Site Information
WordPress Version: 4.9.26 ⚠️ VULNERABLE
Theme: zerif-lite (used by 3,415 domains)
Last Checked: 2026-07-20 21:07:20
HTTPS: ✅ Yes
Plugins (12)
| Plugin | Used By |
|---|---|
| anchor-smooth-scroll | 69 |
| bbspoiler | 918 |
| carousel-horizontal-posts-content-slider | 462 |
| custom-form | 9 |
| fancybox-for-wordpress | 7,279 |
| flowpaper-lite-pdf-flipbook | 4,397 |
| leyka | 259 |
| news-manager | 144 |
| pirate-forms | 4,755 |
| smart-slider-3 | 76,989 |
| themeisle-companion | 10,692 |
| widget-options | 28,829 |
Security Headers
F
Grade F
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (4.9.26) — CVE-2024-4439: Unauthenticated Stored XSS. Update to 6.5.2 or later immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.