Site Information
WordPress Version: 7.0.1 VULNERABLE
Theme: hello-elementor (used by 612,173 domains)
Last Checked: 2026-07-15 00:55:26
HTTPS: Yes
Plugins (24)
| Plugin | Used By |
|---|---|
| bookly-addon-customer-cabinet | 221 |
| bookly-addon-packages | 81 |
| bookly-addon-pro | 3,455 |
| bookly-responsive-appointment-booking-tool | 6,850 |
| connect-polylang-elementor | 14,374 |
| elementor | 1,737,471 |
| elementor-pro | 1,034,575 |
| frontend-reset-password | 2,283 |
| jet-blocks | 22,855 |
| jet-elements | 63,754 |
| jet-engine | 76,691 |
| jet-tabs | 32,506 |
| jet-tricks | 21,755 |
| jet-woo-builder | 11,684 |
| make-column-clickable-elementor | 11,199 |
| newsletter | 46,170 |
| page-scroll-to-id | 28,296 |
| ultimate-blocks | 10,596 |
| unlimited-elementor-inner-sections-by-taspristudio | 421 |
| woocommerce | 802,542 |
| woocommerce-currency-switcher | 5,276 |
| woocommerce-gateway-stripe | 67,985 |
| woocommerce-side-cart-premium | 2,548 |
| wp-rocket | 329,440 |
Security Headers
D
Grade D
3 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (7.0.1) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 7.0.2 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.