Domain Information
WordPress Version: 6.1.12 VULNERABLE
Theme: startos (used by 19 domains)
Last Checked: 2026-09-07 00:49:32
HTTPS: Yes
Server: HOSTVN.NET
Response time (TTFB): 1,511 ms slow
Hosting: The Constant Company, LLC (AS20473)
IP address: 66.42.59.xxx
Plugins (10)
| Plugin | Used By |
|---|---|
| all-in-one-contact-buttons-wpshare247 | 372 |
| contact-form-7 | 1,717,556 |
| content-views-query-and-display-post-page | 27,067 |
| foobox-image-lightbox | 24,041 |
| js_composer | 407,161 |
| pushalert-web-push-notifications | 75 |
| sticky-side-buttons | 2,835 |
| ultimate_vc_addons | 53,822 |
| woocommerce | 795,651 |
| woocustomizer | 2,885 |
Security Headers
3 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.1.12) — outdated core with known vulnerabilities. Update to the latest release immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.