Domain Information
WordPress Version: 6.9 VULNERABLE
Theme: Divi 4.27.5· 60% conf. (theme used by 474,774 domains)
Last Checked: 2026-09-09 19:53:16
HTTPS: Yes
Server: wetopi
Response time (TTFB): 665 ms
Hosting: OVH SAS (AS16276)
IP address: 54.38.163.xxx
Plugins (12)
| Plugin | Version | Used By |
|---|---|---|
| ajax-search-for-woocommerce | 1.32.2· 60% conf. | 20,637 |
| divi-pixel | 1.0.0· 85% conf. | 13,228 |
| equal-height-columns | 1.2.1· 60% conf. | 3,337 |
| gravityforms | — | 246,917 |
| gravityformsrecaptcha | 2.1.0· 60% conf. | 71,325 |
| gs-logo-slider | 3.8.1· 85% conf. | 7,481 |
| side-cart-woocommerce | 2.7.2· 85% conf. | 8,805 |
| sitepress-multilingual-cms | — | 203,722 |
| webtoffee-cookie-consent | 3.5.0· 85% conf. | 5,592 |
| woocommerce | 10.5.2· 85% conf. | 783,975 |
| woocommerce-gateway-stripe | — | 57,963 |
| woocommerce-multilingual | 5.5.3.1· 60% conf. | 25,605 |
Security Headers
3 missing headers
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (6.9) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 6.9.5 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress infrastructure? Contact us for a professional security audit.
Other WordPress domains on this IP (1)
These WordPress domains are served from the same IP (54.38.163.xxx) — usually shared hosting or the same operator. Domains are obfuscated uniformly.