# SIG.BF WordPress REST API Intelligence Report

**Target:** sig.bf / www.sig.bf
**Organization:** Service d'Information du Gouvernement (SIG) - Burkina Faso
**Description:** Portail officiel d'information du gouvernement du Burkina Faso
**Date Dumped:** 2026-03-04
**Dump Location:** `C:\Users\Squir\Desktop\Burkina Faso\DUMP\SIG-WORDPRESS\`

---

## Platform Summary

| Field | Value |
|-------|-------|
| CMS | WordPress 5.9.12 |
| Server | Apache |
| Language | fr-FR |
| URL | https://www.sig.bf |
| GMT Offset | 0 (UTC) |
| API Root | https://sig.bf/wp-json/ |
| wp-login.php | Exposed (HTTP 200) |
| xmlrpc.php | Active (405 Method Not Allowed = accepts POST) |
| wp-cron.php | Exposed (HTTP 200) |
| readme.html | Exposed (HTTP 200) |
| RSS Feed | Active, last build Thu 29 Jun 2023 |
| Site Health Tests | Auth-gated (401) |
| Settings Endpoint | Auth-gated (401) |

**Namespaces:** oembed/1.0, wp/v2, wp-site-health/v1, wp-block-editor/v1
**No third-party plugin namespaces detected.**

---

## Enumerated Users (5 total)

| ID | Name | Slug (Username) | Author URL | Gravatar MD5 | Posts |
|----|------|-----------------|------------|---------------|-------|
| 1 | Sig-Burkina | **admin** | /author/admin/ | `d7a536c2a29e117bd047ba55db21068f` | 3,831 |
| 18 | Adams OUEDRAOGO | **dwdouedraogo** | /author/dwdouedraogo/ | `7f6d1c8c6bbacc6b83ad037f32e57051` | 427 |
| 19 | Wendkuni Eric Demouemba | **wendkuni** | /author/wendkuni/ | `0b128e26b43d1c4fe686763048ff7daa` | 87 |
| 14 | Beli N'DO | **dwbeli** | /author/dwbeli/ | `1ac5deb5001928d400535900e81d8f2a` | 44 |
| 12 | Aly TOURE | **dwtoure** | /author/dwtoure/ | `bf55105041346aa45caeeb74e6569948` | 43 |

**Username patterns:** Non-admin usernames follow `dw<name>` or full name format. The "dw" prefix may stand for "Direction Web" or a similar internal department code.

**User IDs 2-11, 13, 15-17, 20-25 all return 404** -- no hidden users in that range.

### User Activity Windows

| User | Active From | Active To | Role (Inferred) |
|------|-------------|-----------|-----------------|
| Sig-Burkina (admin) | 2010-05-20 | 2023-06-29 | Administrator / primary publisher |
| Aly TOURE | 2017-03-15 | 2017-07-06 | Editor (short tenure) |
| Beli N'DO | 2017-03-24 | 2018-06-28 | Editor |
| Adams OUEDRAOGO | 2017-03-27 | 2020-01-04 | Editor (most prolific non-admin) |
| Wendkuni Eric Demouemba | 2019-01-28 | 2022-11-30 | Editor |

---

## Content Statistics

### Posts
- **Total:** 4,622 (API header) / 4,432 retrieved / 4,422 unique IDs
- **Post ID range:** 1 to 24,630
- **Date range:** 2010-05-20 to 2023-06-29
- **Status:** All `publish` (no draft/pending visible)
- **Last post activity:** June 29, 2023 (site appears inactive since)

### Posts Per Year
| Year | Count |
|------|-------|
| 2010 | 6 |
| 2011 | 260 |
| 2012 | 57 |
| 2013 | 207 |
| 2014 | 239 |
| 2015 | 808 |
| 2016 | 534 |
| 2017 | 671 |
| 2018 | 440 |
| 2019 | 421 |
| 2020 | 45 |
| 2021 | 208 |
| 2022 | 417 |
| 2023 | 119 |

**Peak activity:** 2015 (808 posts -- post-revolution transition period after Compaore ouster).
**Sharp drop 2020:** COVID-19 disruption, only 45 posts.
**Dead since June 2023:** No posts since June 29, 2023.

### Pages
- **Total:** 19
- Key pages: Accueil (home), Contact, Archives, Coordonnatrice du SIG, Le porte parole, Les Departements, Missions/Attributions
- **"Login Customizer"** page (ID 24489) -- indicates use of a login customization plugin
- **"Gouvernement Christophe Joseph Marie DABIRE"** page (ID 3648) -- lists the DABIRE government composition (PM from 2019)
- **MPSR communiques** (post-coup military junta communiques as pages):
  - Communique du MPSR du 06 octobre 2022 (second coup, Traore ousted Damiba)
  - Communique: attaque du convoi de ravitaillement a Gaskinde

