Site Information
WordPress Version: 7.0.1 VULNERABLE
Theme: proficient (used by 96 domains)
Last Checked: 2026-07-17 16:31:11
HTTPS: Yes
Plugins (28)
| Plugin | Used By |
|---|---|
| add-to-any | 70,555 |
| bbspoiler | 926 |
| comfortable-reading | 180 |
| contact-form-7 | 1,726,397 |
| contact-form-7-honeypot | 44,344 |
| contact-form-7-signature-addon | 1,380 |
| cross-device-social-share | 62 |
| data-tables-generator-by-supsystic | 3,684 |
| easy-pricing-tables | 1,815 |
| for-the-visually-impaired | 481 |
| fully-background-manager | 1,370 |
| material-design-for-contact-form-7 | 1,546 |
| miniorange-otp-verification | 556 |
| mp3-audio-player | 48 |
| panopress | 552 |
| pirate-forms | 4,614 |
| q2w3-fixed-widget | 16,676 |
| real3d-flipbook | 2,661 |
| ru_kluhtmlmap | 0 |
| sk_igallery | 11 |
| supercarousel | 398 |
| tablepress | 101,547 |
| templatesnext-toolkit | 1,256 |
| the-events-calendar | 120,894 |
| ulogin | 39 |
| wp-miniaudioplayer | 1,071 |
| wp-recall | 332 |
| wp-smart-editor | 135 |
Security Headers
F
Grade F
6 missing headers
Missing headers:
- Strict-Transport-Security (HSTS) — Forces HTTPS connections ?
- Content-Security-Policy (CSP) — Prevents XSS attacks ?
- X-Content-Type-Options — Prevents MIME sniffing ?
- X-Frame-Options — Prevents clickjacking ?
- Referrer-Policy — Controls referrer information ?
- Permissions-Policy — Limits browser features ?
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (7.0.1) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 7.0.2 immediately.
Need help securing your WordPress site? Contact us for a professional security audit.