Domain Information
WordPress Version: 6.8.2 VULNERABLE
Theme: guardteam 1.2.1· 100% conf. (theme used by 12 domains)
Last Checked: 2026-09-10 01:38:13
HTTPS: Yes
Server: Apache
Response time (TTFB): 839 ms
Hosting: velia.net Internetdienste GmbH (AS29066)
IP address: 85.93.89.xxx
Plugins (15)
| Plugin | Version | Used By |
|---|---|---|
| contact-form-7 | 6.1.7· 85% conf. | 1,694,402 |
| dflip | 1.7.6.2· 85% conf. | 4,905 |
| foobox-image-lightbox | 2.8.4· 85% conf. | 23,708 |
| foogallery | 3.2.6· 85% conf. | 5,789 |
| formcraft3 | — | 5,505 |
| interactive-3d-flipbook-powered-physics-engine | 1.16.21· 60% conf. | 16,458 |
| js_composer | 6.8.0· 85% conf. | 400,654 |
| mega-addons-for-visual-composer | — | 5,625 |
| my-calendar | 3.8.1· 85% conf. | 5,598 |
| pixtheme-custom | — | 81 |
| post-carousel | 4.0.7· 85% conf. | 3,679 |
| revslider | 6.5.12· 85% conf. | 580,456 |
| ro-map | 1.0· 60% conf. | 0 |
| smart-slider-3 | — | 72,974 |
| the-events-calendar-templates-and-shortcode | 2.9.2· 60% conf. | 348 |
Security Headers
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.8.2) — unauthenticated SQL injection (CVE-2026-60137). Update to 6.8.6 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.