WordPress maintenance or security needs? Reach out!
TLDWP

Plugin: qmf4 (Used by 5 domains)

Security snapshot

Across 5 qmf4 WordPress sites indexed by TLDWP, compared to the all-WordPress average.

Grade A 20% Grade B 0% Grade C 20% Grade D 0% Grade F 60%
Fail the header check (F)60%vs 82.5% avg
Leak usernames40%vs 38.5% avg
Expose a sensitive file60%vs 1.8% avg
Use HTTPS40%vs 96.2% avg

What stands out

TLDWP currently associates 5 indexed WordPress sites with qmf4, equivalent to 0% of the current WordPress dataset.

The largest measured difference is sensitive-file exposure: 60% versus 1.8% overall (+58.2 percentage points).

HTTPS adoption is 40% vs 96.2% overall (-56.2 pp); Header-grade F is 60% vs 82.5% overall (-22.5 pp); Username enumeration is 40% vs 38.5% overall (+1.5 pp).

These are observational associations among sites where TLDWP detected qmf4, not evidence that the technology, provider, or domain attribute caused a security outcome. See the overall WordPress security baseline.

qmf4 Premium / Custom

This plugin is not available on WordPress.org. It may be a premium plugin, a custom plugin, or a plugin from a third-party marketplace.

Domain Exposures Headers Last Checked
l*t*a*l*b*e*.com (WP 6.8.1) F Aug 22, 2026
g*s*r*c*i*i*a*.com (WP 7.1) F Aug 21, 2026
i*-*a*e*t.mx A Aug 2, 2026
m*k*l*c*u.com (WP 6.9.5) C Jul 31, 2026
g*e*c*l*e*t*r.com (WP 6.9.4) F Jul 19, 2026