Site Information
WordPress Version: 6.9.4 VULNERABLE
Theme: hello-elementor (used by 607,710 domains)
Last Checked: 2026-09-06 04:50:33
HTTPS: Yes
Server: openresty
Response time (TTFB): 457 ms
Hosting: WebSupport s.r.o. (AS51013)
IP address: 37.9.175.188
Other WordPress sites on this IP (14)
These WordPress sites are served from the same IP (37.9.175.188) — usually shared hosting or the same owner. Domains are obfuscated, as everywhere on the site.
- a*v*s*o.sk
- b*o*e*a*e*c*.com
- b*v*.sk
- e*a*a*h*n*k*v*.com
- g*n*a*u*s*i*.sk
- m*l*i*p*r*.sk
- m*y*k*a*d*a*e.com
- m*l*h*u*.sk
- n*p*a*-*o*u*y.sk
- p*d*e*a*a*i*m*r*v*.sk
- p*o*e*h*u*.sk
- r*n*-*v*n*.com
- s*o*o*a*a*o*.sk
- s*d*-*o*i*g.com
Plugins (29)
| Plugin | Used By |
|---|---|
| custom-price-for-woocommerce-pro | 32 |
| elementor | 1,724,510 |
| elementor-pro | 1,027,569 |
| flexible-coupons-pro | 372 |
| give-form-field-manager | 2,520 |
| give-recurring | 3,852 |
| jet-blocks | 22,787 |
| jet-blog | 15,203 |
| jet-elements | 63,474 |
| jet-engine | 76,362 |
| jet-menu | 28,231 |
| jet-popup | 16,560 |
| jet-tabs | 32,468 |
| jet-theme-core | 11,266 |
| jet-tricks | 21,678 |
| jet-woo-builder | 11,649 |
| jet-woo-builder-custom-quantity-selectors-main | 179 |
| jet-woo-product-gallery | 7,285 |
| jetformbuilder | 5,881 |
| latepoint | 4,526 |
| latepoint-service-extras | 57 |
| mailchimp-for-woocommerce | 43,653 |
| old-give | 0 |
| sitepress-multilingual-cms | 206,277 |
| wc-quantity-plus-minus-button | 2,040 |
| woo-variation-swatches | 31,135 |
| woocommerce | 796,664 |
| woocommerce-latepoint | 5 |
| wpc-grouped-product-premium | 300 |
Security Headers
6 missing headers
Missing headers:
- Strict-Transport-Security (HSTS) — Forces HTTPS connections ?
- Content-Security-Policy (CSP) — Prevents XSS attacks ?
- X-Content-Type-Options — Prevents MIME sniffing ?
- X-Frame-Options — Prevents clickjacking ?
- Referrer-Policy — Controls referrer information ?
- Permissions-Policy — Limits browser features ?
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9.4) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
Need help securing your WordPress site? Contact us for a professional security audit.