Site Information
WordPress Version: 4.9.29 ⚠️ VULNERABLE
Theme: catch-base (used by 391 domains)
Last Checked: 2026-06-13 11:40:54
HTTPS: ✅ Yes
Plugins (19)
| Plugin | Used By |
|---|---|
| add-to-any | 76,566 |
| advanced-random-posts-widget | 1,329 |
| captcha | 9,307 |
| codelights-shortcodes-and-widgets | 804 |
| contact-coldform | 68 |
| livemesh-siteorigin-widgets | 3,857 |
| media-player-style-kit | 143 |
| nktagcloud | 28 |
| print-post-and-page | 301 |
| relevant | 262 |
| responsive-lightbox | 35,035 |
| siteorigin-panels | 59,987 |
| the-events-calendar | 133,432 |
| uk-cookie-consent | 2,835 |
| widgets-for-siteorigin | 1,828 |
| wp-floating-menu | 1,007 |
| wp-pgp-encrypted-emails | 0 |
| wp-statistics | 56,343 |
| wp-typography | 4,756 |
Security Headers
F
Grade F
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (4.9.29) — CVE-2024-4439: Unauthenticated Stored XSS. Update to 6.5.2 or later immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.