WordPress maintenance or security needs? Reach out!
TLDWP

Domain Security Report for p*p*c*m*r*u*.cm

Domain Information

WordPress Version: 5.6.19 VULNERABLE

Theme: betheme 21.7.2· 100% conf. (theme used by 50,964 domains)

Last Checked: 2026-09-08 22:33:35

HTTPS: Yes

Server: Apache

Response time (TTFB): 1,821 ms slow

Hosting: Telehouse EAD (AS57344)

IP address: 78.142.63.xxx

PHP version: 7.4.33 — end-of-life, no security updates

Plugins (13)

Plugin Version Used By
album-and-image-gallery-plus-lightbox 2.1.8.1· 85% conf. 1,269
contact-form-7 5.4· 85% conf. 1,707,342
download-manager 3.1.15· 60% conf. 20,265
gtranslate 119,614
js_composer 6.4.2· 85% conf. 404,320
layerslider 6.11.2· 85% conf. 85,734
newsletter 7.0.3· 60% conf. 45,478
post-slider-and-carousel 2.0.5· 85% conf. 2,615
revslider 6.2.23· 85% conf. 586,216
videogallery-plus-player-pro 1.2.1· 85% conf. 124
wp-events-manager 2.1.8· 60% conf. 1,700
wp-responsive-recent-post-slider 3.7.1· 60% conf. 3,427
wpdm-button-templates 551

Security Headers

F
Grade F

5 missing headers

Missing headers:

  • Content-Security-Policy (CSP) — Prevents XSS attacks ?
  • X-Content-Type-Options — Prevents MIME sniffing ?
  • X-Frame-Options — Prevents clickjacking ?
  • Referrer-Policy — Controls referrer information ?
  • Permissions-Policy — Limits browser features ?

Exposed Files & Configurations

This domain has publicly accessible security-sensitive files or configurations:

  • Vulnerable WordPress Version (5.6.19) — outdated core with known vulnerabilities. Update to the latest release immediately.
  • User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?

Need help securing your WordPress infrastructure? Contact us for a professional security audit.