Domain Information
WordPress Version: 6.9 VULNERABLE
Theme: affinger 1.5.9· 60% conf. (theme used by 4,425 domains)
Last Checked: 2026-09-12 01:00:47
HTTPS: Yes
Server: nginx
Response time (TTFB): 1,590 ms slow
Hosting: GMO Internet, Inc. (AS58791)
IP address: 160.251.148.xxx
Plugins (11)
| Plugin | Version | Used By |
|---|---|---|
| contact-form-7 | 6.1.7· 85% conf. | 1,685,958 |
| ewww-image-optimizer | — | 75,377 |
| google-analytics-for-wordpress | 11.2.0· 60% conf. | 192,894 |
| google-site-kit | — | 259,669 |
| quick-adsense-reloaded | 3.0.5· 85% conf. | 4,144 |
| st-affiliate-manager | — | 557 |
| st-blocks | — | 1,254 |
| st-kaiwa | 2.3.2· 60% conf. | 129 |
| st-pv-monitor | 2.2.2· 60% conf. | 356 |
| wordpress-popular-posts | 7.3.8· 85% conf. | 34,310 |
| wp-associate-post-r2 | 5.0.1· 60% conf. | 507 |
Security Headers
4 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.
Other WordPress domains on this IP (25+)
These WordPress domains are served from the same IP (160.251.148.xxx) — usually shared hosting or the same operator. Domains are obfuscated uniformly.
- a*t*n*a*c*t.com
- a*l*f*b*o*.com
- a*u*-*e*b*r.com
- a*a*a*a*o*i.com
- b*1*0*a*b*o*.com
- e*g*g*k*s*u*u*h*.com
- e*r*w*r*s.com
- f*n*a*a*-*g*t*d*.com
- g*e*n*o*e*t.jp
- h*r*h*r*0*0*.com
- h*k*n*b*o*.com
- k*i*e*i*e*.com
- k*n*o*k*i*a*.com
- k*n*j*j*.com
- k*k*n*-*l*g.com
- k*n*o*k*n*e*.com
- k*r*y*o*d*i*f*.com
- k*t*b*g*n*e*.com
- k*y*l*g.com
- k*d*n*-*i*n*-*c*o*l.com
- k*h*r*l*f*.com
- k*m*k*m*l*f*.com
- k*m*r*g*t*.com
- k*u*a*o*5.com
- m*y*h*l*g.com