developer.wordpress.org - suspicious URL scan, 24 Aug 2026
MalwareAnalyzer by Cyble scanned developer.wordpress.org and returned a suspicious verdict (score 20), categorised as suspicious-infrastructure. The page resolved to 66.6.42.252 on TUMBLR, INC. in US. The domain was registered 8550 days ago through MarkMonitor Inc.. 34 domains and 2 IPs were contacted, over 23 HTTP requests. 95 malware samples communicate with this URL (Obfus). The request followed 2 redirects before landing. This is a point-in-time observation from 24 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 20) · Confidence 32%
- Scanned URL:
https://api.w.org/ - Domain: developer.wordpress.org · IP: 66.6.42.252 · AS2635 · US
- Server: nginx
- Page title: REST API Handbook | Developer.WordPress.org
- HTTP status: 200 · text/html; charset=UTF-8
- Registrar: MarkMonitor Inc. · domain age 8550 days · created 2003-03-28
- TLS issuer: C=US, O=Let's Encrypt, CN=YE1 · valid to Oct 23 19: · subject CN=wordpress.org
- HTTP requests captured: 23
- Scan tier: fast · observed 2026-08-24 11:27:43 UTC
Redirect chain
https://api.w.org/https://api.wordpress.org/https://developer.wordpress.org/rest-api/
Malware communicating with this URL (95)
These samples were observed contacting or being served from developer.wordpress.org. Each links to its full analysis.
- c853f21d0fce150b709fa8ab91d7558e63d1dc9ce6cba29e1873e7bf228e8630 - referenced ·
c853f21d0fce150b709fa8ab91d7558e· first seen 2026-08-24 - 7c269917565562c55760ad3db31b306ef0e63aa388eb45065bebd7d39e850067 - referenced ·
7c269917565562c55760ad3db31b306e· first seen 2026-08-24 - 59bffe58a04a809bfc936b50772d580e6cc99d881962193c3c44fd0df10d8d42 - referenced ·
59bffe58a04a809bfc936b50772d580e· first seen 2026-08-24 - 5ed3a88eb9552f71f053e6b014925b4651d45852c5835fb139e7848a8d509400 - referenced ·
5ed3a88eb9552f71f053e6b014925b46· first seen 2026-08-24 - 6a1d6815608114fe4d5ffe26ba8c9ad52a0489ea4283da39338f61822897de40 - referenced ·
6a1d6815608114fe4d5ffe26ba8c9ad5· first seen 2026-08-24 - 5ed54f45718e9763e5f3cb306647b1051837833c3db905b4d9e26d6308838499 - referenced ·
5ed54f45718e9763e5f3cb306647b105· first seen 2026-08-24 - b6e8beb17d43f3ed47433f1175961c4a77b30345145ba99001ab4c8abedb5ed3 - referenced ·
b6e8beb17d43f3ed47433f1175961c4a· first seen 2026-08-24 - Obfus - referenced ·
b6e9176cfcc00c45695d05f4e2fa22bc· first seen 2026-08-24 - 6ab308ac3b4b76697cf1b5d44a1e3eda9e23ee5dd44d7d7e069e9ba18d0c106b - referenced ·
6ab308ac3b4b76697cf1b5d44a1e3eda· first seen 2026-08-24 - b6e232457312de6171a0e002b5c937d2ff0fd9d44328e0694cd6000629262ff4 - referenced ·
b6e232457312de6171a0e002b5c937d2· first seen 2026-08-24 - 680ef9db42b81c3aad64ef789df7f0eecf6754df1bbb21bc0ec7652f06c21138 - referenced ·
680ef9db42b81c3aad64ef789df7f0ee· first seen 2026-08-23 - 913c7a8cdfd2fe432f92c39bc7b5f20b0c83185259d46a6493bb2dc595492d0e - referenced ·
913c7a8cdfd2fe432f92c39bc7b5f20b· first seen 2026-08-23 - ca9a457a10d9b9ae64bf80d9cec74f6cdfd94c5aeb541293b15a437cec245d8f - referenced ·
ca9a457a10d9b9ae64bf80d9cec74f6c· first seen 2026-08-23 - 5bcebd872926795f7903c550337ab862e9d3c6eb853752eeb27ae254682e9058 - referenced ·
5bcebd872926795f7903c550337ab862· first seen 2026-08-23 - bdf7e0de4851f166f4ffa4d5af1d5108794f41ec6acb2b754ecce7d869454b9a - referenced ·
bdf7e0de4851f166f4ffa4d5af1d5108· first seen 2026-08-23
Antivirus & YARA (1 of 48 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Categories
- suspicious-infrastructure
Why this verdict
- Algorithmically-generated (DGA-like) hostname
- Valid TLS, no impersonation or off-origin credential post
- A signature matched text in the page (DLV_HTML_Smuggling) — pages that discuss malware can match, so this alone is not a malicious verdict
- Cross-host redirect chain
Detected technologies
- Nginx
- WordPress
- Google Analytics
- jQuery
Contacted infrastructure
- 66.6.42.252 - AS2635 TUMBLR, INC. (United States)
- 66.6.42.251 - AS2635 TUMBLR, INC. (United States)
Observed indicators
- developer.wordpress.org
- www.googletagmanager.com
- i0.wp.com
- c0.wp.com
- fonts.googleapis.com
- fonts.gstatic.com
- s.w.org
- wordpress.org
- learn.wordpress.org
- openverse.org
- wordpress.tv
- make.wordpress.org
- events.wordpress.org
- jobs.wordpress.net
- mercantile.wordpress.org
- en.wikipedia.org
- codex.wordpress.org
- github.com
- wordpressfoundation.org
- wordpress.com
Other scans of developer.wordpress.org (2)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - suspicious
- 16 Aug 2026 - unknown ·
https://wordpress.org/
Questions about developer.wordpress.org
- Is developer.wordpress.org safe?
- No. MalwareAnalyzer scanned developer.wordpress.org on 24 Aug 2026 and returned a suspicious verdict with a score of 20 out of 100, categorised as suspicious-infrastructure. Treat it as hostile until it is re-checked.
- What malware is associated with developer.wordpress.org?
- 95 analysed samples communicate with this URL, including Obfus.
- How was developer.wordpress.org checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of developer.wordpress.org
Scanned on MalwareAnalyzer by Cyble · Open interactive scan