Domain Information
WordPress Version: 6.8.3 VULNERABLE
Theme: twentynineteen (theme used by 11,003 domains)
Last Checked: 2026-08-25 14:48:00
HTTPS: Yes
Plugins (15)
| Plugin | Version | Used By |
|---|---|---|
| animated-number-counters | — | 395 |
| contact-form-7 | — | 1,685,958 |
| elementor | — | 1,678,767 |
| email-subscribers | — | 11,284 |
| essential-addons-for-elementor-lite | — | 248,826 |
| fluentform | — | 56,121 |
| g-business-reviews-rating | — | 4,803 |
| header-footer-elementor | — | 194,204 |
| mp3-jplayer | — | 1,528 |
| mp3-music-player-by-sonaar | — | 3,164 |
| mp3-player | — | 37 |
| multi-rating | — | 216 |
| page-views-count | — | 2,884 |
| rate-my-post | — | 5,994 |
| social-polls-by-opinionstage | — | 1,467 |
Security Headers
C
Grade C
2 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.8.3) — unauthenticated SQL injection (CVE-2026-60137). Update to 6.8.6 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.