Domain Information
WordPress Version: 6.1.12 VULNERABLE
Theme: spacious (used by 4,180 domains)
Last Checked: 2026-09-07 06:41:45
HTTPS: Yes
Server: Apache
Response time (TTFB): 20,017 ms slow
Hosting: Cogent Communications, LLC (AS174)
IP address: 38.45.64.xxx
Plugins (27)
| Plugin | Used By |
|---|---|
| bbpress | 13,306 |
| bigbluebutton | 111 |
| candy-social-widget | 39 |
| cookie-notice | 143,627 |
| drop-shadow-boxes | 959 |
| emember-profile-extended | 27 |
| estore-advanced-variations-ui | 18 |
| estore-browse-products-by-category | 21 |
| estore-bulk-item-purchase | 0 |
| estore-extra-shortcodes | 274 |
| estore-stylish-squeeze-form | 25 |
| everest-forms | 12,002 |
| h5p | 4,708 |
| instagram-feed | 218,355 |
| modern-events-calendar-lite | 13,738 |
| notibar | 1,085 |
| protected-video | 122 |
| simple-google-recaptcha | 7,738 |
| simply-gallery-block | 6,776 |
| siteorigin-panels | 55,310 |
| so-widgets-bundle | 27,746 |
| ultimate-social-media-icons | 25,602 |
| wp-affiliate-platform | 216 |
| wp-cart-for-digital-products | 705 |
| wp-emember | 366 |
| wp-lightbox-ultimate | 117 |
| wp-payment-gateway | 63 |
Security Headers
6 missing headers
Missing headers:
- Strict-Transport-Security (HSTS) — Forces HTTPS connections ?
- Content-Security-Policy (CSP) — Prevents XSS attacks ?
- X-Content-Type-Options — Prevents MIME sniffing ?
- X-Frame-Options — Prevents clickjacking ?
- Referrer-Policy — Controls referrer information ?
- Permissions-Policy — Limits browser features ?
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.1.12) — outdated core with known vulnerabilities. Update to the latest release immediately.
- phpinfo.php exposed — Server configuration publicly visible ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.