# Hacked new wordpress sites, because LE is created

**URL:** <https://community.letsencrypt.org/t/hacked-new-wordpress-sites-because-le-is-created/175284>\
**Category:** Help\
**Created:** [April 6, 2022, 8:09am UTC](https://community.letsencrypt.org/t/hacked-new-wordpress-sites-because-le-is-created/175284 "2022-04-06T08:09:53Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [April 6, 2022, 8:19am UTC](https://community.letsencrypt.org/t/hacked-new-wordpress-sites-because-le-is-created/175284/2 "2022-04-06T08:19:19Z")

</div>

> [@raj](#):
>
> I think that it is because crt.sh is scanned

More likely they are directly polling the CT log servers, as the delay to detect new domains is much shorter. But yes, what you describe has been happening for a few years now. I see requests to paths like `/.git/index` within seconds of issuing new certificates!

---

_[View the full topic](https://community.letsencrypt.org/t/hacked-new-wordpress-sites-because-le-is-created/175284)._
