07/22/2026
Your admin username is probably visible to the entire internet.
If you use WordPress, there's a default file that lists all your site users (including the admin) publicly. Attackers use this to find out who to target when trying to break into a site.
It's not a huge risk by itself — but combined with a weak password, it makes you an easy target.
The fix: delete a single file (/wp-json/wp/v2/users) or use a security plugin. Takes 5 minutes.
🔒 This is one of 20+ security checks we run in every Website Audit.