Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Repeated requests for random .php paths are usually automated probes: bots try familiar application, plugin, or vulnerability-related paths and observe the server’s response. A request in a log means someone tried a path; it does not, by itself, show that the file exists, that the probe worked, or that your site is compromised.

Why do bots request PHP files my site does not have?

Automated scanners can send requests for recognizable files and endpoints across many websites without first determining which software each site runs. A bot may therefore request a WordPress path on a site that does not use WordPress. That is a plausible explanation for an individual log entry, not proof of the sender’s method or your site’s software.

Popular application paths can attract repeated attention. WordPress identifies xmlrpc.php as a frequent brute-force target and notes that attempts can be distributed across sources. This helps explain why a recognizable WordPress path might appear in logs, but the request does not establish that WordPress is installed or that the attempt succeeded. See the WordPress guidance on brute-force attacks.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Research has also documented automated browsing that probes for web-shell names and likely sensitive file extensions. The findings in the 2021 IEEE Symposium on Security and Privacy study apply to its dataset; they are not a general estimate of how often websites receive PHP probes. Read the study.

Does a request mean my site was hacked?

No. A request is an attempt to reach a URL, not evidence that the requested file was present or that code ran. A 404 response is consistent with an unsuccessful guess, but it is not a complete security assessment: it tells you about that response, not the overall state of the site.

Interpret the filename alongside the HTTP method, response status, timing, surrounding requests, and effect on the service. A single unsuccessful request is different from a sequence that reaches sensitive resources or coincides with unexpected site behavior. There is no universal request-rate cutoff in the cited guidance that distinguishes harmless probing from an incident.

How should I check the requests?

  1. Inspect the full request. Record the path, method, status code, timestamp, and source information available in your access logs.
  2. Look for a sequence. Check whether the same source—or many sources—requests a series of related paths, and whether any requests receive successful responses.
  3. Check for corroborating signs. Investigate unexpected changes to files or accounts, unusual application behavior, successful access to sensitive resources, or service degradation.
  4. Review your exposed software. Confirm that the web server, CMS, plugins, themes, and other public-facing components are maintained and patched.
  5. Keep useful records. Continue monitoring relevant logs so you can compare activity and investigate outcomes. NIST’s Guidelines on Securing Public Web Servers includes log monitoring alongside patching, upgrades, and backups.

What response makes sense?

Choose a response based on impact and what the site actually needs. If probes are merely reaching nonexistent paths without harming service, monitoring and keeping software current may be proportionate. If traffic creates meaningful load or targets real endpoints, consider a firewall rule or website application firewall (WAF), while preserving legitimate site functions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Edge or host-provided WAF

A WAF can sit between internet traffic and the hosting server, filtering requests before they reach the origin. WordPress’s hardening guidance describes a website firewall as an intermediary; its brute-force guidance discusses edge or WAF protections for blocking harmful traffic before it reaches the server. This can reduce traffic reaching the origin, but rules need to account for legitimate endpoints and should preserve enough logging to investigate activity.

Narrow server-level or application rules

A rule at the web server or application can reject or handle specific unwanted paths at the origin. Scope it narrowly, document exceptions, and verify that site features still work. Blocking every .php request can break a PHP-based site or integrations that depend on PHP endpoints. For WordPress, identify which endpoints the site uses before blocking any of them.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How do I decide whether to escalate?

  • Monitor and maintain: requests receive unsuccessful responses, the site behaves normally, and there are no corroborating signs of unauthorized change.
  • Investigate promptly: requests receive unexpected successful responses, touch sensitive resources, or appear alongside changed files or accounts, unusual application behavior, or service degradation.
  • Mitigate operational impact: traffic is burdening the service or repeatedly targeting real endpoints; consider a narrowly configured WAF or server rule and check that legitimate functionality remains available.

WordPress security guidance also describes coordination between site owners, hosting providers, and security providers in mitigating attacks. See WordPress.org’s security overview.

Best Value
ZPARIK 6 Pack Guest Checks Books, Server Note Pads, Pink
  • Standard size: 6 pink server note pads, Each Book Comes with 50 bound order slips - that's 300 ticket sheets total! Check Pads Size 6.75 x 3.5 inch.
  • Convenient Work: These guest check books for servers have a tear-free dotted line that is easy to rip off. You can give as a customer copy or keep for record keeping. We've provided extra rows on the back for additional note taking.Perfect For Restaurants, Lounges, Hotels, Cafes, And Waiters To Use.
  • Record Important Information: These server note pads can record important information.Each ticket has a unique serial number printed at the top, dates, order details, number of guests, order amount, table numbers etc. They are lightweight, small and can fit most aprons. They can be used on-demand and can help decrease errors in orders, while improving work efficiency.
  • High Quality: Sturdy, Not Drop Powder, It's Thick, You Can Write On The Back And Front Easily.Their whole page printing has clear handwriting and a reasonable layout. On the customer retention part of each guest check, "THANK YOU" on the back to make customers feel appreciated.
  • Contact Us: We're confident that the quality of the server note pads will go beyond your expectation. If you experience an issue, feel free to contact us, we'll appreciate it to learn from your experience, and we'll make it better
Rank #4
ZPARIK 6 Pack Guest Checks Books, Server Note Pads, Green
  • Standard Size: 6 green server note pads, Each Book Comes with 50 bound order slips - that's 300 ticket sheets total! Check Pads Size 6.75 x 3.5 inch.
  • Convenient Work: These guest check books for servers have a tear-free dotted line that is easy to rip off. You can give as a customer copy or keep for record keeping. We've provided extra rows on the back for additional note taking.Perfect For Restaurants, Lounges, Hotels, Cafes, And Waiters To Use.
  • Record Important Information: These server note pads can record important information.Each ticket has a unique serial number printed at the top, dates, order details, number of guests, order amount, table numbers etc. They are lightweight, small and can fit most aprons. They can be used on-demand and can help decrease errors in orders, while improving work efficiency.
  • High Quality: Sturdy, Not Drop Powder, It's Thick, You Can Write On The Back And Front Easily.Their whole page printing has clear handwriting and a reasonable layout. On the customer retention part of each guest check, "THANK YOU" on the back to make customers feel appreciated.
  • Contact Us: We're confident that the quality of the server note pads will go beyond your expectation. If you experience an issue, feel free to contact us, we'll appreciate it to learn from your experience, and we'll make it better

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.