Site Information
WordPress Version: 6.9 VULNERABLE
Theme: astra (used by 405,245 domains)
Last Checked: 2026-08-23 20:46:15
HTTPS: Yes
Plugins (21)
| Plugin | Used By |
|---|---|
| astra-addon | 91,881 |
| astra-portfolio | 2,807 |
| astra-pro-sites | 18,664 |
| better-payment | 500 |
| betterdocs | 5,198 |
| betterlinks | 3,455 |
| contact-form-7 | 1,728,599 |
| elementor | 1,739,910 |
| elementor-pro | 1,036,042 |
| essential-addons-for-elementor-lite | 259,216 |
| essential-blocks | 23,435 |
| h5p | 4,781 |
| header-footer-elementor | 201,778 |
| learnpress | 6,864 |
| presto-player | 8,986 |
| surecart | 4,280 |
| sureforms | 7,085 |
| suretriggers | 4,872 |
| tablepress | 101,608 |
| ultimate-member | 27,547 |
| wp-live-chat-support | 6,112 |
Security Headers
B
Grade B
1 missing header
Missing headers:
- Content-Security-Policy (CSP) — Prevents XSS attacks ?
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
Need help securing your WordPress site? Contact us for a professional security audit.