Domain Information
WordPress Version: 6.9 VULNERABLE
Theme: blossom-spa (theme used by 779 domains)
Last Checked: 2026-09-07 11:37:24
HTTPS: Yes
Server: Apache
Response time (TTFB): 253 ms fast
Hosting: SuperHosting.BG Ltd. (AS201200)
IP address: 185.45.66.xxx
Plugins (8)
| Plugin | Version | Used By |
|---|---|---|
| blossomthemes-email-newsletter | — | 3,038 |
| blossomthemes-instagram-feed | — | 2,460 |
| blossomthemes-toolkit | — | 5,053 |
| complianz-gdpr | — | 250,139 |
| exit-notifier | — | 604 |
| html5-cumulus | — | 515 |
| page-links-to | — | 56,521 |
| theme-junkie-shortcodes | — | 293 |
Security Headers
6 missing headers
Missing headers:
- Strict-Transport-Security (HSTS) — Forces HTTPS connections ?
- Content-Security-Policy (CSP) — Prevents XSS attacks ?
- X-Content-Type-Options — Prevents MIME sniffing ?
- X-Frame-Options — Prevents clickjacking ?
- Referrer-Policy — Controls referrer information ?
- Permissions-Policy — Limits browser features ?
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
Need help securing your WordPress infrastructure? Contact us for a professional security audit.
Other WordPress domains on this IP (19)
These WordPress domains are served from the same IP (185.45.66.xxx) — usually shared hosting or the same operator. Domains are obfuscated uniformly.
- a*d*t*x*.com
- a*i*e*b*.com
- a*i*t*l*s*r.com
- b*t*.bg
- d*m*a*a*d*l*h*v*.com
- d*s*r*d.com
- d*o*g*-*o*i*t*o*.com
- d*e*m*h*m*.bg
- e*e*t*t*t*o*-*g.com
- e*o*i*e.bg
- h*x*r*i*e*t*r.com
- k*n*l*p*i*a.com
- m*a*-*s*n*v*r*d.com
- m*d*k*p*r*u*.com
- m*d*i*u*e*i*i.com
- r*n*m*t*o*a.com
- s*f*a*r*s*g*l*e*y.com
- s*m*r*m*r.com
- t*v*t*m*r*s*l*v.com