Domain Information
WordPress Version: 6.9.1 VULNERABLE
Theme: woodmart 8.0.6· 100% conf. (theme used by 44,484 domains)
Last Checked: 2026-09-10 07:17:04
HTTPS: Yes
Server: Apache
Response time (TTFB): 1,287 ms slow
Hosting: IONOS SE (AS8560)
IP address: 217.160.0.xxx
PHP version: 8.5.10
Plugins (16)
| Plugin | Version | Used By |
|---|---|---|
| conditional-fields-for-elementor-form | 1.6.2· 60% conf. | 3,145 |
| daily-prayer-time-for-mosques | 2025.10.26· 85% conf. | 151 |
| elementor | 4.2.4· 85% conf. | 1,695,155 |
| elementor-pro | 3.27.3· 85% conf. | 1,009,656 |
| essential-addons-for-elementor-lite | 6.5.11· 85% conf. | 251,601 |
| give | — | 17,173 |
| give-gift-aid | 2.1.3· 85% conf. | 245 |
| give-recurring | 2.11.1· 85% conf. | 3,791 |
| give-stripe | 2.6.0· 60% conf. | 784 |
| jet-appointments-booking | 2.1.5· 60% conf. | 736 |
| jet-engine | 3.6.3· 60% conf. | 75,225 |
| jet-popup | 2.0.11· 85% conf. | 16,278 |
| jetformbuilder | 1.0.0· 60% conf. | 5,752 |
| powerpack-elements | 2.11.10· 85% conf. | 14,650 |
| woocommerce | 10.5.3· 85% conf. | 783,975 |
| woocommerce-gateway-stripe | — | 57,963 |
Security Headers
6 missing headers
Missing headers:
- Strict-Transport-Security (HSTS) — Forces HTTPS connections ?
- Content-Security-Policy (CSP) — Prevents XSS attacks ?
- X-Content-Type-Options — Prevents MIME sniffing ?
- X-Frame-Options — Prevents clickjacking ?
- Referrer-Policy — Controls referrer information ?
- Permissions-Policy — Limits browser features ?
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9.1) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.
Other WordPress domains on this IP (25+)
These WordPress domains are served from the same IP (217.160.0.xxx) — usually shared hosting or the same operator. Domains are obfuscated uniformly.
- a*d*e*m*u*e*i*u*r*z*o*i*t*.com
- a*g*l*n*-*j.com
- a*n*c*s*n*v*s*a*v*c*d*.com
- a*n*a*r*n*t*.com
- a*a*t*m*n*o*m*r*n*c*r*e*i*.com
- b*r*w*k*-*a*s*.com
- b*a*d*b*a*n*.com
- b*a*o*m*t*r*y*l*s.c*.uk
- b*g*r*n*e*r*p*.com
- d*n*e*s*n*g*b*.com
- d*f*a*t*l*.com
- d*c*i*p*o*o*s*t*.com
- d*c*n*r*d.com
- d*i*e*k*a*r*i*m.de
- d*n*i*t*y*8*.com
- d*r*b*d*e*k*r.com
- d*s*m*s*n*o*t*i*l*.com
- d*s*t*a*q*e*-*i*a*r*.com
- d*s*t*a*q*e*l*s*g*a.com
- d*s*l*s*k*l*i*n.com
- e*r*e*p*r*t*e.com
- e*e*l*e*-*o*s.com
- e*i*h*l*m*s*c.com
- e*i*e*c*m*t*r*p*r*.com
- e*p*e*s*j*r*d*q*e.com