Site Information
WordPress Version: 5.3.21 ⚠️ VULNERABLE
Theme: grandtour (used by 290 domains)
Last Checked: 2026-07-22 13:00:43
HTTPS: ✅ Yes
Plugins (17)
| Plugin | Used By |
|---|---|
| advanced-backgrounds | 7,821 |
| booked | 9,360 |
| booked-frontend-agents | 371 |
| booked-woocommerce-payments | 243 |
| carousel-horizontal-posts-content-slider | 462 |
| contact-form-7 | 1,769,647 |
| different-menus-in-different-pages | 824 |
| grandtour-custom-post | 250 |
| kali-forms | 2,733 |
| post-views-counter | 29,203 |
| real-time-auto-find-and-replace | 9,894 |
| revslider | 614,561 |
| shortcode-for-current-date | 1,406 |
| sliderspack-all-in-one-image-sliders | 208 |
| woocommerce | 819,753 |
| wp-font-awesome | 2,821 |
| wp-review-slider-pro | 6,106 |
Security Headers
F
Grade F
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (5.3.21) — CVE-2024-4439: Unauthenticated Stored XSS. Update to 6.5.2 or later immediately.
- phpinfo.php exposed — Server configuration publicly visible ?
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.