Domain Information
WordPress Version: 6.9.4 VULNERABLE
Theme: projectinvictus
Last Checked: 2026-09-05 16:12:56
HTTPS: Yes
Server: nginx
CDN / WAF: CloudFront
Response time (TTFB): 1,420 ms slow
Hosting: Amazon.com, Inc. (AS16509)
IP address: 18.239.105.xxx
Plugins (16)
| Plugin | Version | Used By |
|---|---|---|
| elementor | — | 1,689,719 |
| elementor-pro | — | 1,005,817 |
| fooevents | — | 1,626 |
| hextra-aws-cloudfront | — | 5 |
| kk-star-ratings | — | 15,242 |
| megamenu | — | 76,897 |
| pixelyoursite | — | 69,437 |
| rapid-support-popup | — | 0 |
| scalapay-payment-gateway-for-woocommerce | — | 200 |
| terms-consent-manager | — | 0 |
| wc-carta-docente-premium | — | 24 |
| wc-carte-cultura-premium | — | 8 |
| woocommerce | — | 781,569 |
| woocommerce-paypal-payments | — | 33,200 |
| woocommerce-product-bundles | — | 8,125 |
| woocommerce-smart-coupons | — | 4,411 |
Security Headers
2 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9.4) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
Need help securing your WordPress infrastructure? Contact us for a professional security audit.
Other WordPress domains on this IP (5)
These WordPress domains are served from the same IP (18.239.105.xxx) — usually shared hosting or the same operator. Domains are obfuscated uniformly.