Domain Information
WordPress Version: 6.8.3 VULNERABLE
Theme: xstore 9.7.7· 100% conf. (theme used by 3,656 domains)
Last Checked: 2026-09-10 12:25:38
HTTPS: Yes
Server: nginx
Response time (TTFB): 607 ms
Hosting: Oracle Corporation (AS31898)
IP address: 162.241.218.xxx
Plugins (12)
| Plugin | Version | Used By |
|---|---|---|
| bluehost-wordpress-plugin | 4.6.3· 60% conf. | 186,490 |
| contact-form-7 | 6.1.2· 85% conf. | 1,694,402 |
| et-core-plugin | 1.0· 60% conf. | 3,009 |
| js_composer | 8.0.1· 85% conf. | 400,654 |
| mpc-massive | 2.4.8· 85% conf. | 3,294 |
| revslider | 6.7.18· 85% conf. | 580,456 |
| top-bar | — | 4,284 |
| woocommerce | 10.2.2· 85% conf. | 781,569 |
| woocommerce-gateway-paypal-express-checkout | 2.1.3· 85% conf. | 7,948 |
| woocommerce-gift-cards | 1.16.14· 85% conf. | 2,735 |
| woocommerce-paypal-payments | 3.1.2· 85% conf. | 33,200 |
| wordpress-popup | 7.8.7· 85% conf. | 7,033 |
Security Headers
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.8.3) — unauthenticated SQL injection (CVE-2026-60137). Update to 6.8.6 immediately.
Need help securing your WordPress infrastructure? Contact us for a professional security audit.
Other WordPress domains on this IP (25+)
These WordPress domains are served from the same IP (162.241.218.xxx) — usually shared hosting or the same operator. Domains are obfuscated uniformly.
- a*n*c*a*r*v*l*e*s.com
- a*t*p*d*a*e*g*n*e*.com
- b*r*s*r*m*k*g*.net
- b*a*d*s*a*t.com
- b*i*g*p*s.com
- c*i*e*r*o*.ai
- d*n*e*f*r*e*t*o*f*a*.com
- d*r*l*h*n*.com
- d*v*h*c*.com
- d*v*d*m*k*l*o*.com
- d*e*b*u*s*p*h*r*.com
- e*m*o*o*a.com
- e*t*e*r*n*u*r*c*e*f*e*.com
- e*i*o*n*e.com
- e*c*l*e*t*h*u*h*.net
- f*i*h*o*e*n*m*n*y.com
- h*l*n*l*z*b*t*.com
- k*r*e*p.com
- k*t*e*e*n*e*h*t*g*a*h*.com
- k*i*h*r*s*i*k*t*d*o*.com
- k*a*k*n*l*s.com
- k*m*o*e*l*.com
- k*m*b*r*.com
- m*x*e*l*a*d*o*e*v*c*.com
- m*d*t*t*o*i*e*u*a*i*n.com