Site Information
WordPress Version: 6.0.12 VULNERABLE
Theme: astra (used by 415,793 domains)
Last Checked: 2026-07-26 17:21:46
HTTPS: Yes
Plugins (20)
| Plugin | Used By |
|---|---|
| all-in-one-seo-pack | 89,405 |
| business-reviews-bundle | 12,923 |
| cleantalk-spam-protect | 82,958 |
| custom-facebook-feed | 41,710 |
| custom-twitter-feeds | 32,579 |
| dynamicconditions | 18,362 |
| elementor | 1,775,447 |
| elementor-pro | 1,054,368 |
| essential-addons-for-elementor-lite | 265,853 |
| feeds-for-youtube | 11,995 |
| ht-mega-for-elementor | 9,700 |
| instagram-feed | 225,606 |
| lightweight-grid-columns | 3,497 |
| mystickymenu-pro | 1,138 |
| pixelyoursite | 73,622 |
| reviews-feed | 20,394 |
| stratum | 3,537 |
| toolset-blocks | 4,925 |
| widget-google-reviews | 36,029 |
| wp-google-map-plugin | 10,036 |
Security Headers
F
Grade F
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.0.12) — CVE-2024-4439: Unauthenticated Stored XSS. Update to 6.5.2 or later immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.