Domain Information
WordPress Version: 5.7.16 VULNERABLE
Theme: sydney 1.75· 100% conf. (theme used by 15,631 domains)
Last Checked: 2026-09-08 21:28:57
HTTPS: Yes
Server: nginx
Response time (TTFB): 570 ms
Hosting: KIFU (Governmental Info Tech Development Agency) (AS1955)
IP address: 193.6.201.xxx
Plugins (10)
| Plugin | Version | Used By |
|---|---|---|
| contact-form-7 | 5.4.1788902489· 85% conf. | 1,707,342 |
| cookie-notice | — | 143,167 |
| google-analytics-for-wordpress | 7.16.2.1788902489· 85% conf. | 196,476 |
| jquery-collapse-o-matic | — | 8,324 |
| nextgen-gallery | 3.8.0.1788902489· 85% conf. | 16,498 |
| search-filter | 1.1788902489· 60% conf. | 13,683 |
| super-socializer | 7.13.13.1788902489· 85% conf. | 4,083 |
| svg-support | 1.0.0.1788902489· 60% conf. | 27,866 |
| widget-options | — | 28,340 |
| widgetize-pages-light | 1.1.1788902489· 85% conf. | 824 |
Security Headers
1 missing header
Missing headers:
- Content-Security-Policy (CSP) — Prevents XSS attacks ?
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (5.7.16) — outdated core with known vulnerabilities. Update to the latest release immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.