Site Information
WordPress Version: Unknown
Theme: kava (used by 4,689 domains)
Last Checked: 2026-09-01 03:56:16
HTTPS: Yes
Plugins (27)
| Plugin | Used By |
|---|---|
| addon-gravityforms-sendinblue-free | 290 |
| advanced-product-labels-for-woocommerce | 2,517 |
| business-reviews-bundle | 12,610 |
| cleantalk-spam-protect | 80,574 |
| duracelltomi-google-tag-manager | 88,731 |
| elementor | 1,737,471 |
| elementor-pro | 1,034,575 |
| google-site-kit | 245,603 |
| gravityforms | 253,444 |
| gravityformsrecaptcha | 72,949 |
| jet-blocks | 22,855 |
| jet-blog | 15,236 |
| jet-engine | 76,691 |
| jet-menu | 28,296 |
| jet-smart-filters | 10,662 |
| jet-tricks | 21,755 |
| jet-woo-builder | 11,684 |
| jet-woo-product-gallery | 7,281 |
| jetpack | 445,014 |
| kliken-marketing-for-google | 5,125 |
| mailin | 45,356 |
| pixelyoursite | 71,501 |
| powerpack-elements | 14,962 |
| toolkit-master | 71 |
| woocommerce | 802,542 |
| woocommerce-customer-history | 111 |
| woocommerce-smart-coupons | 4,590 |
Security Headers
B
Grade B
1 missing header
Missing headers:
- Content-Security-Policy (CSP) — Prevents XSS attacks ?
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.