Audiobookshelf: no app fingerprint and 13,963 title matches
A self-hosted media server usually sits on a home network, which is exactly what makes its internet-reachable instances interesting. Audiobookshelf serves audiobooks and podcasts, and the index identifies it by page title while finding nothing by application signature.
What the queries measured
Two queries were run against the ZoomEye index on 5 October 2026, scoped to all asset types.
Search query: app="Audiobookshelf". Result: 0 matching assets.
Comparison query: title="Audiobookshelf". Result: 13,963 matching assets.
Reading a one-sided result
A single figure with no fingerprint counterpart is a weaker measurement than a pair, and the weakness should be stated rather than smoothed over. The title count covers assets whose page carries the product name. It includes running instances, and it includes pages that reference the product.
The population is large enough to suggest that a meaningful share of these assets are real deployments. A media server that is reachable from the internet is usually one that was set up for personal use and published so it can be reached from outside the home.
What an instance holds
Audiobookshelf stores a library, user accounts and, in a typical configuration, the details needed to reach the storage behind it. The interface is the control surface. Authentication is the only layer between a public address and both the library and the accounts.
Two configuration patterns produce most of the exposure. A container with a published port on a host with a public address, and a reverse proxy that was added to make remote access work and was never scoped to the accounts that should have it.
What an operator can do next
Compare the count against the hosts the organisation manages. A media server is rarely in a corporate asset inventory, which is the reason to check for one rather than assume it is absent.
Where remote access is a requirement, the useful check is which accounts exist and whether any of them were created for a purpose that no longer applies. A server with one live account and five forgotten ones has five ways in.
Limitations
The figure describes indexed assets on one day and cannot separate a running server from a page that mentions one. It does not identify versions, authentication methods or owner intent. A count this size is an inventory prompt, not a finding.
References
[1] Audiobookshelf. https://www.audiobookshelf.org/
[2] Audiobookshelf source repository. https://github.com/advplyr/audiobookshelf
[3] ZoomEye. https://www.zoomeye.ai/
Top comments (0)