WordPress maintenance or security needs? Reach out!
TLDWP

Domain Security Report for o*t*h*n*d.io

Domain Information

WordPress Version: 7.1

Theme: oceanwp 4.2.5· 100% conf. (theme used by 77,087 domains)

Last Checked: 2026-09-09 05:54:30

HTTPS: Yes

Server: nginx

Response time (TTFB): 1,443 ms slow

Hosting: Oracle Corporation (AS31898)

IP address: 50.6.19.xxx

Plugins (24)

Plugin Version Used By
ai-engine-pro 1,224
bluehost-wordpress-plugin 4.19.1· 60% conf. 187,823
elementor 3.33.4· 85% conf. 1,707,286
google-site-kit 258,056
jetpack 15.8.1· 60% conf. 411,832
ocean-cookie-notice 1,081
ocean-elementor-widgets 2,466
ocean-extra 53,420
ocean-footer-callout 810
ocean-gutenberg-blocks 1.1.9· 85% conf. 424
ocean-instagram 508
ocean-modal-window 2.3.2· 60% conf. 1,699
ocean-popup-login 2.2.1· 60% conf. 461
ocean-portfolio 2.3.2· 85% conf. 1,200
ocean-posts-slider 1,389
ocean-pro-demos 1.5.2· 60% conf. 32
ocean-product-sharing 2.2.3· 60% conf. 1,879
ocean-side-panel 772
ocean-social-sharing 2.2.2· 60% conf. 7,269
ocean-stick-anything 2.0.8· 85% conf. 2,401
ocean-sticky-footer 533
ocean-sticky-header 4,970
ocean-woo-popup 209
woocommerce 10.3.7· 85% conf. 789,108

Security Headers

F
Grade F

5 missing headers

Missing headers:

  • Strict-Transport-Security (HSTS) — Forces HTTPS connections ?
  • Content-Security-Policy (CSP) — Prevents XSS attacks ?
  • X-Content-Type-Options — Prevents MIME sniffing ?
  • X-Frame-Options — Prevents clickjacking ?
  • Referrer-Policy — Controls referrer information ?

Exposed Files & Configurations

This domain has publicly accessible security-sensitive files or configurations:

  • User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?

Need help securing your WordPress infrastructure? Contact us for a professional security audit.