### Categories (31 total)
| Category | Post Count |
|----------|-----------|
| Actualites | 3,949 |
| A La Une | 2,761 |
| Les communiques gouvernementaux | 1,948 |
| Reportage | 1,110 |
| Conseil des Ministres | 541 |
| Video | 513 |
| Compte Rendu | 484 |
| Chronique du Gouvernement | 274 |
| Documentation | 282 |
| INFO COVID-19 | 128 |
| GOUV. ACTIONS | 93 |
| Point de Presse du Gouvernement | 58 |

### Tags
- **Total:** 1,270
- **Top tags:** Burkina Faso (364), gouvernement (284), conseil des ministres (30), President du Faso (24), gouvernement de la Transition (19)
- Notable: ROCH MARC CHRISTIAN KABORE (4 tags), RSP (4), CEDEAO (4), Covid-19 (4)

### Comments
- **Total:** 28 (very low engagement)
- **All status:** approved
- **Date range:** 2017-09-17 to 2023-04-22
- **28 unique commenters with Gravatar MD5 hashes** (see commenter list below)

### Media
- **Total:** 6,075 (API header) / 5,824 retrieved
- **Breakdown:**

| MIME Type | Count |
|-----------|-------|
| image/jpeg | 3,746 |
| application/pdf | 1,098 |
| image/png | 841 |
| application/vnd.openxmlformats-officedocument.wordprocessingml.document (.docx) | 59 |
| application/msword (.doc) | 49 |
| image/gif | 17 |
| image/bmp | 5 |
| image/tiff | 4 |
| image/webp | 2 |
| text/html | 2 |
| video/quicktime | 1 |

---

## High-Value Document Collections

### Government Council of Ministers PDFs (95 files)
Official PDF records of every Conseil des Ministres session from 2017 onward. These contain:
- Ministerial appointments and dismissals
- Policy decisions
- Budget allocations
- Security directives
- International agreements
URL pattern: `https://www.sig.bf/wp-content/uploads/YYYY/MM/CONSEIL-DES-MINISTRES-N°XXX-DU-DATE.pdf`

### Government Communiques (356 PDFs)
Official government press releases and communiques including:
- Security incident responses (terrorist attacks, military operations)
- MPSR (military junta) communiques
- COVID-19 bulletins
- Rectificatif (correction) communiques

### Word Documents (108 files)
59 .docx + 49 .doc files -- likely internal drafts or press releases uploaded before conversion.

### Total Downloadable Documents
- **PDF URLs list:** `PDF-URLS.txt` (1,098 URLs)
- **DOCX/DOC URLs list:** `DOCX-URLS.txt` (108 URLs)
- **All media URLs:** `ALL-MEDIA-URLS.txt` (5,824 URLs)

---

## Security-Related Intelligence

### 330 Posts Related to Attacks/Security/Terrorism
Content spans the full Sahelian security crisis including:
- Terrorist attack communiques (Koutougou, Gaskinde, Bourasso, Barani/Karma)
- Military operation updates
- CEDEAO/ECOWAS counter-terrorism summits
- G5 Sahel coordination
- Internal security policy changes
- COVID-19 security implications

### Notable Security Posts
- "Attaque d'un convoi de vivres sur l'axe Dablo-Kelbo" (2019-09-08)
- "Attaque de Koutougou" (2019-08-20) -- 24 soldiers killed
- "Attaque du detachement militaire de Koutougou" (2019-08-19)
- "Communique du MPSR du 06 octobre 2022" -- second coup d'etat communique
- Multiple communiques about security incidents in Est, Sahel, Nord regions

