Domain Information
WordPress Version: 6.9.3 VULNERABLE
Theme: astra (theme used by 396,526 domains)
Last Checked: 2026-07-24 23:49:43
HTTPS: Yes
Plugins (23)
| Plugin | Version | Used By |
|---|---|---|
| astra-sites | — | 106,680 |
| click-to-chat-for-whatsapp | — | 57,462 |
| currency-converter-widget | — | 223 |
| elementor | — | 1,707,286 |
| fluentform | — | 57,134 |
| google-listings-and-ads | — | 24,379 |
| google-site-kit | — | 258,056 |
| header-footer-elementor | — | 197,317 |
| jetpack | — | 411,832 |
| login-with-phone-number | — | 101 |
| miniorange-otp-verification | — | 557 |
| mystickymenu | — | 16,775 |
| pixelyoursite | — | 70,333 |
| shopengine | — | 4,031 |
| smart-slider-3 | — | 73,611 |
| variation-swatches-woo | — | 3,101 |
| woo-custom-add-to-cart-button | — | 1,264 |
| woo-variation-swatches | — | 30,805 |
| woocommerce-google-adwords-conversion-tracking-tag | — | 9,677 |
| wp-sms | — | 1,450 |
| wp-smushit | — | 87,233 |
| wp-whatsapp-chat | — | 25,169 |
| wpforms-lite | — | 116,435 |
Security Headers
B
Grade B
1 missing header
Missing headers:
- Content-Security-Policy (CSP) — Prevents XSS attacks ?
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9.3) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
Need help securing your WordPress infrastructure? Contact us for a professional security audit.