Security Scan Results

https://archangelmichaelsecurity.co.ke

Screenshot of https://archangelmichaelsecurity.co.ke

archangelmichaelsecurity.co.ke

A

Excellent Security

13 issues detected

Scanned 3 months ago

13

Total

0

Critical

0

High

3

Medium

Medium

Theme 'salient' v17.0.3: Salient < 17.4.0 - Missing Authorization

Info

WP_DEBUG is disabled (no PHP errors visible)

Info

PHP 8.2.15 detected (supported version)

Low

X-Powered-By header exposed: PHP/8.2.15, PleskLin — reveals server software

How to fix: Hide X-Powered-By header. In php.ini set expose_php = Off, or add Header unset X-Powered-By to .htaccess.

Medium

Missing security header: Strict-Transport-Security -- Enforces HTTPS connections

How to fix: Add to .htaccess or nginx: Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"

Info

Missing security header: Content-Security-Policy -- Controls resource loading

Info

Missing security header: Permissions-Policy -- Controls browser feature access

Info

3 of 6 security headers configured

Info

SSL certificate valid (264 days remaining) — issued by DigiCert Inc

Medium

HTTP redirect does not point to HTTPS

How to fix: Add a redirect rule in .htaccess or your host's SSL settings to force HTTP → HTTPS.

Info

REST API user enumeration blocked

Info

No external scripts detected

Checked against 11 blacklist services

Spamhaus DBL
SURBL
URIBL
SpamEatingMonkey
Barracuda
SORBS
Invaluement
URLhaus
OpenPhish
Google Safe Browsing
VirusTotal (70+ engines)

Looking good!

Your site passed the surface scan. For complete peace of mind, a deep scan checks file integrity, database injections, and hidden backdoors at the server level.

Run Deep Scan — $1
Scan another site