Domain Information
WordPress Version: 6.8.3 VULNERABLE
Theme: oceanwp 4.2.5· 100% conf. (theme used by 76,442 domains)
Last Checked: 2026-09-09 10:42:18
HTTPS: Yes
Server: Apache
Response time (TTFB): 1,697 ms slow
Hosting: LiquidNet US LLC (AS14555)
IP address: 162.210.96.xxx
Plugins (11)
| Plugin | Version | Used By |
|---|---|---|
| cf7-conditional-fields | 2.6.6· 85% conf. | 32,811 |
| connect-contact-form-7-to-social-apps | — | 202 |
| contact-form-7 | 6.1.3· 85% conf. | 1,694,402 |
| elementor | 3.33.1· 85% conf. | 1,689,719 |
| elementskit-lite | 3.0.4· 85% conf. | 169,378 |
| happy-elementor-addons | 3.20.2· 85% conf. | 47,052 |
| megamenu | 3.6.2· 60% conf. | 76,897 |
| ocean-extra | — | 52,969 |
| revslider | 6.6.18· 85% conf. | 580,456 |
| woocommerce | 10.3.5· 85% conf. | 781,569 |
| wp-logo-showcase-responsive-slider-slider | 3.8.7· 85% conf. | 6,155 |
Security Headers
6 missing headers
Missing headers:
- Strict-Transport-Security (HSTS) — Forces HTTPS connections ?
- Content-Security-Policy (CSP) — Prevents XSS attacks ?
- X-Content-Type-Options — Prevents MIME sniffing ?
- X-Frame-Options — Prevents clickjacking ?
- Referrer-Policy — Controls referrer information ?
- Permissions-Policy — Limits browser features ?
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.8.3) — unauthenticated SQL injection (CVE-2026-60137). Update to 6.8.6 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.
Other WordPress domains on this IP (25+)
These WordPress domains are served from the same IP (162.210.96.xxx) — usually shared hosting or the same operator. Domains are obfuscated uniformly.
- a*g*l*i*h*a*e*.e*u.ph
- a*g*o*s*l*i*g.com
- a*g*o*p*t*l*t*.com
- a*p*r*h*b.com
- b*a*e*e*a*c*n*t*u*t*o*.com
- d*c*d*s*n*d*f*e*e*t*a*s.com
- d*d*l*s*l*h*u*e.com
- d*s*g*t*r*l*.com
- e*i*i*a*m*r*e*i*g*o*c*p*s.com
- e*t*t*c*m*r*h*v*l*z.com
- e*c*v*t*o*w*s*.com
- e*p*r*e*c*b*n*e*i*l*.com
- f*w*e*i*n*.com
- f*d*o*.com
- f*o*t*i*e*m*d*c*r*.com
- h*l*l*v*i*s*i*e.com
- k*n*o*h*m.com
- k*n*s*o*r*i*t*r*a*i*n*l*c*o*l*a*u*e.com
- l*c*o*a*a*i*n*e.e*u.gt
- m*u*.com
- n*c*l*a*s*e*.com
- o*a*a*f*r*a*r*c*v*r*.com
- o*e*n*o*t*a*t*r*l*m*t*d.com
- o*i*e*r*e*h*r*p*w*l*n*s*.com
- o*y*p*s*h*r*a.com