Site Information
WordPress Version: 6.4.8 VULNERABLE
Theme: mf (used by 344 domains)
Last Checked: 2026-07-22 02:03:29
HTTPS: Yes
Plugins (15)
| Plugin | Used By |
|---|---|
| 3d-flipbook-dflip-lite | 43,971 |
| blog-designer-pack | 5,899 |
| clickcease-click-fraud-protection | 2,308 |
| cookie-law-info | 229,708 |
| counter-number-showcase | 2,756 |
| dk-pricr-responsive-pricing-table | 3,086 |
| essential-grid | 35,085 |
| gtranslate | 125,694 |
| js_composer | 421,957 |
| litespeed-cache | 143,612 |
| loftloader-pro | 1,666 |
| masterslider | 14,774 |
| mpc-massive | 3,459 |
| service-box | 559 |
| wp-marvelous-hover | 116 |
Security Headers
F
Grade F
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.4.8) — CVE-2024-4439: Unauthenticated Stored XSS. Update to 6.5.2 or later immediately.
- Directory listing exposed — /wp-content/ is publicly browsable ?
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.