Site Information
WordPress Version: 6.9.4 VULNERABLE
Theme: briny (used by 118 domains)
Last Checked: 2026-07-14 23:44:44
HTTPS: Yes
Plugins (24)
| Plugin | Used By |
|---|---|
| akismet | 83,173 |
| auto-terms-of-service-and-privacy-policy | 16,775 |
| basekit-addons | 101 |
| contact-form-7 | 1,726,397 |
| creame-whatsapp-me | 67,258 |
| duracelltomi-google-tag-manager | 88,731 |
| elementor | 1,737,471 |
| essential-addons-for-elementor-lite | 258,821 |
| essential-blocks | 23,394 |
| essential-grid | 34,021 |
| exclusive-addons-for-elementor | 7,103 |
| gdpr-cookie-compliance | 66,579 |
| google-site-kit | 245,603 |
| happy-elementor-addons | 48,508 |
| header-footer-elementor | 201,465 |
| premium-addons-for-elementor | 81,334 |
| revslider | 594,292 |
| royal-elementor-addons | 54,119 |
| sitepress-multilingual-cms | 206,942 |
| trx_addons | 21,777 |
| trx_socials | 795 |
| types | 4,470 |
| wplegalpages | 2,887 |
| wpml-cms-nav | 20,109 |
Security Headers
F
Grade F
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9.4) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.