Domain Information
WordPress Version: 7.0 VULNERABLE
Theme: astra (used by 396,526 domains)
Last Checked: 2026-07-26 20:18:24
HTTPS: Yes
Plugins (28)
| Plugin | Used By |
|---|---|
| advanced-backgrounds | 7,497 |
| astra-addon | 90,405 |
| bridge-for-woocommerce | 719 |
| contact-form-7 | 1,707,342 |
| counters-block | 680 |
| couponwheel | 119 |
| elementor | 1,707,286 |
| elementor-pro | 1,017,560 |
| essential-blocks | 22,804 |
| facebook-for-woocommerce | 25,920 |
| fooevents | 1,648 |
| fooevents-calendar | 799 |
| fooevents_bookings | 418 |
| fooevents_seating | 274 |
| google-site-kit | 258,056 |
| if-menu | 9,492 |
| jet-elements | 62,959 |
| mailin | 44,921 |
| seating-charts | 284 |
| theme-my-login | 10,401 |
| tickera | 1,003 |
| tickera-events-listing | 241 |
| translatepress-multilingual | 65,570 |
| video-background | 2,349 |
| woo-payu-payment-gateway | 1,882 |
| woocommerce | 789,108 |
| woocommerce-ultimate-gift-card | 256 |
| wt-woocommerce-related-products | 2,836 |
Security Headers
F
Grade F
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (7.0) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 7.0.2 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.