Domain Information
WordPress Version: 6.8.2 VULNERABLE
Theme: johannes (used by 192 domains)
Last Checked: 2026-08-19 08:10:21
HTTPS: Yes
Plugins (11)
| Plugin | Used By |
|---|---|
| awsm-team-pro | 3,461 |
| content-views-query-and-display-post-page | 26,987 |
| meks-audio-player | 384 |
| meks-easy-instagram-widget | 3,414 |
| meks-easy-social-share | 2,847 |
| meks-flexible-shortcodes | 3,800 |
| meks-smart-author-widget | 3,129 |
| meks-smart-social-widget | 3,658 |
| meks-themeforest-smart-widget | 2,208 |
| metronet-profile-picture | 9,408 |
| no-right-click-images-plugin | 5,314 |
Security Headers
D
Grade D
4 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.8.2) — unauthenticated SQL injection (CVE-2026-60137). Update to 6.8.6 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.