Site Information
WordPress Version: 7.0 VULNERABLE
Theme: oceanwp (used by 80,372 domains)
Last Checked: 2026-06-30 06:56:02
HTTPS: Yes
Plugins (20)
| Plugin | Used By |
|---|---|
| borlabs-cookie | 65,297 |
| contact-form-7 | 1,752,449 |
| contact-form-7-honeypot | 37,455 |
| contact-form-7-signature-addon | 1,447 |
| elementor | 1,770,693 |
| elementor-pro | 1,052,481 |
| embedpress | 18,924 |
| embedpress-pro | 916 |
| events-calendar-pro | 27,077 |
| lightbox-photoswipe | 5,688 |
| mailster | 1,765 |
| mappress-google-maps-for-wordpress | 8,916 |
| podlove-podcasting-plugin-for-wordpress | 937 |
| podlove-web-player | 1,168 |
| post-views-counter | 29,426 |
| registrations-for-the-events-calendar-pro | 388 |
| stars-at-night | 36 |
| the-events-calendar | 122,493 |
| wp-gdpr-compliance | 12,857 |
| wpdatatables | 7,237 |
Security Headers
D
Grade D
3 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (7.0) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 7.0.2 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.