WordPress maintenance or security needs? Reach out!
TLDWP

Domain Security Report for d*v*l*c*s*o*s.com

Domain Information

WordPress Version: 6.8.3 VULNERABLE

Theme: dotwork (theme used by 9 domains)

Last Checked: 2026-09-07 22:42:09

HTTPS: Yes

Server: Apache

Response time (TTFB): 3,203 ms slow

Hosting: 282, Sector 19 (AS132420)

IP address: 101.53.154.xxx

PHP version: 7.3.33 — end-of-life, no security updates

Plugins (26)

Plugin Version Used By
brave-popup-builder 3,752
cart-for-woocommerce 3,415
cf7-multi-step 3,088
contact-form-7 1,707,342
country-dropdown-for-contact-form-7 220
country-state-city-auto-dropdown 1,050
customize-my-account-for-woocommerce 941
dotwork-core 8
email-subscribers 11,411
facebook-conversion-pixel 6,749
facebook-pagelike-widget 6,244
html5-videogallery-plus-player 306
instagram-feed 217,663
js_composer 404,320
menu-image 23,127
print-invoices-packing-slip-labels-for-woocommerce 1,084
quick-view-and-buy-now-for-woocommerce 142
revslider 586,216
rocket-lazy-load 19,389
sticky-menu-or-anything-on-scroll 18,362
woo-extra-flat-rate 963
woo-variation-gallery 3,472
woo-variation-swatches 30,805
woocommerce 789,108
wpcf7-redirect 53,558
wt-smart-coupons-for-woocommerce 4,784

Security Headers

F
Grade F

5 missing headers

Missing headers:

  • Strict-Transport-Security (HSTS) — Forces HTTPS connections ?
  • Content-Security-Policy (CSP) — Prevents XSS attacks ?
  • X-Content-Type-Options — Prevents MIME sniffing ?
  • X-Frame-Options — Prevents clickjacking ?
  • Permissions-Policy — Limits browser features ?

Exposed Files & Configurations

This domain has publicly accessible security-sensitive files or configurations:

  • Vulnerable WordPress Version (6.8.3) — unauthenticated SQL injection (CVE-2026-60137). Update to 6.8.6 immediately.

Need help securing your WordPress infrastructure? Contact us for a professional security audit.