Domain Information
WordPress Version: 6.9.4 VULNERABLE
Theme: astra (theme used by 394,051 domains)
Last Checked: 2026-09-06 14:01:17
HTTPS: Yes
Server: Apache
Response time (TTFB): 2,436 ms slow
Hosting: IONOS SE (AS8560)
IP address: 74.208.236.xxx
Plugins (11)
| Plugin | Version | Used By |
|---|---|---|
| astra-sites | — | 105,950 |
| elementor | — | 1,695,155 |
| header-footer-elementor | — | 195,990 |
| latepoint | — | 4,423 |
| simply-schedule-appointments | — | 7,351 |
| suretriggers | — | 4,711 |
| tablesome | — | 947 |
| the-post-grid | — | 13,939 |
| woocommerce | — | 783,975 |
| woocommerce-payments | — | 101,569 |
| wp-live-chat-support | — | 5,862 |
Security Headers
5 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9.4) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.
Other WordPress domains on this IP (22)
These WordPress domains are served from the same IP (74.208.236.xxx) — usually shared hosting or the same operator. Domains are obfuscated uniformly.
- b*o*y*r*p*e*i*v*n*t*.com
- d*v*d*a*s*n*r*s.com
- d*s*g*a*t*n*.com
- d*t*i*a*d*c*l*.com
- d*v*u*e*d*l*a*.com
- h*l*m*d*v*r*e*o*.com
- h*r*a*t*w*l*.com
- k*n*t*c*n*.com
- m*m*o*u*i*n*l*d.com
- o*s*s*i*r*.com
- o*y*p*a*a*e*y.com
- o*e*a*p*i*s.com
- r*d*u*m*s*e*i*g.com
- r*s*l*e*c*f*r*.com
- r*s*m*s*r*i*a*i*e*.com
- r*c*s*d*o*e*s.com
- s*l*g*z.com
- s*u*h*a*t*e*d.com
- s*c*p*p*a.com
- t*e*o*h*m*c*r*.com
- w*l*w*t*r*o*o.ca
- y*l*o*d*g*n*e*p*i*e*.com