Domain Information
WordPress Version: 6.2.11 VULNERABLE
Theme: agama-pro 1.4.1.1· 100% conf. (theme used by 179 domains)
Last Checked: 2026-09-11 12:04:42
HTTPS: Yes
Server: Apache
Response time (TTFB): 3,962 ms slow
Hosting: CNIT Italian National Consortium for Telecommunications (AS20745)
IP address: 217.9.64.xxx
Plugins (15)
| Plugin | Version | Used By |
|---|---|---|
| cf7-conditional-fields | 2.3.8· 85% conf. | 32,811 |
| contact-form-7 | 5.7.6· 85% conf. | 1,694,402 |
| download-attachments | 1.4.1· 60% conf. | 1,064 |
| drag-and-drop-multiple-file-upload-contact-form-7 | 1.3.9.9· 85% conf. | 11,186 |
| easy-accordion-free | 3.1.10· 85% conf. | 5,283 |
| gdpr-compliant-recaptcha-for-all-forms | 5.6.0· 60% conf. | 508 |
| photo-gallery | — | 33,771 |
| responsive-menu | 4.3.2· 60% conf. | 14,547 |
| vision-core | 1.1.6· 85% conf. | 171 |
| wp-accessibility | 2.3.3· 85% conf. | 17,554 |
| wp-gallery-custom-links | 1.1· 60% conf. | 5,400 |
| wp-pagenavi | 2.70· 60% conf. | 75,553 |
| wp-video-lightbox | 3.1.6· 85% conf. | 9,559 |
| yop-poll | — | 1,398 |
| youtube-embed-plus | 14.2.4· 85% conf. | 35,569 |
Security Headers
6 missing headers
Missing headers:
- Strict-Transport-Security (HSTS) — Forces HTTPS connections ?
- Content-Security-Policy (CSP) — Prevents XSS attacks ?
- X-Content-Type-Options — Prevents MIME sniffing ?
- X-Frame-Options — Prevents clickjacking ?
- Referrer-Policy — Controls referrer information ?
- Permissions-Policy — Limits browser features ?
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.2.11) — outdated core with known vulnerabilities. Update to the latest release immediately.
Need help securing your WordPress infrastructure? Contact us for a professional security audit.