Site Information
WordPress Version: 5.6.17 ⚠️ VULNERABLE
Theme: oceanwp (used by 81,135 domains)
Last Checked: 2026-07-01 00:06:46
HTTPS: ✅ Yes
Plugins (17)
| Plugin | Used By |
|---|---|
| elementor | 1,780,304 |
| elementor-pro | 1,056,797 |
| miniorange-login-openid | 1,937 |
| ocean-cookie-notice | 1,162 |
| ocean-extra | 57,102 |
| ocean-footer-callout | 899 |
| ocean-instagram | 540 |
| ocean-modal-window | 1,800 |
| ocean-popup-login | 484 |
| ocean-portfolio | 1,309 |
| ocean-posts-slider | 1,482 |
| ocean-side-panel | 837 |
| ocean-social-sharing | 7,835 |
| ocean-stick-anything | 2,526 |
| ocean-sticky-footer | 566 |
| ocean-sticky-header | 5,280 |
| wpforms-lite | 125,269 |
Security Headers
C
Grade C
2 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (5.6.17) — CVE-2024-4439: Unauthenticated Stored XSS. Update to 6.5.2 or later immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.