WordPress maintenance or security needs? Reach out!
TLDWP

Domain Security Report for h*v*y*c*d*m*.com

Domain Information

WordPress Version: 5.4.21 VULNERABLE

Theme: astra (theme used by 394,051 domains)

Last Checked: 2026-09-03 13:34:45

HTTPS: Yes

Plugins (31)

Plugin Version Used By
bbpress 13,211
bp-activity-plus-reloaded 88
buddypress 6,171
buddypress-learndash 130
design-upgrade-learndash 769
dynamicconditions 17,493
elementor 1,695,155
elementor-pro 1,009,656
event-espresso-core-reg 845
events-addon-for-elementor 873
google-analytics-for-wordpress 194,980
gp-limit-dates 466
gp-populate-anything 561
gravityforms 246,917
gravityformssignature 313
gravityformssurvey 390
header-footer-elementor 195,990
jet-engine 75,225
ld-content-cloner 586
mediapress 363
page-links-to 55,941
seriously-simple-podcasting 2,885
sfwd-lms 13,257
stax-buddy-builder 0
tin-canny-learndash-reporting 677
uncanny-learndash-toolkit 3,743
uncanny-toolkit-pro 1,494
w3-total-cache 37,577
wp-staging 1,169
wp-user 0
wpforms-lite 115,645

Security Headers

D
Grade D

4 missing headers

Missing headers:

  • Strict-Transport-Security (HSTS) — Forces HTTPS connections ?
  • X-Content-Type-Options — Prevents MIME sniffing ?
  • X-Frame-Options — Prevents clickjacking ?
  • Permissions-Policy — Limits browser features ?

Exposed Files & Configurations

This domain has publicly accessible security-sensitive files or configurations:

  • Vulnerable WordPress Version (5.4.21) — outdated core with known vulnerabilities. Update to the latest release immediately.
  • phpinfo.php exposed — Server configuration publicly visible ?

Need help securing your WordPress infrastructure? Contact us for a professional security audit.