Site Information
WordPress Version: 6.9.1 VULNERABLE
Theme: astra (used by 413,038 domains)
Last Checked: 2026-08-15 22:24:04
HTTPS: Yes
Plugins (23)
| Plugin | Used By |
|---|---|
| ajax-login-and-registration-modal-popup-pro | 655 |
| astra-addon | 93,429 |
| betterlinks | 3,537 |
| duracelltomi-google-tag-manager | 90,223 |
| elementor | 1,766,015 |
| elementor-pro | 1,050,428 |
| formidable | 73,354 |
| jet-blocks | 23,336 |
| jet-menu | 28,848 |
| pixelyoursite-pro | 10,283 |
| power-course | 121 |
| powerhouse | 277 |
| revslider | 606,345 |
| solid_affiliate | 691 |
| woo-bought-together-premium | 952 |
| woo-discount-rules | 17,560 |
| woo-discount-rules-pro | 8,512 |
| woo-variation-swatches | 31,923 |
| woocommerce | 815,055 |
| woomp | 668 |
| wp-quiz-pro | 411 |
| wp-rocket | 340,803 |
| wp-social-reviews | 4,214 |
Security Headers
F
Grade F
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9.1) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.