WordPress maintenance or security needs? Reach out!
TLDWP

Plugin: js_composer_bad (Used by 1 domains)

Security snapshot

Across 1 js_composer_bad WordPress sites indexed by TLDWP, compared to the all-WordPress average.

Grade A 0% Grade B 0% Grade C 0% Grade D 0% Grade F 100%
Fail the header check (F)100%vs 82.5% avg
Leak usernames0%vs 38.5% avg
Expose a sensitive file100%vs 1.8% avg
Use HTTPS0%vs 96.2% avg

What stands out

TLDWP currently associates 1 indexed WordPress sites with js_composer_bad, equivalent to 0% of the current WordPress dataset.

The largest measured difference is sensitive-file exposure: 100% versus 1.8% overall (+98.2 percentage points).

HTTPS adoption is 0% vs 96.2% overall (-96.2 pp); Username enumeration is 0% vs 38.5% overall (-38.5 pp); Header-grade F is 100% vs 82.5% overall (+17.5 pp).

These are observational associations among sites where TLDWP detected js_composer_bad, not evidence that the technology, provider, or domain attribute caused a security outcome. See the overall WordPress security baseline.

Domain Exposures Headers Last Checked
c*o*m*g.com (WP 6.4.8) F Jul 22, 2026