Are These Tor Requests to My Static Website Just Bots?

0
4
Asked By MellowPine42 On

I'm new to web development and recently deployed my first small static site using HTML, CSS, and JavaScript. I'm learning about observability and noticed 12 requests from what appeared to be a Tor exit node over about five minutes. The requests had relatively high latency and mostly targeted "/", "/favicon", or a single PNG/JPG file—the image happened to be the favicon itself. None of the other JPG files that normally load after scrolling were requested. Could this have been a real person, or is it more likely to be a crawler, scanner, or other automated script? There is no backend or sensitive functionality, so I'm mainly trying to understand what this traffic pattern means.

3 Answers

Answered By QuietMaple3 On

Bots, search crawlers, and basic scanners routinely hit public websites, including brand-new ones. Twelve requests over five minutes is not unusual, and one burst doesn’t necessarily indicate a targeted attack. Keep an eye on broader patterns over days or weeks, and check that unexpected paths or query strings are handled without exposing errors or internal details.

Answered By PixelHarbor88 On

If the traffic becomes annoying, you can put the site behind a service such as Cloudflare and enable its basic bot protection. A robots.txt file may help with well-behaved crawlers, but it won’t stop scanners that ignore those rules. For a simple static site, sensible deployment settings and keeping secrets out of the frontend are usually more important than trying to block every unusual request.

Answered By CobaltWren7 On

This is very likely automated traffic rather than someone browsing normally. A real browser would usually request the lazy-loaded images after scrolling, while a simple crawler or script may only fetch the homepage and favicon. Tor exit nodes are shared by many users and scripts, so you can’t identify who was behind the request from that alone. On a static site there usually isn’t much to attack, but make sure you never put API keys, tokens, or other secrets in client-side JavaScript—anything shipped to the browser should be treated as public.

MellowPine42 -

That makes sense. I’m not especially worried about this site, but I wanted to understand why the pattern looked different from a normal visit. I’ll keep checking that the frontend doesn’t contain anything sensitive.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.