Domain Information
WordPress Version: 6.9 VULNERABLE
Theme: hello-elementor (used by 604,726 domains)
Last Checked: 2026-09-08 07:28:34
HTTPS: Yes
Server: Apache
Response time (TTFB): 1,894 ms slow
Hosting: IONOS SE (AS8560)
IP address: 74.208.236.xxx
PHP version: 8.1.34 — end-of-life, no security updates
Plugins (17)
| Plugin | Used By |
|---|---|
| ajax-search-for-woocommerce | 20,795 |
| cart-for-woocommerce | 3,432 |
| contact-form-7 | 1,711,818 |
| customer-reviews-woocommerce | 11,381 |
| elementor | 1,713,799 |
| elementor-pro | 1,021,839 |
| elementskit-lite | 172,072 |
| funnel-builder | 2,801 |
| jet-woo-product-gallery | 7,232 |
| premium-addons-for-elementor | 79,662 |
| qi-addons-for-elementor | 29,069 |
| royal-elementor-addons | 53,215 |
| skyboot-custom-icons-for-elementor | 14,412 |
| woo-smart-wishlist | 7,220 |
| woo-variation-swatches | 30,895 |
| woocommerce | 791,879 |
| woocommerce-gateway-stripe | 60,700 |
Security Headers
6 missing headers
Missing headers:
- Strict-Transport-Security (HSTS) — Forces HTTPS connections ?
- Content-Security-Policy (CSP) — Prevents XSS attacks ?
- X-Content-Type-Options — Prevents MIME sniffing ?
- X-Frame-Options — Prevents clickjacking ?
- Referrer-Policy — Controls referrer information ?
- Permissions-Policy — Limits browser features ?
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.
Other WordPress domains on this IP (25+)
These WordPress domains are served from the same IP (74.208.236.xxx) — usually shared hosting or the same operator. Domains are obfuscated uniformly.
- a*n*s*a*p*i*h*r*s.com
- d*n*e*-*r*u*.com
- d*r*f*l*.com
- d*t*b*s*c*.com
- d*v*d*i*l*a*s*o*s.com
- d*v*l*z.com
- d*z*g*m*n*.com
- d*e*v*.info
- h*r*o*t*r*.com
- i*a*m.bg
- k*l*e*t*.com
- k*r*h*n*i*u*s.com
- k*y*m*q.com
- m*y*d*.com
- n*w*n*o*t*n*i*g.com
- r*e*s*o*t*d*.com
- r*t*r*d*g*o*x.com
- r*t*o*o*n*c*i*n*a*d.com
- r*i*o*r*s*o*.com
- r*c*b*s*r*d*n*e*.com
- s*l*c*i*.com
- s*l*d*r*u*d*r*j*c*.com
- t*i*t*b*n*i*l*.com
- t*o*i*a*-*e*d*n*p*a*n*r.com
- t*u*t*i*l*.com