Analyzing 113k Requests Across 9 WordPress Sites: 1 in 8 Are Active Attacks
Check your site's traffic logs; 1 in 8 requests are attacks, with 7 IPs hitting multiple sites—use shared blocklists to protect all sites.
Implement shared blocklists across sites to block coordinated attackers.
Summary
An analysis of 113,000 requests over 24 hours on nine WordPress sites revealed a striking traffic composition. 66 % of the traffic came from real humans, 14 % from generic bots, 5.9 % from legitimate crawlers such as Googlebot, and 4.4 % from AI bots like GPTBot and ClaudeBot. The remaining 8.7 % were active attacks, meaning one in eight requests was malicious. Notably, seven of the attacking IPs were observed hitting multiple unrelated sites simultaneously, indicating coordinated scanning.
Wordfence and most security plugins treat each WordPress install as an isolated island, so an attacker who is blocked on site A can still start fresh on site B. This lack of cross‑site visibility allows coordinated attacks to continue unchecked. The data underscores the value of shared blocklists and centralized monitoring for WordPress operators. Understanding these traffic patterns can help site owners prioritize security hardening and traffic filtering.
Key changes
- 113,000 requests over 24 hours across nine WordPress sites
- 66 % of traffic from real humans
- 14 % from generic bots
- 5.9 % from legitimate crawlers (Googlebot, etc.)
- 4.4 % from AI bots (GPTBot, ClaudeBot, Bytespider)
- 8.7 % active attacks (one in eight requests)
- Seven attacking IPs hit multiple unrelated sites simultaneously