Site Information
WordPress Version: 6.9.4 VULNERABLE
Theme: astra (used by 405,245 domains)
Last Checked: 2026-08-29 04:57:50
HTTPS: No
Plugins (12)
| Plugin | Used By |
|---|---|
| astra-addon | 91,881 |
| astra-pro-sites | 18,664 |
| elementskit-lite | 175,308 |
| if-menu | 9,608 |
| jobs | 18 |
| jobseeker-import-manager | 0 |
| jobshola-admin | 0 |
| paynow-sg-gravityforms | 0 |
| spectra-pro | 8,420 |
| turn-rank-math-faq-block-to-accordion | 1,326 |
| ultimate-addons-for-gutenberg | 47,924 |
| wp-whatsapp | 15,334 |
Security Headers
F
Grade F
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9.4) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
- phpinfo.php exposed — Server configuration publicly visible ?
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.