Domain Information
WordPress Version: 6.3.10 VULNERABLE
Theme: cressida 1.2· 100% conf. (theme used by 20 domains)
Last Checked: 2026-09-10 13:06:12
HTTPS: Yes
Server: Apache
Response time (TTFB): 1,574 ms slow
Hosting: IONOS SE (AS8560)
IP address: 74.208.236.xxx
Plugins (14)
| Plugin | Version | Used By |
|---|---|---|
| 1and1-wordpress-assistant | 5.0.0· 60% conf. | 5,669 |
| a3-lazy-load | 2.7.3· 85% conf. | 21,946 |
| amazon-product-in-a-post-plugin | — | 233 |
| burst-statistics | 1.7.3· 85% conf. | 39,544 |
| complianz-gdpr | — | 247,894 |
| contact-form-7 | 5.9.7· 85% conf. | 1,694,402 |
| elementor-pro | 1.2.1· 60% conf. | 1,005,817 |
| feeds-for-youtube | 2.3· 60% conf. | 11,283 |
| floating-social-media-icon | — | 1,626 |
| google-analytics-dashboard-for-wp | 10.2.0· 60% conf. | 24,739 |
| pinterest-pin-it-button-on-image-hover-and-post | — | 5,471 |
| recent-posts-widget-with-thumbnails | 7.1.1· 60% conf. | 24,468 |
| simple-social-icons | 3.0.2· 60% conf. | 34,382 |
| social-images-widget | — | 108 |
Security Headers
6 missing headers
Missing headers:
- Strict-Transport-Security (HSTS) — Forces HTTPS connections ?
- Content-Security-Policy (CSP) — Prevents XSS attacks ?
- X-Content-Type-Options — Prevents MIME sniffing ?
- X-Frame-Options — Prevents clickjacking ?
- Referrer-Policy — Controls referrer information ?
- Permissions-Policy — Limits browser features ?
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.3.10) — outdated core with known vulnerabilities. Update to the latest release immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.
Other WordPress domains on this IP (25+)
These WordPress domains are served from the same IP (74.208.236.xxx) — usually shared hosting or the same operator. Domains are obfuscated uniformly.
- a*i*a*r*s*u*t*.com
- a*t*o*y*y*r*.com
- b*y*a*a*i.com
- b*g*a*d*c*p*n*l*c.com
- b*o*d*c*n*u*t*n*.com
- c*n*u*t*r*a*n*p.c*m.mx
- d*g*g*o*t*m*s.com
- e*r*n*h*e*.com
- e*p*s*s*.com
- f*n*y*a*t*.com
- f*r*m*d*l*.com
- f*a*i*r*o*o*r*p*y.com
- h*s*f*t*f*r*t.com
- h*a*e*e*i*n.com
- h*a*g*i*o*.com
- k*n*a*o*a*h.com
- k*n*b*a.com
- k*h*e*h*r*.com
- k*y*a*t*e*l*a*u*.com
- k*n*r*d*a*d*r*u*t.com
- k*n*o*k*d*.com
- k*b*m*s*e*l.com
- k*o*t*r*.com
- l*n*a*e*s*n.com
- m*t*r*i*a*.org