https://archdioceseofnairobi.org
Scan complete
51 issues detected
Scanned 2 months ago
51
Total
0
Critical
1
High
38
Medium
WordPress version 5.3.21 detected
Plugin 'woocommerce' v4.8.0: WooCommerce - Arbitrary Admin User Creation via CSRF vulnerability
Plugin 'contact-form-7' v5.2.1: Contact Form 7 < 6.0.6 - Order Replay Vulnerability
Plugin 'contact-form-7' v5.2.1: Contact Form 7 [contact-form-7] < 5.3.2
Plugin 'contact-form-7' v5.2.1: Contact Form 7 [contact-form-7] < 5.3.2
Plugin 'contact-form-7' v5.2.1: Contact Form 7 [contact-form-7] < 5.9.5
Plugin 'contact-form-7' v5.2.1: Contact Form 7 [contact-form-7] < 5.9.2
Plugin 'contact-form-7' v5.2.1: Contact Form 7 [contact-form-7] < 5.8.4
Plugin 'revslider' v6.1.1: Slider Revolution < 6.7.38 - Contributor+ Arbitrary File Read
Plugin 'revslider' v6.1.1: Slider Revolution [revslider] < 6.6.13
Plugin 'revslider' v6.1.1: Slider Revolution < 6.7.14 - Authenticated (Administrator+) Stored Cross-Site Scripting
Plugin 'revslider' v6.1.1: Slider Revolution < 6.7.0 - Missing Authorization
Plugin 'revslider' v6.1.1: Slider Revolution < 6.7.11 - Authenticated (Author+) Stored Cross-Site Scripting
Plugin 'wpb-elementor-addons' v1.0: WPB Elementor Addons <= 1.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via url Parameter
Plugin 'wpb-elementor-addons' v1.0: WPB Elementor Addons <= 1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
Plugin 'wpb-elementor-addons' v1.0: WPB Elementor Addons <= 1.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Plugin 'wpb-elementor-addons' v1.0: WPB Elementor Addons <= 1.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Plugin 'wpb-elementor-addons' v1.0: WPB Elementor Addons [wpb-elementor-addons] < 1.2 (closed)
Plugin 'wpb-elementor-addons' v1.0: WPB Elementor Addons [wpb-elementor-addons] < 1.2 (closed)
Plugin 'wpb-elementor-addons' v1.0: WPB Elementor Addons [wpb-elementor-addons] < 1.2 (closed)
Plugin 'wpb-elementor-addons' v1.0: WPB Elementor Addons [wpb-elementor-addons] <= 1.6 (unfixed)
Plugin 'eventON' v1.0: EventON [eventON] < 4.5.5
Plugin 'eventON' v1.0: EventON [eventON] < 3.0.6
Plugin 'eventON' v1.0: EventON [eventON] < 4.5.5
Plugin 'eventON' v1.0: EventON [eventON] < 4.5.5
Plugin 'eventON' v1.0: EventON [eventON] < 4.5.5
Plugin 'eventON' v1.0: EventON [eventON] < 4.5.5
Plugin 'eventON' v1.0: EventON [eventON] < 4.5.5
Plugin 'eventON' v1.0: EventON [eventON] < 4.5.5
Plugin 'eventON' v1.0: EventON [eventON] < 4.9.7
Plugin 'eventON' v1.0: EventON [eventON] <= 4.9.9 (unfixed)
Plugin 'elementor' v3.2.5: Elementor Website Builder - Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template vulnerability
WP_DEBUG is disabled (no PHP errors visible)
PHP 7.0.33 detected — end of life, no security updates
How to fix: Upgrade PHP to 8.2+ via your hosting control panel. Outdated PHP receives no security patches.
X-Powered-By header exposed: PHP/7.0.33, PleskLin — reveals server software
How to fix: Hide X-Powered-By header. In php.ini set expose_php = Off, or add Header unset X-Powered-By to .htaccess.
Missing security header: X-Frame-Options -- Prevents clickjacking attacks
How to fix: Add to .htaccess: Header always set X-Frame-Options "SAMEORIGIN" — prevents clickjacking attacks.
Missing security header: X-Content-Type-Options -- Prevents MIME-type sniffing
How to fix: Add to .htaccess: Header always set X-Content-Type-Options "nosniff" — prevents MIME-type sniffing.
Missing security header: Strict-Transport-Security -- Enforces HTTPS connections
How to fix: Add to .htaccess or nginx: Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"
Missing security header: Content-Security-Policy -- Controls resource loading
Missing security header: Referrer-Policy -- Controls referrer information
Missing security header: Permissions-Policy -- Controls browser feature access
SSL certificate valid (228 days remaining) — issued by DigiCert Inc
HTTP correctly redirects to HTTPS
REST API user enumeration blocked
wp-cron.php is publicly accessible (potential DDoS vector)
/wp-cron.php
How to fix: Disable WP-Cron in wp-config.php with define("DISABLE_WP_CRON", true) and use a real server cron job instead.
Suspicious inline JavaScript: String.fromCharCode obfuscation
How to fix: Inspect this inline JavaScript carefully — obfuscated code can indicate malware injection.
Suspicious inline JavaScript: unescape() usage
How to fix: Inspect this inline JavaScript carefully — obfuscated code can indicate malware injection.
Suspicious inline JavaScript: unescape() usage
How to fix: Inspect this inline JavaScript carefully — obfuscated code can indicate malware injection.
Suspicious inline JavaScript: unescape() usage
How to fix: Inspect this inline JavaScript carefully — obfuscated code can indicate malware injection.
3 trusted external script(s): maps.googleapis.com (Google), www.google.com (Google), www.googletagmanager.com (Google)
Checked against 11 blacklist services
We found critical security issues. Our experts can clean your site and fix all vulnerabilities within 24 hours.
Get Expert Cleanup — $49