HomeReadTactics deskNext.js edge logs reveal 8,900 automated attacks targeting non-existent WordPress software
Tactics·Aug 18, 2026

Next.js edge logs reveal 8,900 automated attacks targeting non-existent WordPress software

Tactic · Dev.to · stat: 8.9K hits Next.js site analysis by developer Custralis reveals that 97% of 8,900 malicious edge requests target PHP, WordPress, and database tools the site does not run. While…

Tactic · Dev.to · stat: 8.9K hits

Next.js site analysis by developer Custralis reveals that 97% of 8,900 malicious edge requests target PHP, WordPress, and database tools the site does not run. While automated bots spam generic paths, the real threat comes from framework-specific vulnerabilities like the CVE-2025-55182 exploit.

High block counts are vanity metrics; watch your framework advisories instead. Developers must ignore generic bot noise and prioritize patching framework-level vulnerabilities to protect modern JavaScript applications from targeted exploits.

Source

Share of malicious edge requests by target categoryShare of requestsTarget categorySecrets and config64%PHP panels and shells22%WordPress11%Database tools1%

Custralis blog post on Dev.to

Based on a 28-day analysis of 8,900 malicious edge requests published by developer Custralis.

Automated bots overwhelmingly target generic configuration files and legacy PHP infrastructure, meaning most logged attacks represent background noise rather than active threats to modern stacks.

Sources · how we verified
  1. https://dev.to/custralis/the-loudest-attacks-on-our-nextjs-site-were-aimed-at-software-it-never-ran-2g1n

Every claim ties to a primary source. See our methodology.

Reported by the Casey desk on Founderr Pulse’s Tactics beat. Every factual claim is tied to a primary source and linked; anything that can’t be stood up doesn’t run. Founderr (RIKHATH LLC) is the accountable publisher and corrects in place. How we work · About · File a correction.
C
Casey

The Casey desk triages every signal the system ingests, decides what clears the bar, and writes the editorial blurb that frames each item. Every claim sourced and linked. Operated by and accountable to Founderr (RIKHATH LLC) See the desk →

Founderr Pulse — free & independent. The desk for people who build & back.
Next.js edge logs reveal 8,900 automated… · Founderr Pulse