Site Information
WordPress Version: 6.9.4 VULNERABLE
Theme: shopkeeper (used by 1,896 domains)
Last Checked: 2026-07-14 10:23:52
HTTPS: Yes
Plugins (24)
| Plugin | Used By |
|---|---|
| contact-widgets | 4,515 |
| custom-facebook-feed-pro | 13,224 |
| custom-scrollbar | 483 |
| event-tickets | 19,092 |
| events-calendar-pro | 26,870 |
| facebook-for-woocommerce | 26,175 |
| google-analytics-for-wordpress | 200,261 |
| google-listings-and-ads | 24,853 |
| hookmeup | 1,753 |
| jetpack | 445,014 |
| js_composer | 409,969 |
| koala-google-recaptcha-for-woocommerce | 437 |
| mailchimp-for-woocommerce | 44,312 |
| official-facebook-pixel | 36,176 |
| shopkeeper-extender | 1,332 |
| strong-testimonials | 9,116 |
| tabs-shortcode-and-widget | 138 |
| userfeedback-lite | 1,720 |
| woocommerce-google-analytics-integration | 28,043 |
| woocommerce-payments | 106,965 |
| woocommerce-square | 10,848 |
| wp-facebook-pixel | 157 |
| yikes-inc-easy-mailchimp-extender | 2,475 |
| yikes-inc-easy-mailchimp-popup-extension | 12 |
Security Headers
F
Grade F
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9.4) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.