The System Reserved keywords

The system-reserved keywords are words that cannot be used in any page URLs. They cannot be redirected to any other page however any page can be redirected to them (pages with system-reserved keywords in their URL).

These keywords do not work in combinations where you separate the keyword using a hyphen like:

  1. – keyword
  2. my-keyword
  3. keyword-my or any such combination.

However, you can add letters to the keywords without any special characters. Combinations that work are:

  1. mykeyword
  2. keywords or any such combination.

Here, the keyword can be any system-reserved keyword.


Here’s the list of system-reserved keywords:

    1. account
    2. action
    3. actuator
    4. admin
    5. administrator
    6. alfacgiapi
    7. api
    8. app
    9. apps
    10. assets
    11. attachment
    12. auth
    13. authentication
    14. author
    15. authorize
    16. autosave
    17. backdoor
    18. backend
    19. backup
    20. blackhat
    21. bot
    22. botnet
    23. brute-force
    24. bruteforce
    25. cache
    26. card-checker
    27. cart
    28. cc-checker
    29. cgi-bin
    30. checkout
    31. ckeditor
    32. clipboard
    33. comment
    34. comments
    35. config
    36. config-shell
    37. core
    38. cpanel
    39. csrf
    40. css
    41. darkweb
    42. dashboard
    43. database
    44. db
    45. dbadmin
    46. debug
    47. debugger
    48. dev
    49. download
    50. drupal7
    51. drupal8
    52. drupal
    53. edit
    54. editor
    55. embed
    56. env
    57. error
    58. errors
    59. exploit
    60. favorite
    61. favorites
    62. fckeditor
    63. feed
    64. file
    65. files
    66. folder
    67. forms
    68. getjsassets
    69. graphql
    70. hack
    71. hacktools
    72. handle
    73. html
    74. images
    75. info-page
    76. inject
    77. install
    78. install-old
    79. item
    80. jcrop
    81. joomla
    82. jquery
    83. js
    84. json
    85. lfi
    86. link
    87. log
    88. login
    89. logs
    90. malware
    91. manager
    92. mysql
    93. mysql-admin
    94. mysqladmin
    95. order
    96. orderby
    97. page
    98. passwd
    99. password-dump
    100. payload
    101. payment
    102. php
    103. phpinfo
    104. phpmyadmin
    105. phpunit
    106. pki-validation
    107. post
    108. posts
    109. preview
    110. private
    111. product
    112. products
    113. remote-shell
    114. result
    115. results
    116. rfi
    117. robots
    118. root
    119. script
    120. scripts
    121. search
    122. server
    123. server-info
    124. server-status
    125. setup
    126. share
    127. shell
    128. shortcode
    129. site
    130. site-backup
    131. siteadmin
    132. sites
    133. spam
    134. spammer
    135. sql
    136. sql-injection
    137. sqlmap
    138. static
    139. storage
    140. tag
    141. tags
    142. temp
    143. test-shell
    144. tmp
    145. trojan
    146. update-old
    147. updater
    148. upload
    149. user
    150. user-profile
    151. vulnerabilities
    152. web-shell
    153. webadmin
    154. webdav
    155. webdav-test
    156. widget
    157. widgets
    158. xml
    159. xmlrpc
    160. xss

Can't find what you're looking for?

Get in touch with a Pixpa Expert.