Site Information
WordPress Version: 6.9.4 VULNERABLE
Theme: astra (used by 413,905 domains)
Last Checked: 2026-07-06 14:01:41
HTTPS: Yes
Plugins (22)
| Plugin | Used By |
|---|---|
| breeze-checkout | 8 |
| duracelltomi-google-tag-manager | 90,308 |
| elementor | 1,769,959 |
| elementor-pro | 1,052,336 |
| elementskit-lite | 180,021 |
| enhanced-e-commerce-for-woocommerce-store | 2,227 |
| essential-addons-for-elementor-lite | 264,693 |
| events-tracker-for-elementor | 1,807 |
| google-site-kit | 232,595 |
| gwl-variation-gallery | 0 |
| mabel-shoppable-images-lite | 443 |
| premium-addons-for-elementor | 84,366 |
| say-what | 7,153 |
| site-reviews | 11,272 |
| slider-and-carousel-plus-widget-for-instagram | 616 |
| stratum | 3,513 |
| variation-updater | 0 |
| woo-discount-rules | 17,656 |
| woo-variation-gallery | 3,595 |
| woocommerce | 816,094 |
| wp-store-locator | 17,442 |
| wpc-sticky-add-to-cart | 305 |
Security Headers
C
Grade C
2 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9.4) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.