DokuWiki at 3,980 Matches: A File-Based Wiki and the Backup It Leaves Behind
Wikis are the class of application that accumulates the most value per byte. Setup instructions, runbooks, credentials rotation procedures and architectural decisions end up in one, and the effort of collecting them means the content is rarely deleted. A product measurement of a widely used file-based wiki is therefore a measurement of a particular concentration of institutional knowledge.
The measurement
A ZoomEye query run on 2026-10-02, app="DokuWiki", in the all-types scope, returned 3,980 matches.
Search link: https://www.zoomeye.ai/searchResult?q=YXBwPSJEb2t1V2lraSI%3D
Why the storage model decides the exposure question
DokuWiki stores pages as files rather than in a database. That choice has two consequences for anyone assessing an exposed instance.
The first is that the content is addressable as files. A wiki page is a file with a predictable name under a data directory, so any path that reads or lists files from that directory has a direct route to page content, and page versions are kept alongside the current revision as individual files.
The second is that a file-based application is often deployed in ways a database-backed one is not. It has no separate service to install, so it appears on shared hosting, inside home lab machines, and on a general-purpose web server alongside unrelated sites. Those environments frequently have a single access control decision, which is whether the site is reachable.
That second consequence is the one that shows up in measurements. The application is easy to deploy, so it is deployed in contexts where a separate administrator reviews the web server rather than the wiki, and access control sits at the outer layer if it exists at all.
What the count does not establish
3,980 is a fingerprint count. It does not measure whether the instances are readable without authentication, and DokuWiki supports access control lists that can be configured at a fine grain, including per namespace.
It also does not measure whether the content is current. A wiki that has been superseded and never removed looks the same from outside as an active one, which is exactly the situation where old credentials and old network diagrams remain reachable.
What a reader can check
Three checks are worth the effort, and all three are configuration reviews rather than scans.
Whether the instance is readable without logging in. Where it is, decide whether the content is intended to be public, because the default posture of a wiki is usually private and the change was often accidental.
Whether editing is possible for accounts that should only read. A wiki that has been shared with a wider audience over time frequently accumulates write permissions that were granted for a specific task.
Whether the history is retained. Old revisions frequently contain material that was later removed from the current page, including the reason it was removed.
The wider point
Counts in the low thousands are unremarkable as a population size and useful as a reminder. Every self-hosted documentation platform is a deliberate accumulation of the things an organisation knows, and the measurement is simply a way to check whether any of that accumulation is reachable from outside the network it describes.
References
- [1] ZoomEye search,
app="DokuWiki", executed 2026-10-02 UTC, exact total 3,980. https://www.zoomeye.ai/searchResult?q=YXBwPSJEb2t1V2lraSI%3D - [2] DokuWiki project home page. https://www.dokuwiki.org/
Top comments (0)