https://damemimanga.cl
Scan complete
damemimanga.cl
20 issues detected
Scanned 1 month ago
20
Total
0
Critical
0
High
4
Medium
WordPress version 7.0 detected
WP_DEBUG is disabled (no PHP errors visible)
Missing security header: X-Frame-Options -- Prevents clickjacking attacks
How to fix: Add to .htaccess: Header always set X-Frame-Options "SAMEORIGIN" — prevents clickjacking attacks.
Missing security header: Content-Security-Policy -- Controls resource loading
Missing security header: Referrer-Policy -- Controls referrer information
Missing security header: Permissions-Policy -- Controls browser feature access
2 of 6 security headers configured
SSL certificate valid (70 days remaining) — issued by Google Trust Services
HTTP does not redirect to HTTPS
How to fix: Add a redirect rule in .htaccess or your host's SSL settings to force HTTP → HTTPS.
CORS allows any origin (Access-Control-Allow-Origin: *)
How to fix: Consider restricting CORS to specific domains instead of using wildcard (*) if your site handles sensitive data.
WordPress readme exposed (version info)
/readme.html
WordPress license file exposed
/license.txt
REST API user enumeration blocked
wp-cron.php is publicly accessible (potential DDoS vector)
/wp-cron.php
How to fix: Disable WP-Cron in wp-config.php with define("DISABLE_WP_CRON", true) and use a real server cron job instead.
Suspicious inline JavaScript: heavy unicode-escaped strings (3640 occurrences)
How to fix: Inspect this inline JavaScript carefully — obfuscated code can indicate malware injection.
External JS from popular domain: cdn.trustindex.io (Tranco rank #2,915)
How to fix: This script is from a well-known domain (ranked in the top 100K globally). Likely legitimate, but verify it matches a service you intentionally added.
Suspicious inline JavaScript: heavy unicode-escaped strings (63 occurrences)
How to fix: Inspect this inline JavaScript carefully — obfuscated code can indicate malware injection.
1 trusted external script(s): cdn.brevo.com (Email Marketing)
1 external script(s) from popular domains (Tranco top 100K): cdn.trustindex.io
How to fix: These scripts are from globally popular domains. They are very likely legitimate services but were not in our curated whitelist.
Checked against 11 blacklist services
This surface scan checks what's publicly visible. A deep scan connects via SSH to check file integrity, database injections, and hidden backdoors.
Run Deep Scan — $1