Security snapshot
Across 5 xtra2 WordPress sites indexed by TLDWP, compared to the all-WordPress average.
Grade A 0%
Grade B 0%
Grade C 0%
Grade D 0%
Grade F 100%
Fail the header check (F)100%vs 82.5% avg
Leak usernames40%vs 38.5% avg
Expose a sensitive file0%vs 1.8% avg
Use HTTPS80%vs 96.2% avg
What stands out
TLDWP currently associates 5 indexed WordPress sites with xtra2, equivalent to 0% of the current WordPress dataset.
The largest measured difference is header-grade F: 100% versus 82.5% overall (+17.5 percentage points).
HTTPS adoption is 80% vs 96.2% overall (-16.2 pp); Sensitive-file exposure is 0% vs 1.8% overall (-1.8 pp); Username enumeration is 40% vs 38.5% overall (+1.5 pp).
These are observational associations among sites where TLDWP detected xtra2, not evidence that the technology, provider, or domain attribute caused a security outcome. See the overall WordPress security baseline.
| Domain | Exposures | Headers | Last Checked |
|---|---|---|---|
| t*j*l*m*d.ir (WP 5.7.14) | F | Sep 8, 2026 | |
| l*p*l*s*.com (WP 5.9.16) | F | Aug 27, 2026 | |
| b*l*k*a*e.com (WP 7.1) | F | Aug 26, 2026 | |
| m*h*h*d*e*h*n.com | F | Aug 25, 2026 | |
| p*s*a*o*m.com (WP 7.0.2) | F | Jul 31, 2026 |
Page 1 of 1