Site Information
WordPress Version: 6.4.5 ⚠️ VULNERABLE
Theme: twentytwelve (used by 12,666 domains)
Last Checked: 2026-06-14 12:17:28
HTTPS: ✅ Yes
Plugins (15)
| Plugin | Used By |
|---|---|
| cm-answers | 79 |
| contact-form-7 | 1,814,342 |
| content-views-query-and-display-post-page | 28,044 |
| elementor | 1,844,968 |
| event-calendar-wd | 1,664 |
| gallery-plugin | 1,902 |
| header-footer-elementor | 214,726 |
| ml-slider | 83,224 |
| smart-logo-showcase-lite | 1,443 |
| social-icons | 2,357 |
| tabs-responsive | 3,895 |
| types | 3,793 |
| wp-faq-by-wpdonehere | 5 |
| wp-pagenavi | 81,136 |
| wp-social-widget | 913 |
Security Headers
F
Grade F
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.4.5) — CVE-2024-4439: Unauthenticated Stored XSS. Update to 6.5.2 or later immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.