Domain Information
WordPress Version: 6.9.4 VULNERABLE
Theme: Avada-Child-Theme (theme used by 35,726 domains)
Last Checked: 2026-09-11 07:14:01
HTTPS: Yes
Server: nginx
Response time (TTFB): 529 ms
Hosting: Unified Layer (AS46606)
IP address: 50.87.143.xxx
Plugins (6)
| Plugin | Version | Used By |
|---|---|---|
| 3d-flipbook-dflip-lite | 2.4.27· 60% conf. | 42,340 |
| filebird | — | 13,176 |
| revslider | 6.7.27· 85% conf. | 580,456 |
| simple-youtube-responsive | 3.2.6· 60% conf. | 782 |
| the-events-calendar | 6.15.20· 60% conf. | 117,404 |
| wordpress-tooltips | — | 1,342 |
Security Headers
2 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9.4) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.
Other WordPress domains on this IP (19)
These WordPress domains are served from the same IP (50.87.143.xxx) — usually shared hosting or the same operator. Domains are obfuscated uniformly.
- a*r*n*e*c*e*e*i*e.com
- b*s*o*i*t*l*i*e*t.com
- b*m*m*a*i*l.com
- d*l*a*c*u*t*s*o*t*.com
- e*p*c*c*a*i*y*e*t*e*i*s.com
- f*i*h*u*c*t*c*i*t*.com
- k*l*e*w*l*a*.com
- k*a*l*d.com
- k*n*s*e*c*c*m*a*y.com
- o*i*e*m*x*s.com
- o*t*c*r*l*t*d.com
- o*t*m*-*s.com
- r*s*h*p*.com
- r*v*r*i*e*o*n*e*i*g*e*t*r*a*.com
- s*u*h*o*d*e*u*e*t*r*g*.com
- s*a*n*r*q.com
- v*-*n*p*r*p*e*s.com
- v*e*s*o*.com
- y*y*n*s*n.com