WordPress maintenance or security needs? Reach out!
TLDWP

Domain Security Report for a*o*l*p*a*s.com

Domain Information

WordPress Version: 7.1

Theme: wallstreet 2.8.2· 100% conf. (theme used by 234 domains)

Last Checked: 2026-09-10 12:52:45

HTTPS: Yes

Server: nginx

Response time (TTFB): 1,820 ms slow

Hosting: Alibaba (US) Technology Co., Ltd. (AS45102)

IP address: 8.217.184.xxx

Plugins (17)

Plugin Version Used By
add-to-any 68,978
all-in-one-seo-pack 5.0.1.1· 60% conf. 84,480
contact-form-7 6.1.7· 85% conf. 1,694,402
easy-login-woocommerce 4.0.4· 85% conf. 3,468
elementor 4.2.4· 85% conf. 1,689,719
elementskit-lite 4.0.5· 85% conf. 169,378
google-analytics-for-wordpress 11.2.0· 60% conf. 194,301
header-footer-elementor 2.9.4· 85% conf. 195,384
jetpack 16.1.3· 60% conf. 402,304
paid-memberships-pro 3.6.4· 85% conf. 9,636
payerurl-crypto-currency-payment-gateway-for-woocommerce 185
shopengine 4.9.5· 85% conf. 3,975
spice-post-slider 2.2.1· 85% conf. 823
super-socializer 7.14.5· 85% conf. 4,045
tutor 4.0.7· 85% conf. 7,256
woo-save-abandoned-carts 8.10.2· 85% conf. 1,391
woocommerce-paypal-payments 4.1.3· 85% conf. 33,200

Security Headers

D
Grade D

4 missing headers

Missing headers:

  • Content-Security-Policy (CSP) — Prevents XSS attacks ?
  • X-Content-Type-Options — Prevents MIME sniffing ?
  • X-Frame-Options — Prevents clickjacking ?
  • Referrer-Policy — Controls referrer information ?

Exposed Files & Configurations

This domain has publicly accessible security-sensitive files or configurations:

  • User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?

Need help securing your WordPress infrastructure? Contact us for a professional security audit.