Site Information
WordPress Version: 5.7.15 ⚠️ VULNERABLE
Theme: buddyboss-theme (used by 2,875 domains)
Last Checked: 2026-07-24 15:18:38
HTTPS: ✅ Yes
Plugins (22)
| Plugin | Used By |
|---|---|
| 3d-flipbook-dflip-lite | 44,260 |
| bridge-for-woocommerce | 769 |
| captcha-code-authentication | 7 |
| creame-whatsapp-me | 70,944 |
| digits | 4,411 |
| elementor | 1,785,835 |
| elementor-pro | 1,058,196 |
| embedpress | 19,169 |
| essential-addons-for-elementor-lite | 267,975 |
| jannah-extensions | 106 |
| lifterlmsfa | 0 |
| modern-events-calendar | 6,649 |
| notificationx | 1,561 |
| presto-player | 9,456 |
| presto-player-pro | 67 |
| random-quiz-addon-for-lifterlms | 5 |
| seating-charts | 313 |
| supportcandy | 1,342 |
| tickera-event-ticketing-system | 508 |
| woocommerce | 819,654 |
| woocommerce-memberships | 7,695 |
| wp-shamsi | 2,803 |
Security Headers
D
Grade D
3 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (5.7.15) — CVE-2024-4439: Unauthenticated Stored XSS. Update to 6.5.2 or later immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.