Site Information
WordPress Version: 6.9.4 VULNERABLE
Theme: blocksy (used by 50,827 domains)
Last Checked: 2026-07-23 20:17:37
HTTPS: Yes
Plugins (13)
| Plugin | Used By |
|---|---|
| ajax-search-for-woocommerce | 21,143 |
| blocksy-companion-pro | 14,009 |
| coordinadora | 34 |
| creame-whatsapp-me | 69,709 |
| duracelltomi-google-tag-manager | 90,308 |
| facebook-for-woocommerce | 26,239 |
| google-listings-and-ads | 25,133 |
| omnisend-connect | 2,349 |
| popup-maker | 109,701 |
| stackable-ultimate-gutenberg-blocks | 12,688 |
| woo-product-bundle | 4,389 |
| woocommerce | 816,094 |
| wpforms-lite | 123,739 |
Security Headers
B
Grade B
1 missing header
Missing headers:
- Content-Security-Policy (CSP) — Prevents XSS attacks ?
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9.4) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
Need help securing your WordPress site? Contact us for a professional security audit.