Site Information
WordPress Version: 5.9.3 ⚠️ VULNERABLE
Theme: astra (used by 417,037 domains)
Last Checked: 2026-06-06 23:59:46
HTTPS: ✅ Yes
Plugins (18)
| Plugin | Used By |
|---|---|
| addon-elements-for-elementor-page-builder | 17,063 |
| chaty-pro | 4,536 |
| contact-form-7 | 1,766,500 |
| cookie-notice | 150,866 |
| custom-facebook-feed | 42,281 |
| custom-twitter-feeds | 33,472 |
| dynamic-content-for-elementor | 14,295 |
| elementor | 1,796,703 |
| elementor-pro | 1,047,233 |
| elfsight-weather-cc | 258 |
| feeds-for-youtube | 12,548 |
| google-language-translator | 28,541 |
| header-footer-elementor | 209,749 |
| instagram-feed | 227,632 |
| klaviyo | 9,750 |
| reviews-feed | 20,353 |
| tiktok-for-business | 4,346 |
| wp-live-chat-software-for-wordpress | 4,377 |
Security Headers
D
Grade D
4 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (5.9.3) — CVE-2024-4439: Unauthenticated Stored XSS. Update to 6.5.2 or later immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.