Leaks
Leaked-Credential Login Attempts
An attacker working through a list of leaked passwords against your login page is the quietest phase of an attack: until one works, it leaves no trace. Specula shows the count of those attempts, day by day.
No extra scanning
The data is read from Cloudflare's own check; Specula sends your site no additional requests for it.
A real signal
Measured: one zone saw 64 attempts against /wp-login.php in a single hour, ten of them with a leaked password. Another day the same zone saw 223 leaked-password attempts.
Days in your own timezone
The series is grouped by the customer's timezone. Grouping by UTC day would file attempts made after midnight under the previous day.
Busiest day: 223 attempts
Its limits
This feature works only on domains connected through Cloudflare.
Cloudflare only looks for leaked passwords in login formats it recognises (WordPress, OWA, Joomla, Drupal, Magento, Ghost, Plone and a generic form); “none seen” does not mean no attempts were made.
Other features
Run this check on your own domain.
Add a domain and Specula finishes the first scan within minutes. No credit card needed.