WordPress maintenance or security needs? Reach out!
TLDWP

Plugin: js_composer-purchashed (Used by 12 domains)

Security snapshot

Across 12 js_composer-purchashed WordPress sites indexed by TLDWP, compared to the all-WordPress average.

Security metrics currently cover 11 matching records in the cached metrics snapshot.

Grade A 0% Grade B 0% Grade C 0% Grade D 9% Grade F 91%
Fail the header check (F)91%vs 82.5% avg
Leak usernames64%vs 38.5% avg
Expose a sensitive file0%vs 1.8% avg
Use HTTPS91%vs 96.2% avg

What stands out

TLDWP currently associates 12 indexed WordPress sites with js_composer-purchashed, equivalent to 0% of the current WordPress dataset.

The largest measured difference is username enumeration: 63.6% versus 38.5% overall (+25.1 percentage points).

Header-grade F is 90.9% vs 82.5% overall (+8.4 pp); HTTPS adoption is 90.9% vs 96.2% overall (-5.3 pp); Sensitive-file exposure is 0% vs 1.8% overall (-1.8 pp).

These are observational associations among sites where TLDWP detected js_composer-purchashed, not evidence that the technology, provider, or domain attribute caused a security outcome. See the overall WordPress security baseline.

js_composer-purchashed Premium / Custom

This plugin is not available on WordPress.org. It may be a premium plugin, a custom plugin, or a plugin from a third-party marketplace.

Domain Exposures Headers Last Checked
s*w*e*i*e*e*.com (WP 6.7.7) F Sep 9, 2026
g*i*2*.fr F Sep 4, 2026
a*l*d*u*a*.com (WP 6.4.10) F Aug 29, 2026
t*-*l*a*i*g.com (WP 4.9.3) F Aug 27, 2026
p*s*h*n*e*t*r.com F Aug 25, 2026
b*n*e*.com (WP 5.3.23) F Aug 16, 2026
u*i*i*y*a*i*g*h*b.com (WP 4.9.8) F Aug 16, 2026
s*a*a.c*.ke (WP 6.8.8) D Aug 16, 2026
i*s*i*u*o*n*i*.es (WP 4.7.10) F Aug 3, 2026
c*s*e*e*a*d*a*m*c*.com (WP 5.3.21) F Jul 30, 2026
h*a*a*d*a*h*h*n.com (WP 6.6.5) F Jul 19, 2026