I bought an expired domain which had a few links, but am a a bit surprised at the level of traffic to pages that don't exist. I checked the domain beforehand but many of these pages did not show up as links.

I also have an amazing amount of traffic to wp-login.php, xmlrpc.php and wp-admin/admin-ajax.php.

This does not sound good, but I run an anti-hacker app that comes up with nothing significant.

Are these the remains of a hack on the previous website, perhaps? Is there anything more I can do to protext the site (self-hosted Wordpress).

Do the pages getting traffic appear to be genuine?
Or is it all trackback spam?
The traffic to wp-admin and the XML RPC stuff isn't that surprising - there's a bunch of attacks on those


Sounds like it is probably bot traffic. They likely aren't real visitors and probably scraped the domain before you owned it.
