Site Information
WordPress Version: 4.9.29 VULNERABLE
Theme: catch-base (used by 396 domains)
Last Checked: 2026-06-13 11:40:54
HTTPS: Yes
Plugins (19)
| Plugin | Used By |
|---|---|
| add-to-any | 71,950 |
| advanced-random-posts-widget | 1,385 |
| captcha | 9,297 |
| codelights-shortcodes-and-widgets | 787 |
| contact-coldform | 67 |
| livemesh-siteorigin-widgets | 3,760 |
| media-player-style-kit | 133 |
| nktagcloud | 30 |
| print-post-and-page | 277 |
| relevant | 241 |
| responsive-lightbox | 33,846 |
| siteorigin-panels | 57,177 |
| the-events-calendar | 122,873 |
| uk-cookie-consent | 2,633 |
| widgets-for-siteorigin | 1,837 |
| wp-floating-menu | 895 |
| wp-pgp-encrypted-emails | 0 |
| wp-statistics | 56,297 |
| wp-typography | 4,108 |
Security Headers
F
Grade F
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (4.9.29) — CVE-2024-4439: Unauthenticated Stored XSS. Update to 6.5.2 or later immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.