Site Information
WordPress Version: 6.0.12 ⚠️ VULNERABLE
Theme: customify (used by 6,572 domains)
Last Checked: 2026-07-20 21:35:29
HTTPS: ✅ Yes
Plugins (9)
| Plugin | Used By |
|---|---|
| addon-so-widgets-bundle | 1,143 |
| easy-twitter-feed-widget | 3,933 |
| elementor | 1,785,034 |
| siteorigin-panels | 57,547 |
| so-widgets-bundle | 29,065 |
| tk-google-fonts | 226 |
| ultimate-member | 28,393 |
| widgets-for-siteorigin | 1,845 |
| wp-video-lightbox | 10,304 |
Security Headers
D
Grade D
3 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.0.12) — CVE-2024-4439: Unauthenticated Stored XSS. Update to 6.5.2 or later immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.