Domain Information
WordPress Version: 7.0 VULNERABLE
Theme: astra (used by 400,217 domains)
Last Checked: 2026-08-24 09:15:07
HTTPS: Yes
Plugins (29)
| Plugin | Used By |
|---|---|
| addify-payment-gateway-fee-discounts | 80 |
| advanced-backgrounds | 7,566 |
| advanced-coupons-for-woocommerce-free | 5,053 |
| astra-pro-sites | 18,478 |
| avantlink-integration-for-woocommerce | 121 |
| contact-form-7 | 1,715,130 |
| credova-financial | 79 |
| customer-reviews-woocommerce | 11,415 |
| duracelltomi-google-tag-manager | 88,001 |
| elementor | 1,718,917 |
| essential-addons-for-elementor-lite | 255,652 |
| formidable | 72,053 |
| free-shipping-label | 584 |
| jet-engine | 76,204 |
| klaviyo | 9,193 |
| spectra-pro | 8,393 |
| ultimate-addons-for-gutenberg | 47,295 |
| variation-swatches-woo | 3,170 |
| woo-discount-rules | 17,111 |
| woo-discount-rules-pro | 8,229 |
| woo-product-attachment | 999 |
| woo-product-bundle | 4,344 |
| woocommerce | 794,091 |
| woocommerce-gateway-authorize-net-cim | 7,963 |
| woocommerce-product-addons | 10,524 |
| wp-age-gate | 0 |
| wp-store-locator | 16,905 |
| wployalty | 232 |
| youtube-embed-plus | 36,194 |
Security Headers
F
Grade F
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (7.0) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 7.0.2 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.