Domain Information
WordPress Version: 7.0.1 VULNERABLE
Theme: Divi (used by 480,738 domains)
Last Checked: 2026-09-06 06:22:44
HTTPS: Yes
Server: cloudflare
CDN / WAF: Cloudflare
Response time (TTFB): 155 ms fast
Hosting: Cloudflare, Inc. (AS13335)
IP address: 162.159.130.xxx
Plugins (7)
| Plugin | Used By |
|---|---|
| addons-for-divi | 11,530 |
| dg-carousel | 3,977 |
| gravityforms | 251,722 |
| gravityformsrecaptcha | 72,730 |
| megamenu | 78,506 |
| supreme-modules-for-divi | 19,222 |
| wp-smush-pro | 44,799 |
Security Headers
6 missing headers
Missing headers:
- Strict-Transport-Security (HSTS) — Forces HTTPS connections ?
- Content-Security-Policy (CSP) — Prevents XSS attacks ?
- X-Content-Type-Options — Prevents MIME sniffing ?
- X-Frame-Options — Prevents clickjacking ?
- Referrer-Policy — Controls referrer information ?
- Permissions-Policy — Limits browser features ?
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (7.0.1) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 7.0.2 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.
Other WordPress domains on this IP (21)
These WordPress domains are served from the same IP (162.159.130.xxx) — usually shared hosting or the same operator. Domains are obfuscated uniformly.
- a*p*e*i*i*n*.org
- a*c*o*h*a*t*c*r*.com
- a*c*l*a*y*a*e*o*u*i*n*.com
- a*c*l*a*y*a*e*t*a*e*i*s.com
- b*r*h*s*g*l*e*y.com
- c*a*s*c*o*i*a*s.c*.uk
- d*l*o*s*e*t*l*o*i*g.com
- d*n*c*s*e*i*s*j*.com
- e*o*t*o.io
- e*p*r*b*o*e*r*s*u*c*s.com
- e*e*g*e*n*e*t*d.com
- e*o*a*s.com
- k*l*n*t*d*o*.com
- m*k*i*r*g*t*w*.org
- n*m*n*g*d*t.com
- r*f*a*k*t*.com
- r*g*n*r*t*v*-*h*r*a*-*x*d*z*r*.com
- r*n*v*c*o*t*t*l.com
- r*t*i*s*c*e*s.com
- t*r*e*i*o*a*o.it
- v*p*r*.com