Domain Information
WordPress Version: 5.1.19 VULNERABLE
Theme: sweety_tcd029 (theme used by 175 domains)
Last Checked: 2026-09-08 15:12:46
HTTPS: Yes
Server: Apache
Response time (TTFB): 2,183 ms slow
Hosting: GMO Internet, Inc. (AS7506)
IP address: 157.7.107.xxx
PHP version: 7.4.33 — end-of-life, no security updates
Plugins (4)
| Plugin | Version | Used By |
|---|---|---|
| contact-form-7 | — | 1,707,342 |
| foobox-image-lightbox | — | 23,921 |
| tcd-google-maps | — | 2,135 |
| xo-event-calendar | — | 3,531 |
Security Headers
6 missing headers
Missing headers:
- Strict-Transport-Security (HSTS) — Forces HTTPS connections ?
- Content-Security-Policy (CSP) — Prevents XSS attacks ?
- X-Content-Type-Options — Prevents MIME sniffing ?
- X-Frame-Options — Prevents clickjacking ?
- Referrer-Policy — Controls referrer information ?
- Permissions-Policy — Limits browser features ?
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (5.1.19) — outdated core with known vulnerabilities. Update to the latest release immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.
Other WordPress domains on this IP (25+)
These WordPress domains are served from the same IP (157.7.107.xxx) — usually shared hosting or the same operator. Domains are obfuscated uniformly.
- b*o*s*-*s*u*.com
- b*a*i*r*l*n*o*.com
- f*g*t*l*b.c*.jp
- h*c*o*n*t*.com
- h*d*y*s*a.com
- h*g*4*3.com
- k*k*-*o*z*.com
- k*n*d*-*a*.com
- k*n*y*e*.com
- k*n*o*o*h*r*q.com
- k*o*i*p*o.com
- k*t*c*i*o*o.com
- k*i*i*m*n*g*m*n*.com
- k*d*-*n*l*s*s*u*y.com
- k*k*k*3.com
- k*s*-*e*h*g*t*i*h*.com
- k*y*m*-*e*u*y*a*o*.com
- o*i*e*p*n.com
- r*s*a*r*n*-*c*c*a.com
- r*a*l*m*.com
- s*o*k*o*d*.net
- s*b*r*o.com
- s*c*a*-*r*t*i*.com
- t*i*o.online
- y*k*a*c*i*j*-*u*b*.com