WordPress maintenance or security needs? Reach out!
TLDWP

Domain Security Report for c*i*a.c*m.mx

Domain Information

WordPress Version: 6.9.4 VULNERABLE

Theme: astra (theme used by 394,051 domains)

Last Checked: 2026-09-02 02:39:01

HTTPS: Yes

Plugins (18)

Plugin Version Used By
apppresser 227
astra-addon 89,810
astra-pro-sites 18,295
contact-form-7 1,698,348
download-monitor 20,061
elementor 1,695,155
elementor-pro 1,009,656
newsletter 44,987
pixelyoursite 69,662
sfwd-lms 13,257
the-events-calendar 117,844
the-events-calendar-templates-and-shortcode 348
uncanny-learndash-toolkit 3,743
uncanny-toolkit-pro 1,494
woocommerce 783,975
woocommerce-memberships 7,273
woocommerce-paypal-payments 33,766
woocommercecfdi33_3 22

Security Headers

B
Grade B

1 missing header

Missing headers:

  • Content-Security-Policy (CSP) — Prevents XSS attacks ?

Exposed Files & Configurations

This domain has publicly accessible security-sensitive files or configurations:

  • Vulnerable WordPress Version (6.9.4) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
  • User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?

Need help securing your WordPress infrastructure? Contact us for a professional security audit.