Site Information
WordPress Version: 6.9.4 VULNERABLE
Theme: twentynineteen (used by 11,581 domains)
Last Checked: 2026-07-09 05:19:41
HTTPS: Yes
Plugins (17)
| Plugin | Used By |
|---|---|
| 3d-flipbook-dflip-lite | 43,937 |
| advanced-woo-search | 10,815 |
| ajax-search-lite | 15,866 |
| easy-fancybox | 45,751 |
| google-listings-and-ads | 25,176 |
| independent-analytics | 18,513 |
| instagram-feed | 224,950 |
| official-mailerlite-sign-up-forms | 18,538 |
| oxy-toolbox | 1,022 |
| oxygen | 25,070 |
| pinterest-for-woocommerce | 4,970 |
| sticky-social-icons | 1,152 |
| woo-mailerlite | 2,829 |
| woocommerce | 816,111 |
| woocommerce-paypal-payments | 51,679 |
| woocommerce-square | 11,090 |
| wp-smushit | 90,918 |
Security Headers
C
Grade C
2 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9.4) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.