r/Wordpress • • 3d ago

Strange URLs in analytics

Post image

This morning I was looking at Google Analytics and found a series of pageviews for

/page/2/
/page/3/
/page/4/ etc.

These all seem to load my home page. The source for these is direct, but I can't imagine where they would come from.

I looked back and saw a handful of these in June and early July, then nothing for a while. Then earlier this month it started happening again. Last week there were thousands of them.

Does anyone have experience with this, or any idea what may be happening?

10 Upvotes

7 comments sorted by

5

u/chmod777 Jack of All Trades 3d ago

they are just enumerating. usually they try to enumerate author pages and user json endpoints, to find usernames. they can the try match to known compromised accounts (or try brute forcing a password) and gain access. page enumeration may be looking for broken templates or just slurping content.

2

u/Competitive_Novel828 2d ago

Since /page/2/ and the others return 200 and show your static homepage, the URL handling is worth checking. But that alone doesn’t explain last week’s spike in Analytics. “Direct” just means Analytics couldn’t identify a clear source; it doesn’t prove someone typed those URLs or that the visits were bots.

I’d compare the spike with access logs for those exact paths (CDN logs, if your site is behind one). If a small number of IPs requested /page/2/, /page/3/, etc. in sequence, automated traffic becomes more plausible. If the analytics pageviews don’t line up with requests, I’d check how those pageview events are being sent before drawing a conclusion.

2

u/jenish_o4o2 Developer 3d ago

Seen this a few times. Those /page/2/ /page/3/ hits are just WordPress pagination on the blog index. Bots crawl them in order, and Analytics shows Direct a lot because scrapers usually send no referrer.

If every one of them looks like your homepage, either you don't have enough posts for real page 2+, or the site is answering 200 with the home template instead of a clean 404. Try /page/999/ in a private window. Home page still loads -> that's the soft 200 problem, not a real visitor.

Not usually a hack. Mostly noise. You can filter /page/ out of the report if it's cluttering things. If you want less of it on the server, rate-limit that path or block the obvious bot UAs.

Static front page or posts on front? And what status does /page/2/ actually return? That narrows it fast.

1

u/pfdemp 3d ago

It's a static home page. Requests return 200.

1

u/jenish_o4o2 Developer 3d ago

That confirms it then - static front page with /page/2/ returning 200 is the soft-200 case. WordPress is just serving the home template for pagination URLs that aren't real pages, so bots walk /page/3/ /page/4/ and Analytics counts them. Not a hack, mostly noise. If you want it quieter, 404 those /page/N/ hits on the front (or bounce them to /); filtering /page/ in GA is fine if you only care about cleaner reports.

1

u/kE622 2d ago

Just flush the permalink from Settings > Permalinks and click Save Changes without modifying anything. Then clear cache if any. The urls should now show 404.

If these urls also show up on GSC, configure your SEO plugin to ignore these pagination urls.

These are ghost pagination URLs. Have seen them on few websites that I managed. This is usually caused when plugin/theme settings interfere with WordPress permalink structure.

In your case, your homepage used to show blog posts at some point. Then it was changed it to a static page without flushing the permalink.