Security snapshot
Across 7 extends WordPress sites indexed by TLDWP, compared to the all-WordPress average.
Grade A 0%
Grade B 14%
Grade C 0%
Grade D 14%
Grade F 71%
Fail the header check (F)71%vs 82.5% avg
Leak usernames14%vs 38.5% avg
Expose a sensitive file0%vs 1.8% avg
Use HTTPS100%vs 96.2% avg
What stands out
TLDWP currently associates 7 indexed WordPress sites with extends, equivalent to 0% of the current WordPress dataset.
The largest measured difference is username enumeration: 14.3% versus 38.5% overall (-24.2 percentage points).
Header-grade F is 71.4% vs 82.5% overall (-11.1 pp); HTTPS adoption is 100% vs 96.2% overall (+3.8 pp); Sensitive-file exposure is 0% vs 1.8% overall (-1.8 pp).
These are observational associations among sites where TLDWP detected extends, not evidence that the technology, provider, or domain attribute caused a security outcome. See the overall WordPress security baseline.
| Domain | Exposures | Headers | Last Checked |
|---|---|---|---|
| c*n*e*t*o*s*.pl (WP 6.8.8) | F | Aug 31, 2026 | |
| r*g*q*i*g*m*s.com | F | Aug 30, 2026 | |
| s*e*b*u*o*s*a.pl (WP 7.1) | F | Aug 26, 2026 | |
| z*m*p*.pl (WP 7.0.4) | F | Aug 19, 2026 | |
| s*o*d*z*c*a.pl | D | Aug 4, 2026 | |
| k*t*l*n.pl (WP 7.0.2) | B | Jul 27, 2026 | |
| f*a*l*s*.pl | F | Jul 23, 2026 |
Page 1 of 1