Some websites should be hidden
There are good reasons why some websites just shouldn’t be accessble to everyone.
Usually, it’s for privacy and security:
The “old” version of your main website, before it got that gorgeous new visual update.
The “new but not yet ready” version of your main website, while you’re still working on that gorgeous new visual update.
A special-purpose site that’s really only needed by a few staff members.
Temporary versions of a site during a migration.
In those situations, you or some of your staff need to access the site, so you can’t just take it offline.
But there are plenty of people who really shouldn’t be able to see anything about the site. For example:
Search engines: You really don’t need “old.mysite.org” showing up in search results on Google and elsehwere.
AI tools: You don’t want these sites influencing what ChatGPT and other AI tools are saying about you.
Criminal hackers: You definitely don’t want spam bots, data thieves, and security hackers hammering away at these sites.
And since the general public doesn’t need access, it makes sense to keep them completely hidden.
That’s why we’ll often put an extra layer of security in front of such sites.
as a way to keep most folks (anyone who doesn’t really need to be there) from learning anything about the site at all.
Here’s an example:
Take a look at https://basicauth.joineryhq.com/ . Can you tell if it’s running an outdated version of WordPress, or if it contains lots of valuable private data?
Nope, you can’t.
And for the kind of “not meant for everyone” sites we’re talking about, that’s exactly what we want.
All the best,
A.
P.S. If you’re curious what’s hiding at https://basicauth.joineryhq.com/ , try username “example” and password “pass”. (No security vulnerabilities or juicy data, though. Sorry to disappoint.)

