Domain Information
WordPress Version: 5.5.20 VULNERABLE
Theme: oriel 1.6.1· 100% conf. (theme used by 9 domains)
Last Checked: 2026-09-10 22:06:46
HTTPS: Yes
Server: Apache
Response time (TTFB): 2,356 ms slow
Hosting: IONOS SE (AS8560)
IP address: 217.160.0.xxx
PHP version: 7.4.33 — end-of-life, no security updates
Plugins (13)
| Plugin | Version | Used By |
|---|---|---|
| 1and1-wordpress-assistant | — | 5,669 |
| block-gallery | 1.1.6· 60% conf. | 418 |
| column-shortcodes | 1.0· 60% conf. | 14,548 |
| contact-form-7 | 5.1.3· 85% conf. | 1,694,402 |
| dvgallery | 1.0· 85% conf. | 84 |
| gallery-videos | — | 2,572 |
| oriel-features | 1.0· 85% conf. | 24 |
| photo-gallery | 1.5.30· 85% conf. | 33,771 |
| responsive-lightbox | 2.1.0· 85% conf. | 32,820 |
| robo-gallery | 2.8.25· 60% conf. | 6,893 |
| team-members | — | 5,187 |
| translatepress-multilingual | 1.5.1· 60% conf. | 64,960 |
| wpgsi | 3.7.6· 85% conf. | 316 |
Security Headers
6 missing headers
Missing headers:
- Strict-Transport-Security (HSTS) — Forces HTTPS connections ?
- Content-Security-Policy (CSP) — Prevents XSS attacks ?
- X-Content-Type-Options — Prevents MIME sniffing ?
- X-Frame-Options — Prevents clickjacking ?
- Referrer-Policy — Controls referrer information ?
- Permissions-Policy — Limits browser features ?
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (5.5.20) — outdated core with known vulnerabilities. Update to the latest release immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.
Other WordPress domains on this IP (25+)
These WordPress domains are served from the same IP (217.160.0.xxx) — usually shared hosting or the same operator. Domains are obfuscated uniformly.
- 1*0*-*o*m*r.de
- a*d*e*p*c*e*.com
- a*p*p*s*i*a.com
- a*u*v*d*a*a*o*r*e.fr
- b*b*s*e*n.org
- b*b*a*y.de
- b*a*n*p*t*i*g*u*t*i*.com
- b*a*e*e*d*r*.es
- b*o*h*r*-*m*x.com
- b*o*r*g*l.com
- b*u*a*t*e*s.com
- c*b*o.de
- c*a*c*t*r*a*i*e*t*.com
- c*f*e*t*s.biz
- c*a*h*n*r*i*e*-*a*i*e.de
- c*e*t*-*i*h*.de
- d*f*i*o*m*t*o*.fr
- d*a*t*i*f*l*.com
- d*r*o*d*h*t*g*a*h*.com
- d*s*g*a*l*a*c*.de
- d*e*e*-*e*e*.com
- d*g*a*t*o.com
- d*r*t*e*-*l*e*s.de
- d*s*a*a*.com
- d*e*-*c*e*b*.de