Domain Information
WordPress Version: 6.9 VULNERABLE
Theme: medova 1.0.0· 100% conf. (theme used by 9 domains)
Last Checked: 2026-09-08 21:49:57
HTTPS: Yes
Server: Apache
Response time (TTFB): 1,768 ms slow
Hosting: IONOS SE (AS8560)
IP address: 74.208.236.xxx
PHP version: 8.3.33
Plugins (12)
| Plugin | Version | Used By |
|---|---|---|
| contact-form-7 | 6.1· 85% conf. | 1,694,402 |
| elementor | 3.29.2· 85% conf. | 1,689,719 |
| elementor-pro | 3.30.0· 85% conf. | 1,005,817 |
| fluentform | 6.0.4· 60% conf. | 56,499 |
| medova-core | 1.0· 85% conf. | 9 |
| payment-forms-for-paystack | 4.0.4· 85% conf. | 258 |
| rave-payment-forms | 1.0.6· 60% conf. | 41 |
| techmattaz-whatsapp-widget | 4.0.6· 85% conf. | 0 |
| visitors-traffic-real-time-statistics-pro | — | 1,142 |
| woo-smart-quick-view | 4.1.9· 85% conf. | 5,888 |
| woo-smart-wishlist | 5.0.0· 85% conf. | 7,095 |
| woocommerce | 9.9.7· 85% conf. | 781,569 |
Security Headers
6 missing headers
Missing headers:
- Strict-Transport-Security (HSTS) — Forces HTTPS connections ?
- Content-Security-Policy (CSP) — Prevents XSS attacks ?
- X-Content-Type-Options — Prevents MIME sniffing ?
- X-Frame-Options — Prevents clickjacking ?
- Referrer-Policy — Controls referrer information ?
- Permissions-Policy — Limits browser features ?
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.
Other WordPress domains on this IP (25+)
These WordPress domains are served from the same IP (74.208.236.xxx) — usually shared hosting or the same operator. Domains are obfuscated uniformly.
- b*r*2*i*e*t*d*o*.com
- b*i*r*s*n*i*l*.com
- d*l*e*r*h*r*t*n*.com
- d*l*e*r*h*r*t*e*u*s.com
- d*e*t*r*o*.com
- d*t*c*n*l*g*l*c.com
- d*s*r*h*s*i*a*i*y.com
- d*s*g*e*l*b*l*d.com
- e*l*n*e*t*.com
- e*a*o*a*g*l*s.com
- e*p*o*i*g*n*l*s*l*.com
- f*i*y*a*e*t*d*o.com
- h*r*w*g*o*-*l*.com
- h*r*c*p*t*l*s*.com
- h*g*t*i*l*n*.com
- i*n*v*t*o*m*r*l*n*.org
- k*r*w*g*t*u*t*n.com
- k*s*d*d*v*l*p*e*t*.com
- k*l*y*o*h*r*.com
- k*n*a*l*a*k*s*c*o*o*i*t.com
- k*n*l*o*t*g*s*e*.com
- k*n*u*k*c*n*o*a*.com
- k*r*y*a*n*a*d*.com
- k*n*e*d*n*e*t*.com
- k*u*t*m*r.com