Site Information
WordPress Version: 6.1.1 VULNERABLE
Theme: twentyeleven (used by 10,191 domains)
Last Checked: 2026-07-24 14:35:31
HTTPS: Yes
Plugins (13)
| Plugin | Used By |
|---|---|
| add-to-any | 71,950 |
| bbpress | 13,777 |
| cardoza-facebook-like-box | 1,287 |
| document-gallery | 2,222 |
| events-manager | 16,944 |
| events-manager-pro | 2,234 |
| paid-member-subscriptions | 2,341 |
| q2w3-fixed-widget | 17,242 |
| sidebar-login | 1,451 |
| simple-pdf-viewer | 684 |
| twenty-eleven-theme-extensions | 507 |
| wp-fullcalendar | 1,912 |
| wysija-newsletters | 7,818 |
Security Headers
D
Grade D
4 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.1.1) — CVE-2024-4439: Unauthenticated Stored XSS. Update to 6.5.2 or later immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.