WordPress maintenance or security needs? Reach out!
TLDWP

Plugin: gc-message-box (Used by 7 domains)

Security snapshot

Across 7 gc-message-box WordPress sites indexed by TLDWP, compared to the all-WordPress average.

Grade A 0% Grade B 0% Grade C 0% Grade D 0% Grade F 100%
Fail the header check (F)100%vs 82.5% avg
Leak usernames43%vs 38.5% avg
Expose a sensitive file0%vs 1.8% avg
Use HTTPS100%vs 96.2% avg

What stands out

TLDWP currently associates 7 indexed WordPress sites with gc-message-box, equivalent to 0% of the current WordPress dataset.

The largest measured difference is header-grade F: 100% versus 82.5% overall (+17.5 percentage points).

Username enumeration is 42.9% vs 38.5% overall (+4.4 pp); HTTPS adoption is 100% vs 96.2% overall (+3.8 pp); Sensitive-file exposure is 0% vs 1.8% overall (-1.8 pp).

These are observational associations among sites where TLDWP detected gc-message-box, not evidence that the technology, provider, or domain attribute caused a security outcome. See the overall WordPress security baseline.

gc-message-box Premium / Custom

This plugin is not available on WordPress.org. It may be a premium plugin, a custom plugin, or a plugin from a third-party marketplace.

Domain Exposures Headers Last Checked
a*e*i*a*m*d*c*l*r*n*i*.com (WP 5.0.3) F Sep 3, 2026
f*s*t*n*c*n*u*t*n*.c*.uk F Aug 4, 2026
c*c*r*.org F Aug 3, 2026
a*v*p*i*t*n*.com (WP 6.9.5) F Jul 28, 2026
f*s*t*n*c*n*u*t*n*.com F Jul 25, 2026
a*t*e*-*c*c*.org F Jul 23, 2026
m*o*p*a*e.fr F Jul 22, 2026