Site Information
WordPress Version: 7.0 VULNERABLE
Theme: motif (used by 137 domains)
Last Checked: 2026-07-21 22:55:49
HTTPS: Yes
Plugins (17)
| Plugin | Used By |
|---|---|
| christmasify | 406 |
| custom-facebook-feed | 40,299 |
| dps-columns-extension-master | 109 |
| embedpress | 18,400 |
| genesis-blocks | 48,053 |
| honeypot | 96,407 |
| my-calendar | 5,695 |
| opening-hours | 954 |
| paid-memberships-pro | 9,820 |
| simple-banner | 17,209 |
| simple-download-monitor | 6,225 |
| smashballoon-wpchat-livechat-customer-support | 551 |
| srs-simple-hits-counter | 1,231 |
| t4b-news-ticker | 810 |
| tablepress | 101,206 |
| the-events-calendar | 120,211 |
| wp-data-access | 3,508 |
Security Headers
F
Grade F
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (7.0) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 7.0.2 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.