https://czerwonyportfelik.pl
Scan complete
czerwonyportfelik.pl
28 issues detected
Scanned 4 weeks ago
28
Total
11
Critical
3
High
3
Medium
WP_DEBUG is enabled — PHP errors visible on page: PHP Fatal Error
How to fix: Set WP_DEBUG to false in wp-config.php. Debug output exposes file paths and database info to attackers.
Missing security header: X-Frame-Options -- Prevents clickjacking attacks
How to fix: Add to .htaccess: Header always set X-Frame-Options "SAMEORIGIN" — prevents clickjacking attacks.
Missing security header: X-Content-Type-Options -- Prevents MIME-type sniffing
How to fix: Add to .htaccess: Header always set X-Content-Type-Options "nosniff" — prevents MIME-type sniffing.
Missing security header: Strict-Transport-Security -- Enforces HTTPS connections
How to fix: Add to .htaccess or nginx: Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"
Missing security header: Content-Security-Policy -- Controls resource loading
Missing security header: Referrer-Policy -- Controls referrer information
Missing security header: Permissions-Policy -- Controls browser feature access
SSL certificate valid (157 days remaining) — issued by cyber_Folks S.A.
HTTP correctly redirects to HTTPS
Git repository exposed
/.git/config
Environment file exposed
/.env
Debug log exposed
/wp-content/debug.log
WordPress readme exposed (version info)
/readme.html
WordPress license file exposed
/license.txt
Backup of wp-config.php exposed (may contain DB credentials)
/wp-config.php.bak
How to fix: Delete this backup file immediately — it may contain database credentials or sensitive data.
Editor backup of wp-config.php exposed
/wp-config.php~
How to fix: Delete this backup file immediately — it may contain database credentials or sensitive data.
Editor recovery of wp-config.php exposed
/wp-config.php.save
How to fix: Delete this backup file immediately — it may contain database credentials or sensitive data.
Old copy of wp-config.php exposed
/wp-config.php.old
How to fix: Delete this backup file immediately — it may contain database credentials or sensitive data.
Original wp-config.php exposed
/wp-config.php.orig
How to fix: Delete this backup file immediately — it may contain database credentials or sensitive data.
Vim swap file for wp-config.php exposed
/.wp-config.php.swp
How to fix: Delete this backup file immediately — it may contain database credentials or sensitive data.
Database backup file exposed
/backup.sql
How to fix: Delete this backup file immediately — it may contain database credentials or sensitive data.
Database dump file exposed
/database.sql
How to fix: Delete this backup file immediately — it may contain database credentials or sensitive data.
Database dump file exposed
/dump.sql
How to fix: Delete this backup file immediately — it may contain database credentials or sensitive data.
Database dump file exposed
/db.sql
How to fix: Delete this backup file immediately — it may contain database credentials or sensitive data.
REST API user enumeration blocked
wp-cron.php is publicly accessible (potential DDoS vector)
/wp-cron.php
How to fix: Disable WP-Cron in wp-config.php with define("DISABLE_WP_CRON", true) and use a real server cron job instead.
No external scripts detected
Checked against 11 blacklist services
We found critical security issues. Our experts can clean your site and fix all vulnerabilities within 24 hours.
Get Expert Cleanup — $49