Site Information
WordPress Version: 7.0.1 VULNERABLE
Theme: corpiva (used by 435 domains)
Last Checked: 2026-08-01 16:08:34
HTTPS: Yes
Plugins (23)
| Plugin | Used By |
|---|---|
| contact-form-7 | 1,717,556 |
| countdown-timer-for-elementor | 591 |
| custom-twitter-feeds | 31,498 |
| desert-companion | 1,013 |
| ele-blog | 187 |
| elementor | 1,722,365 |
| embedpress | 18,369 |
| epoll-wp-voting | 259 |
| everest-forms | 12,045 |
| formidable | 72,104 |
| gp-hub-driver-widget | 0 |
| js_composer | 407,161 |
| message-ticker | 109 |
| post-carousel-slider-for-elementor | 662 |
| rallix | 0 |
| revslider | 590,856 |
| sassy-social-share | 26,993 |
| simple-share-buttons-adder | 9,203 |
| sportspress | 1,820 |
| ultimate-post-list | 522 |
| user-submitted-posts | 3,091 |
| wpforms-lite | 117,774 |
| youtube-embed-plus | 36,255 |
Security Headers
C
Grade C
2 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (7.0.1) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 7.0.2 immediately.
- Directory listing exposed — /test/ is publicly browsable ?
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.