Site Information
WordPress Version: 5.6.17 ⚠️ VULNERABLE
Theme: astra (used by 431,325 domains)
Last Checked: 2026-06-12 19:58:44
HTTPS: ✅ Yes
Plugins (9)
| Plugin | Used By |
|---|---|
| astra-widgets | 4,372 |
| easy-pull-quotes | 63 |
| heroic-blocks | 469 |
| heroic-glossary | 179 |
| heroic-table-of-contents | 1,261 |
| ht-knowledge-base | 938 |
| mailchimp-for-wp | 85,185 |
| mc4wp-premium | 2,066 |
| wp-bigfoot | 73 |
Security Headers
F
Grade F
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (5.6.17) — CVE-2024-4439: Unauthenticated Stored XSS. Update to 6.5.2 or later immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.