Domain Information
WordPress Version: 5.8.15 VULNERABLE
Theme: enerzee 1.4.1· 100% conf. (theme used by 16 domains)
Last Checked: 2026-09-09 08:31:37
HTTPS: Yes
Server: Apache
Response time (TTFB): 1,761 ms slow
Hosting: IONOS SE (AS8560)
IP address: 74.208.236.xxx
PHP version: 7.4.33 — end-of-life, no security updates
Plugins (9)
| Plugin | Version | Used By |
|---|---|---|
| a3-lazy-load | 2.4.8· 85% conf. | 22,024 |
| contact-form-7 | 5.5.2· 85% conf. | 1,698,348 |
| elementor | 3.4.8· 85% conf. | 1,695,155 |
| elementor-pro | 3.4.1· 85% conf. | 1,009,656 |
| google-analytics-dashboard-for-wp | 10.2.0· 60% conf. | 24,824 |
| pirate-forms | — | 4,557 |
| redux-framework | 11.7· 60% conf. | 12,316 |
| revslider | 6.4.6· 85% conf. | 582,336 |
| themeisle-companion | 1.0.6· 85% conf. | 10,180 |
Security Headers
6 missing headers
Missing headers:
- Strict-Transport-Security (HSTS) — Forces HTTPS connections ?
- Content-Security-Policy (CSP) — Prevents XSS attacks ?
- X-Content-Type-Options — Prevents MIME sniffing ?
- X-Frame-Options — Prevents clickjacking ?
- Referrer-Policy — Controls referrer information ?
- Permissions-Policy — Limits browser features ?
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (5.8.15) — outdated core with known vulnerabilities. Update to the latest release immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.
Other WordPress domains on this IP (25+)
These WordPress domains are served from the same IP (74.208.236.xxx) — usually shared hosting or the same operator. Domains are obfuscated uniformly.
- a*t*i*e*.co
- b*k*r*s*i*.com
- b*t*s*l*t*o*s.com
- b*i*n*c*o*e*n.com
- d*n*c*a*l*c*.com
- d*r*z*t*.com
- d*a*c*m*u*i*a*i*n*.com
- d*a*l*l*1*n*e*n*.com
- d*a*m*s*m*t*.com
- e*u*a*i*n*o*m*l*y*e*t*l*i*n*e.com
- e*g*n*e*s*n*e*l*s*a*e.com
- e*o*t*o*e.com
- e*c*l*e*c*s*r*v*l.com
- e*u*h*s*o*y.com
- f*c*o*f*c*i*n*o*c*s*.com
- g*o*p*d*r*.com
- k*i*h*c*s*o*c*r*s.com
- k*n*a*l*n*e*t*e*t*.com
- k*n*a*l*u*t*i*a*l*i*f*a*t*u*t*r*.com
- m*x*i*l*b*.com
- m*r*w*r*i*e*r*.com
- n*-*f*.com
- o*d*t*l*w*o*s.com
- o*s*n*d*e*t*r*s.com
- o*e*t*p*o*l*.com