Site Information
WordPress Version: 6.8.1 VULNERABLE
Theme: nanosoft (used by 397 domains)
Last Checked: 2026-07-12 03:05:41
HTTPS: Yes
Plugins (27)
| Plugin | Used By |
|---|---|
| animated-headline | 389 |
| contact-form-7 | 1,744,253 |
| devvn-image-hotspot | 5,104 |
| dynamic-visibility-for-elementor | 8,389 |
| easy-fancybox | 45,743 |
| elementor | 1,763,082 |
| elementor-pro | 1,048,791 |
| give | 17,656 |
| global-gallery | 945 |
| google-analytics-premium | 14,383 |
| go_pricing | 5,906 |
| happy-elementor-addons | 49,433 |
| if-menu | 9,786 |
| indeed-affiliate-pro | 914 |
| indeed-membership-pro | 1,912 |
| js_composer | 417,107 |
| line-shortcodes | 820 |
| mailchimp-for-wp | 80,960 |
| mega_main_menu | 3,005 |
| neon-text | 33 |
| page-scroll-to-id | 28,732 |
| q2w3-fixed-widget | 17,105 |
| revslider | 605,237 |
| stachethemes_event_calendar | 341 |
| team-press | 458 |
| ultimate-elementor | 70,543 |
| wp-video-lightbox | 10,105 |
Security Headers
B
Grade B
1 missing header
Missing headers:
- Content-Security-Policy (CSP) — Prevents XSS attacks ?
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.8.1) — unauthenticated SQL injection (CVE-2026-60137). Update to 6.8.6 immediately.
Need help securing your WordPress site? Contact us for a professional security audit.