https://cog.go.ke
Scan complete
cog.go.ke
19 issues detected
Scanned 3 months ago
19
Total
1
Critical
0
High
8
Medium
Plugin 'pojo-accessibility' v4.0.3: Ally - WordPress Ally - Web Accessibility & Usability plugin <= 4.0.3 - Unauthenticated SQL Injection via URL Path vulnerability
Plugin 'pojo-accessibility' v4.0.3: Ally < 4.0.3 - Missing Authorization
Plugin 'pojo-accessibility' v4.0.3: Ally < 4.1.0 - Unauthenticated SQLi via URL Path
Plugin 'elementskit' v3.7.8: ElementsKit Pro <= 3.7.8 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via url Parameter
Plugin 'masterslider' v3.7.8: Master Slider Pro <= 3.7.12 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP_DEBUG is disabled (no PHP errors visible)
Missing security header: X-Frame-Options -- Prevents clickjacking attacks
How to fix: Add to .htaccess: Header always set X-Frame-Options "SAMEORIGIN" — prevents clickjacking attacks.
Missing security header: X-Content-Type-Options -- Prevents MIME-type sniffing
How to fix: Add to .htaccess: Header always set X-Content-Type-Options "nosniff" — prevents MIME-type sniffing.
Missing security header: Strict-Transport-Security -- Enforces HTTPS connections
How to fix: Add to .htaccess or nginx: Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"
Missing security header: Content-Security-Policy -- Controls resource loading
Missing security header: Referrer-Policy -- Controls referrer information
Missing security header: Permissions-Policy -- Controls browser feature access
SSL certificate valid (57 days remaining) — issued by Let's Encrypt
HTTP does not redirect to HTTPS
How to fix: Add a redirect rule in .htaccess or your host's SSL settings to force HTTP → HTTPS.
REST API user enumeration blocked
External JS from popular domain: cdn.elementor.com (Tranco rank #3,593)
How to fix: This script is from a well-known domain (ranked in the top 100K globally). Likely legitimate, but verify it matches a service you intentionally added.
2 trusted external script(s): maps.googleapis.com (Google), www.googletagmanager.com (Google)
1 external script(s) from popular domains (Tranco top 100K): cdn.elementor.com
How to fix: These scripts are from globally popular domains. They are very likely legitimate services but were not in our curated whitelist.
Checked against 11 blacklist services
We found critical security issues. Our experts can clean your site and fix all vulnerabilities within 24 hours.
Get Expert Cleanup — $49