https://archangelmichaelsecurity.co.ke
Scan complete
archangelmichaelsecurity.co.ke
13 issues detected
Scanned 4 months ago
13
Total
0
Critical
0
High
3
Medium
Theme 'salient' v17.0.3: Salient < 17.4.0 - Missing Authorization
WP_DEBUG is disabled (no PHP errors visible)
PHP 8.2.15 detected (supported version)
X-Powered-By header exposed: PHP/8.2.15, PleskLin — reveals server software
How to fix: Hide X-Powered-By header. In php.ini set expose_php = Off, or add Header unset X-Powered-By to .htaccess.
Missing security header: Strict-Transport-Security -- Enforces HTTPS connections
How to fix: Add to .htaccess or nginx: Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"
Missing security header: Content-Security-Policy -- Controls resource loading
Missing security header: Permissions-Policy -- Controls browser feature access
3 of 6 security headers configured
SSL certificate valid (264 days remaining) — issued by DigiCert Inc
HTTP redirect does not point to HTTPS
How to fix: Add a redirect rule in .htaccess or your host's SSL settings to force HTTP → HTTPS.
REST API user enumeration blocked
No external scripts detected
Checked against 11 blacklist services
Your site passed the surface scan. For complete peace of mind, a deep scan checks file integrity, database injections, and hidden backdoors at the server level.
Run Deep Scan — $1