Site Information
WordPress Version: 7.0 VULNERABLE
Theme: joyas-shop (used by 111 domains)
Last Checked: 2026-07-09 14:29:23
HTTPS: Yes
Plugins (23)
| Plugin | Used By |
|---|---|
| advanced-product-search-for-woo | 404 |
| all-in-one-seo-pack-pro | 8,306 |
| chatway-live-chat | 1,931 |
| facebook-for-woocommerce | 26,221 |
| forget-about-shortcode-buttons | 5,951 |
| google-listings-and-ads | 25,038 |
| instagram-feed-pro | 32,270 |
| jetpack | 449,587 |
| krokedil-product-documents | 20 |
| mailchimp-for-woocommerce | 45,028 |
| nextend-smart-slider3-pro | 21,713 |
| onecom-themes-plugins | 119 |
| theme-customisations | 228 |
| theme-essentials | 11 |
| tiktok-for-business | 4,313 |
| universally-language-translation-multilingual-tool | 1,575 |
| woo-epassi | 75 |
| woo-out-of-stock-products | 262 |
| woo-swish-e-commerce | 196 |
| woocommerce | 809,308 |
| woocommerce-payments | 107,872 |
| woocommerce-waitlist | 1,183 |
| yith-woocommerce-badge-management-premium | 992 |
Security Headers
F
Grade F
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (7.0) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 7.0.2 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.