Site Information
WordPress Version: 6.9.1 VULNERABLE
Theme: twentytwentyfive (used by 45,525 domains)
Last Checked: 2026-08-21 19:05:31
HTTPS: Yes
Plugins (24)
| Plugin | Used By |
|---|---|
| authors-list | 1,083 |
| bbpress | 13,403 |
| bowe-codes | 9 |
| buddyboss-wall | 34 |
| buddypress | 6,305 |
| buddypress-edit-activity | 108 |
| buddypress-media | 899 |
| buddypress-upload-avatar-ajax | 0 |
| cleantalk-spam-protect | 80,414 |
| click-to-tweet-by-todaymade | 1,258 |
| contact-form-7 | 1,722,974 |
| duracelltomi-google-tag-manager | 88,558 |
| essential-grid | 33,940 |
| geodirectory | 3,801 |
| js_composer | 409,063 |
| paid-memberships-pro | 9,816 |
| rate-my-post | 6,087 |
| revslider | 592,870 |
| social-articles | 55 |
| social-warfare | 6,610 |
| theme-my-login | 10,584 |
| vc-extensions-cq | 18 |
| wp-gallery-custom-links | 5,105 |
| wysija-newsletters | 7,531 |
Security Headers
C
Grade C
2 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9.1) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
- phpinfo.php exposed — Server configuration publicly visible ?
Need help securing your WordPress site? Contact us for a professional security audit.