Domain Information
WordPress Version: 5.6.19 VULNERABLE
Theme: twentytwenty 1.5· 100% conf. (theme used by 27,201 domains)
Last Checked: 2026-09-11 20:59:15
HTTPS: Yes
Server: Apache
Response time (TTFB): 1,035 ms slow
Hosting: Amazon.com, Inc. (AS14618)
IP address: 54.175.69.xxx
PHP version: 7.4.13 — end-of-life, no security updates
Plugins (10)
| Plugin | Version | Used By |
|---|---|---|
| elementor | 3.0.16· 85% conf. | 1,678,767 |
| elementor-pro | 3.0.9· 85% conf. | 998,699 |
| float-menu | 3.4· 85% conf. | 3,710 |
| happy-elementor-addons | 2.18.0· 85% conf. | 46,705 |
| happy-elementor-addons-pro | 1.13.1· 85% conf. | 7,742 |
| mousewheel-smooth-scroll | 1.4.10· 60% conf. | 11,376 |
| popup-maker | 1.14.0· 85% conf. | 103,253 |
| pum-videos | 1.1.4· 85% conf. | 63 |
| wpforms | 1.6.7· 60% conf. | 51,300 |
| yikes-inc-easy-mailchimp-extender | 6.7.0· 85% conf. | 2,404 |
Security Headers
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (5.6.19) — outdated core with known vulnerabilities. Update to the latest release immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.