Hi,

Should we be adding 3 points for just this, or is there never a reason
users should be using /wp-admin in their URLs?

Oct 19 09:33:11.561 [1299] dbg: rules: ran uri rule __URI_WPADMIN
======> got hit: "/wp-admin/images/"

The rule description says possible phishing, but how would an end-user
be in a position to create a public link that involves their WP admin
directory in the first place?

Reply via email to