About this question
I have a development web server for which the domain is not published or used (legitimately) by anyone other than me. However, I'm seeing hits in my access and error log for the following file from unknown IP addresses: I am using Composer and have the 'vendor' directory published in my main www directory. Will be moving this to an inaccessible directory right away. Is anyone aware of a vulnerability/exploit that bots may be trying to find by hitting this specific URL?