Site Information
WordPress Version: 6.8.1 VULNERABLE
Theme: bricks (used by 26,811 domains)
Last Checked: 2026-07-31 05:11:26
HTTPS: Yes
Plugins (25)
| Plugin | Used By |
|---|---|
| aco-woo-dynamic-pricing-pro | 100 |
| ajax-search-for-woocommerce | 20,902 |
| automaticcss-plugin | 8,873 |
| back-in-stock-and-price-alert | 17 |
| bulk-discounts-for-woocommerce | 91 |
| click-to-chat-for-whatsapp | 58,285 |
| cookie-law-info | 223,080 |
| custom-facebook-feed | 40,299 |
| customer-reviews-woocommerce | 11,458 |
| google-site-kit | 252,072 |
| iconic-woo-sales-booster | 231 |
| jet-smart-filters | 10,697 |
| klaviyo | 9,228 |
| med-rx | 0 |
| metorik-helper | 3,056 |
| mystickymenu | 16,632 |
| pixelyoursite | 71,031 |
| popup-maker | 106,734 |
| reviews-feed | 20,008 |
| revolve-report | 0 |
| super-payments | 42 |
| woo-shop-api | 0 |
| woocommerce | 797,773 |
| woocommerce-ryft-payment-gateway | 16 |
| yith-woocommerce-wishlist | 40,052 |
Security Headers
F
Grade F
6 missing headers
Missing headers:
- Strict-Transport-Security (HSTS) — Forces HTTPS connections ?
- Content-Security-Policy (CSP) — Prevents XSS attacks ?
- X-Content-Type-Options — Prevents MIME sniffing ?
- X-Frame-Options — Prevents clickjacking ?
- Referrer-Policy — Controls referrer information ?
- Permissions-Policy — Limits browser features ?
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.8.1) — unauthenticated SQL injection (CVE-2026-60137). Update to 6.8.6 immediately.
Need help securing your WordPress site? Contact us for a professional security audit.