WordPress sites that publicly leak usernames via the REST API or author archives, making brute-force attacks easier.
/wp-json/wp/v2/users) or the author archive redirect (/?author=1). Knowing a valid username is the first half of a brute-force attack. It can be mitigated with a security plugin or by blocking these endpoints.
| Domain | WP Version | Theme | Headers | Other Issues | Last Scanned |
|---|---|---|---|---|---|
| d*e*a*.a*t*r*i*t*.org 🔒 | 6.9.4 | gutenify-photography | F | — | Jun 6, 2026 |
| m*b*l*f*o*p*n*r*.c*f*o*s*a*e.org 🔒 | 7.0 | kadence | F | — | Jun 6, 2026 |
| n*v*g*t*e*e*e*d.nl 🔒 | 7.0 | arilewp | F | — | Jun 6, 2026 |
| p*1*.fr 🔒 | Unknown | hardwork | F | — | Jun 6, 2026 |
| b*o*.p*w*8.net 🔒 | 7.0 | indreni_dos | F | — | Jun 6, 2026 |
| e*t*p.org 🔒 | 6.9 | twentytwenty | D | — | Jun 6, 2026 |
| e*.p*w*8.net 🔒 | 7.0 | indreni_dosb_en | F | — | Jun 6, 2026 |
| b*b*s*e*p*u*c*s*.com 🔒 | 6.7.5 | dynamic-news-lite | F | — | Jun 6, 2026 |
| b*b*s*e*p*r*s.com 🔒 | Unknown | storefront | F | — | Jun 6, 2026 |
| b*b*s*e*p*r*.com 🔒 | 7.0 | babysleeppro | F | — | Jun 6, 2026 |
| b*b*s*e*p*o*e.com 🔒 | Unknown | Maggie | F | — | Jun 6, 2026 |
| b*b*s*e*p*o*c*.com 🔒 | Unknown | Divi | F | — | Jun 6, 2026 |
| b*b*s*t*e*s*n*a*.com 🔒 | 7.0 | becorp | F | — | Jun 6, 2026 |
| b*b*s*t*e*s*c*e.com 🔒 | 7.0 | hello-elementor | F | — | Jun 6, 2026 |
| b*b*s*t*e*k*t*.com 🔒 | 5.1.19 | university-hub | F | — | Jun 6, 2026 |
| b*b*s*t*e*j*c*.com 🔒 | 7.0 | hello-elementor | F | — | Jun 6, 2026 |
| b*b*s*t*e*-*a*k*n*.com 🔒 | 6.4.8 | babysitter | F | — | Jun 6, 2026 |
| b*b*s*t*i*g*h*s*l*r.com 🔒 | 7.0 | bridge | F | — | Jun 6, 2026 |
| b*b*s*t*i*g*o*i*o.com 🔒 | 7.0 | bridge | F | — | Jun 6, 2026 |
| b*b*s*t*i*g*a*e*.com 🔒 | 7.0 | minimalistique | F | — | Jun 6, 2026 |
| b*b*s*t*i*g*m*k*n*s.com 🔒 | 7.0 | astra | D | — | Jun 6, 2026 |
| b*o*.b*s*l*k*.com 🔒 | 7.0 | BassLakeHotels | F | — | Jun 6, 2026 |
| m*t*l*u*l*i*g*o*p*n*.com 🔒 | Unknown | Avada | A | — | Jun 6, 2026 |
| f*t*t*g*-*r*i*s*e*m.de 🔒 | 7.0 | hello-biz | F | — | Jun 6, 2026 |
| a*d*e*-*r*n*t*r*n*.de 🔒 | 6.1.10 | graphy | F | — | Jun 6, 2026 |
| n*r*.aero 🔒 | Unknown | Unknown | B | — | Jun 6, 2026 |
| d*e*m*.kz 🔒 | 7.0 | blonwe | F | — | Jun 6, 2026 |
| c*t*b*c.fr 🔒 | 7.0 | mh-magazine-lite | F | — | Jun 6, 2026 |
| z*h*a*z*-*r*r*c*.de 🔒 | Unknown | rick | F | — | Jun 6, 2026 |
| e*u*a*i*n*g*n*y.ca 🔒 | 6.8.3 | hello-elementor | F | — | Jun 6, 2026 |
| f*t*l*f*t*g*a*i*.c*m.br 🔒 | 6.9.4 | piroll | F | — | Jun 6, 2026 |
| s*v*h*l*y.org 🔒 | 7.0 | benevolence-wpl | F | — | Jun 6, 2026 |
| j*s*u*l*i*g*l*.com 🔒 | 7.0 | hello-elementor | F | — | Jun 6, 2026 |
| b*u*e*a*d*a*t*.com 🔒 | 7.0 | xstore | F | — | Jun 6, 2026 |
| s*l*r*o*o*a*i*.c*m.br 🔒 | 6.9.4 | twentynineteen | F | — | Jun 6, 2026 |
| r*d*0*5.org 🔒 | 7.0 | websoup5 | F | — | Jun 6, 2026 |
| d*.o*g.ee 🔒 | 7.0 | twentyseventeen | F | — | Jun 6, 2026 |
| e*t*s*a*e.net 🔒 | 6.9.4 | journalistVG | F | — | Jun 6, 2026 |
| m*o*p*s.fi 🔒 | 7.0 | myoppis | F | — | Jun 6, 2026 |
| m*b*o*e*g*n*.com 🔒 | 6.0.12 | opus-blog | F | — | Jun 6, 2026 |
| m*b*g*e*l*w*a*k*a*k.com 🔒 | 7.0 | hestia | F | — | Jun 6, 2026 |
| m*b*g*o*r*e.com 🔒 | 7.0 | bluehost-blueprint | F | — | Jun 6, 2026 |
| m*b*g*o*s.com 🔒 | 7.0 | cobble | F | — | Jun 6, 2026 |
| m*b*t*v.com 🔒 | 7.0 | coinflip | F | — | Jun 6, 2026 |
| m*b*s*r*o*k*.com 🔒 | Unknown | pro | F | — | Jun 6, 2026 |
| m*b*z*h*t*o*.com 🔒 | Unknown | Unknown | F | — | Jun 6, 2026 |
| m*b*l*d*s*g*s.com 🔒 | 7.0 | hello-elementor | F | — | Jun 6, 2026 |
| m*b*l*z*v*c*t*o*.com 🔒 | 7.0 | sitka | F | — | Jun 6, 2026 |
| t*y*3*5*f*i*i*l.ph 🔒 | 7.0 | jupiterx | F | — | Jun 6, 2026 |
| b*8*.construction 🔒 | Unknown | flatsome | C | — | Jun 6, 2026 |