | — | Jun 7, 2026 |
| s*f*a*i*o*o*.j*.net 🔒 | Unknown | flatsome | C | — | Jun 7, 2026 |
| s*h.r*.com 🔒 | 7.0 | flatsome | F | — | Jun 7, 2026 |
| e*e*t*o*i*a.r*.com 🔒 | 7.0 | flatsome | F | — | Jun 7, 2026 |
| f*z*s*r*q.s*.com 🔒 | 6.9.4 | flatsome | F | — | Jun 7, 2026 |
| d*v*i*e*t*2*.t*n*a*o*l*s.de | Unknown | suffusion | F | — | Jun 7, 2026 |
| d*t*y*h*o*4.com 🔒 | 7.0 | vw-hosting-services | F | — | Jun 7, 2026 |
| n*u.c*r*s*i*n*-*t*i*z.de | 6.9.4 | writee | F | — | Jun 7, 2026 |
| l*q*i*-*e*g*i*.de 🔒 | Unknown | Divi | F | — | Jun 7, 2026 |
| t*n*o*.i*e*.es 🔒 | Unknown | Divi | F | — | Jun 7, 2026 |
| c*s*n*m*t*v*.com 🔒 | Unknown | livelylines | D | — | Jun 7, 2026 |
| i*y*s.de 🔒 | 7.0 | page-builder-framework | F | — | Jun 7, 2026 |
| p*o*l*d*t*s*n*e.com | 6.9.4 | cosion | F | — | Jun 7, 2026 |
| v*g*z*n*.de 🔒 | 6.9.4 | vigo_wptheme | B | — | Jun 7, 2026 |
| d*c*o*a*o.f*d*u.u*.cl 🔒 | Unknown | twentytwenty | F | — | Jun 7, 2026 |
| m*s*o*u*l*c*d*d.u*p.cl 🔒 | 6.9.4 | museopublicidad-udp-02 | F | — | Jun 7, 2026 |
| g*n*r*.u*p.cl 🔒 | 7.0 | portable_m | F | — | Jun 7, 2026 |
| i*s*i*u*o*s*u*i*s*u*o*i*t*c*s.u*p.cl 🔒 | 7.0 | udp_portable | F | — | Jun 7, 2026 |
| c*t*d*a*a*r*t*v*s*e*y*.u*r*.cl 🔒 | 6.2.2 | astra | D | — | Jun 7, 2026 |
| s*d*l.cl 🔒 | 7.0 | flatsome | F | — | Jun 7, 2026 |
| r*v*s*a*r*f*.u*p.cl 🔒 | 7.0 | dyad-2-wpcom | F | — | Jun 7, 2026 |