Site Information
WordPress Version: 7.0 VULNERABLE
Theme: hello-elementor (used by 607,710 domains)
Last Checked: 2026-09-06 01:15:21
HTTPS: Yes
Server: Apache
Response time (TTFB): 2,521 ms slow
Hosting: IONOS SE (AS8560)
IP address: 217.160.0.23
Other WordPress sites on this IP (17)
These WordPress sites are served from the same IP (217.160.0.23) — usually shared hosting or the same owner. Domains are obfuscated, as everywhere on the site.
- b*u*n*w*h*e*-*r*i*e*t.de
- d*l*e*c*i*s*b*e*g*r*g*.com
- d*e*r*u*o*b*u.de
- d*u*s*e*u.fr
- e*e*y*e*b*c*e*.com
- e*e*g*e*n*r*w*h*a*i*a*.com
- h*p*y*e*t*r*a*n*e*t.de
- h*l*k*.com
- k*f*e*-*o*f*r.de
- l*h*a*n*r*i*e*.de
- m*r*i*m*s*r.de
- m*u*i*i*a*o*a*o*.com
- m*d*a*e*d*.es
- s*c*e*r*u*-*e*t*u*.de
- s*c*i*z.com
- v*c*e*p*r*.com
- z*o*-*a*m*t*c*n*k.de
Plugins (4)
| Plugin | Used By |
|---|---|
| complianz-gdpr | 251,646 |
| contact-form-7 | 1,718,970 |
| give | 17,561 |
| megamenu | 78,578 |
Security Headers
6 missing headers
Missing headers:
- Strict-Transport-Security (HSTS) — Forces HTTPS connections ?
- Content-Security-Policy (CSP) — Prevents XSS attacks ?
- X-Content-Type-Options — Prevents MIME sniffing ?
- X-Frame-Options — Prevents clickjacking ?
- Referrer-Policy — Controls referrer information ?
- Permissions-Policy — Limits browser features ?
Exposed Files & Configurations
This domain has publicly accessible security-sensitive files or configurations:
- Vulnerable WordPress Version (7.0) — wp2shell unauthenticated RCE (CVE-2026-63030). Update to 7.0.2 immediately.
- User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?
Need help securing your WordPress site? Contact us for a professional security audit.