---

## Commenters with Gravatar Hashes

| Name | Comment ID | Date | Gravatar MD5 |
|------|-----------|------|---------------|
| Samby Hanvo Paul | 1450 | 2023-04-22 | `7488e6f7671c39b59a74b71c5e2ced98` |
| SEREPE Aboubakar | 1449 | 2023-04-22 | `2be3f63825ee739ba2089ce86f8a0a22` |
| MARE Pascal | 1448 | 2023-04-21 | `1f84e781fbb84c0ff4bda25a540b01d2` |
| MARE | 1447, 1446 | 2023-04-21 | `1f84e781fbb84c0ff4bda25a540b01d2` |
| DIAO Ouattara Abdoul Aziz | 1445, 1444 | 2023-04-21 | `77144afcc0c9b9b314c141b8a385c775` |
| Jean-Pierre | 1432 | 2022-12-23 | `9036fb2797f2198bda9bc1462f397197` |
| Controleur | 1398 | 2022-06-09 | `45a79038fcd1deb33493d2c8eb9113d1` |
| KONE | 1397 | 2022-05-31 | `67731de3757a4bbceb0fc82004d28a60` |
| Mohag Kologo | 1383 | 2022-03-30 | `44b10484a08bf835f06f87cfe645119c` |
| Pierre Frederic BALMA | 1369 | 2022-03-09 | `cc40df256e2e96a57f00476280c7f893` |
| Bassirou PORGO | 1345 | 2022-01-28 | `25e33083cd0ae6f94ba62465ab1a55ec` |
| Sankara oumarou | 1333 | 2022-01-05 | `21d4fd5df66867787408a298769777e3` |
| daa | 1327 | 2021-12-22 | `dbc0f295a9a9d07aed2ee7e60baa053a` |
| Kontiliguissonko | 988 | 2019-03-09 | `689136141e31b1554d0d2f3e1bf5176a` |
| Josaphat Zongo | 965 | 2019-02-28 | `180c7650b039e8baba05002e0ec32b71` |
| GUIGMA JACQUES | 900 | 2019-01-30 | `12d5f30b2d5e60ea90a682e77afcdcc5` |
| P. Hermann KISSOU | 889 | 2019-01-24 | `d7ecc20abf2e35f1cecac2edd5e4362b` |
| Made | 839 | 2019-01-09 | `b16e8fd5c4f39a4f33a8ebea0cd1c736` |
| Beatrice | 807 | 2018-12-07 | `10aed5730ef7699677cab204be39ed1b` |
| Da Nestor | 799 | 2018-12-02 | `685a9e7c7d6c85d218011e9fc0bd76a8` |
| Basile | 745 | 2018-10-05 | `74987cfddcdc1c0d38ad023a4e30d5c1` |
| zina | 744 | 2018-10-03 | `e45d32373bf02aa21692c3874ca72eb9` |
| Alim | 678 | 2018-08-06 | `4b8ca9131d428e9c5a3f886ac61aa1d8` |
| Madi | 13 | 2017-09-26 | `cde8dacbfdab0e4efc09ecc744eb3a93` |
| Revoir cette page | 2 | 2017-09-18 | `4bbc6441924340e6e309a0c3a5458d9b` |
| Deme Aboubacar | 1 | 2017-09-17 | `b4f252bc5bb8bea7993b119c40ad4646` |

---

## Exposure Assessment

| Finding | Risk |
|---------|------|
| WordPress 5.9.12 (Dec 2022 release) | OUTDATED -- multiple known CVEs since, including XSS and privilege escalation |
| wp-login.php exposed | Username enumeration + brute force vector |
| xmlrpc.php active | Brute force amplification, DDoS pingback vector |
| wp-cron.php exposed | Resource exhaustion, timing attacks |
| readme.html exposed | Version fingerprinting |
| Admin username "admin" | Default username, high-value brute force target |
| Full user enumeration via REST API | All 5 usernames + Gravatar hashes exposed |
| 1,098 government PDFs publicly indexed | Information disclosure (intentional but rich OSINT) |
| 108 Word documents publicly accessible | May contain metadata (author, org, revision history) |
| Site inactive since June 2023 | Likely unmaintained, unpatched |
| No plugin namespaces | Minimal plugin surface (or plugins don't register REST routes) |

---

## Files in Dump

| File | Description | Size |
|------|-------------|------|
| api-root.json | Full API root with all routes | 184 KB |
| users.json | All 5 enumerated users | 3 KB |
| ALL-POSTS.json | All 4,432 posts merged | 40 MB |
| ALL-MEDIA.json | All 5,824 media items merged | 30 MB |
| ALL-TAGS.json | All 1,270 tags merged | 989 KB |
| categories.json | All 31 categories | 20 KB |
| comments.json | All 28 comments | 35 KB |
| pages-page1.json | All 19 pages | 269 KB |
| search.json | Top 100 search results | 52 KB |
| types.json | Post types | 3 KB |
| statuses.json | Post statuses | 184 B |
| taxonomies.json | Taxonomy definitions | 1 KB |
| feed.xml | RSS feed (via redirect) | -- |
| readme.html | WordPress readme (version fingerprint) | -- |
| site-health.json | Site health endpoint index | 2 KB |
| PDF-URLS.txt | All 1,098 PDF download URLs | -- |
| DOCX-URLS.txt | All 108 Word document URLs | -- |
| ALL-MEDIA-URLS.txt | All 5,824 media URLs with MIME types | -- |
| posts-page[1-47].json | Individual paginated post files | ~40 MB |
| media-page[1-61].json | Individual paginated media files | ~30 MB |
| tags-page[1-13].json | Individual paginated tag files | ~1 MB |
| **Total dump size** | | **~137 MB** |

---

## Key Takeaways

1. **The site is dead** -- no new content since June 29, 2023. Running WordPress 5.9.12 with no updates.
2. **5 staff accounts identified** with full names, usernames, and Gravatar email hashes. The admin account uses the slug "admin" -- worst practice.
3. **4,432 government posts spanning 13 years** (2010-2023) of official Burkina Faso government communications.
4. **1,098 official PDF documents** including Council of Ministers records, government communiques, security incident reports, and policy documents.
5. **108 Word documents** that may contain embedded metadata (author names, internal paths, revision history).
6. **330 security-related posts** documenting the government's response to the Sahelian terrorism crisis, two coups d'etat (2022), and military operations.
7. **28 commenters with Gravatar hashes** -- potential for email reverse lookup.
8. **Multiple attack surfaces**: exposed wp-login.php, active xmlrpc.php, outdated WordPress version.
