Domain Information
WordPress Version: 5.2.21 VULNERABLE
Theme: kontrast 1.0.6· 100% conf. (theme used by 98 domains)
Last Checked: 2026-09-10 14:20:08
HTTPS: Yes
Server: Apache
Response time (TTFB): 3,051 ms slow
Hosting: Nocix, LLC (AS33387)
IP address: 198.204.247.xxx
PHP version: 7.2.34 — end-of-life, no security updates
Plugins (14)
| Plugin | Version | Used By |
|---|---|---|
| advanced-page-visit-counter | 4.3.0· 85% conf. | 682 |
| alx-extensions | 1.0.1· 60% conf. | 45 |
| business-directory-plugin | 5.9.1· 85% conf. | 881 |
| contact-list | 2.9.26· 85% conf. | 203 |
| directorist | 6.5.7· 85% conf. | 2,516 |
| easy-custom-auto-excerpt | 2.4.10· 85% conf. | 1,789 |
| fully-background-manager | — | 1,336 |
| mappress-google-maps-for-wordpress | 2.53.1· 60% conf. | 8,482 |
| master-slider | 3.5.3· 60% conf. | 12,461 |
| photo-gallery | 1.5.4· 85% conf. | 33,856 |
| responsive-lightbox | 2.2.3· 85% conf. | 32,886 |
| ultimate-post-list | 5.1.2· 85% conf. | 512 |
| ultimate-social-media-icons | — | 25,269 |
| wcp-openweather | — | 133 |
Security Headers
6 missing headers
Missing headers:
- Strict-Transport-Security (HSTS) — Forces HTTPS connections ?
- Content-Security-Policy (CSP) — Prevents XSS attacks ?
- X-Content-Type-Options — Prevents MIME sniffing ?
- X-Frame-Options — Prevents clickjacking ?
- Referrer-Policy — Controls referrer information ?
- Permissions-Policy — Limits browser features ?
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (5.2.21) — outdated core with known vulnerabilities. Update to the latest release immediately.
Need help securing your WordPress infrastructure? Contact us for a professional security audit.