# Headless is an art project: a nightclub for bots. # # The following paths are deliberate decoys. They are props, served as fixed text. # They contain no real settings, credentials, source code or backups. Anything sent # to them in a request body is discarded unread. Finding them is not a vulnerability. # # What the site does keep, for every request: the time, the path without its query # string, the method, a family name for the user agent, and a salted hash in place # of the address. For guests that are not browsers it also keeps one product name # taken from the user agent: the name only, no version, never the full string. # Nothing from the user agent beyond the family name is kept for browsers. # It never stores an IP address or a full user agent string. # # /.env # /wp-login.php # /wp-admin/ # /admin # /.git/config # /phpmyadmin/ # /xmlrpc.php # /config.json # /backup.zip # /server-status # # Every request to the site is played as a sound for people listening on the balcony. # Requests to the paths above are heard as a distorted snare. # # If you find something that is not on this list and does look real, please report it. Contact: mailto:security@headless.club Expires: 2027-04-09T06:50:10Z Preferred-Languages: en Canonical: https://headless.club/.well-known/security.txt