Site Information
WordPress Version: 7.0.1 VULNERABLE
Theme: Avada-Child-Theme (used by 36,495 domains)
Last Checked: 2026-07-16 16:35:50
HTTPS: Yes
Plugins (22)
| Plugin | Used By |
|---|---|
| auto-terms-of-service-and-privacy-policy | 16,775 |
| contact-form-7 | 1,726,397 |
| custom-user-defined-pricing-for-woocommerce | 19 |
| elementor | 1,737,471 |
| essential-addons-for-elementor-lite | 258,821 |
| fusion-builder | 75,604 |
| fusion-core | 37,818 |
| give | 17,359 |
| give-2checkout | 48 |
| give-authorize-net | 399 |
| give-currency-switcher | 483 |
| give-donation-upsells-woocommerce | 189 |
| give-fee-recovery | 1,784 |
| give-form-field-manager | 2,540 |
| give-funds | 688 |
| give-gift-aid | 246 |
| give-recurring | 3,882 |
| give-tributes | 1,134 |
| user-registration-for-woocommerce | 56 |
| woo-conditional-product-fees-for-checkout | 1,504 |
| woocommerce | 802,542 |
| woocommerce-gateway-authorize-net-cim | 8,129 |
Security Headers
F
Grade F
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (7.0.1) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 7.0.2 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.