Domain Information
WordPress Version: 6.9.4 VULNERABLE
Theme: Avada-Child-Theme 1.0.0· 60% conf. (theme used by 35,838 domains)
Last Checked: 2026-09-10 11:43:11
HTTPS: Yes
Server: Apache
Response time (TTFB): 1,436 ms slow
Hosting: Keyweb AG (AS31103)
IP address: 62.141.50.xxx
Plugins (6)
| Plugin | Version | Used By |
|---|---|---|
| accessibility-onetap | 2.10.0· 85% conf. | 8,360 |
| fusion-builder | 3.15.3· 85% conf. | 73,913 |
| fusion-core | 5.15.3· 85% conf. | 36,922 |
| revslider | 6.7.41· 85% conf. | 580,456 |
| smoky-floating-contact-buttons | 1.2.0· 85% conf. | 0 |
| timed-content | 2.97· 85% conf. | 1,667 |
Security Headers
3 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9.4) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.