Site Information
WordPress Version: 6.9.1 VULNERABLE
Theme: astra (used by 400,837 domains)
Last Checked: 2026-09-06 04:04:37
HTTPS: Yes
Server: Apache
Response time (TTFB): 631 ms
Hosting: IONOS SE (AS8560)
IP address: 217.160.0.149
PHP version: 8.5.10
Other WordPress sites on this IP (10)
These WordPress sites are served from the same IP (217.160.0.149) — usually shared hosting or the same owner. Domains are obfuscated, as everywhere on the site.
- a*a*n*n*z*h*t*.com
- b*o*t*y*u*-*r*w*h.com
- e*e*a*u*i*r*.com
- e*e*t*u*b*x.com
- h*m*r*.com
- l*b*r*c*m*d*a.fr
- m*e*c*f*d*s*g*.it
- p*e*i*h*m*n*o*i*i*e.it
- r*f*g*o*a*o*a*i*l*.com
- s*c*e*e*s*.com
Plugins (1)
| Plugin | Used By |
|---|---|
| ultimate-addons-for-gutenberg | 47,466 |
Security Headers
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9.1) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.