Domain Information
WordPress Version: 5.0.27 VULNERABLE
Theme: weluka-theme-00 (theme used by 167 domains)
Last Checked: 2026-09-05 21:17:05
HTTPS: Yes
Server: nginx
Response time (TTFB): 2,303 ms slow
Hosting: SAKURA Internet Inc. (AS9371)
IP address: 49.212.237.xxx
PHP version: 7.4.33 — end-of-life, no security updates
Plugins (21)
| Plugin | Version | Used By |
|---|---|---|
| add-to-any | — | 69,260 |
| buddypress | — | 6,172 |
| contact-form-7 | — | 1,699,668 |
| download-monitor | — | 20,078 |
| easy-wp-page-navigation | — | 186 |
| google-language-translator | — | 25,555 |
| menu-image | — | 22,992 |
| mycred | — | 1,339 |
| paid-memberships-pro | — | 9,680 |
| popup-maker | — | 104,824 |
| smart-slider-3 | — | 73,208 |
| stripe-payments | — | 4,345 |
| vk-post-author-display | — | 2,321 |
| w3-total-cache | — | 37,607 |
| weluka | — | 248 |
| wordpress-23-related-posts-plugin | — | 1,998 |
| wordpress-popular-posts | — | 34,506 |
| wp-masonry-layout | — | 332 |
| wp-pagenavi-style | — | 1,623 |
| wp-postratings | — | 6,354 |
| wp-ulike | — | 7,292 |
Security Headers
6 missing headers
Missing headers:
- Strict-Transport-Security (HSTS) — Forces HTTPS connections ?
- Content-Security-Policy (CSP) — Prevents XSS attacks ?
- X-Content-Type-Options — Prevents MIME sniffing ?
- X-Frame-Options — Prevents clickjacking ?
- Referrer-Policy — Controls referrer information ?
- Permissions-Policy — Limits browser features ?
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (5.0.27) — outdated core with known vulnerabilities. Update to the latest release immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.