https://digilove.no
Scan complete
digilove.no
13 issues detected
Scanned 4 months ago
13
Total
0
Critical
0
High
3
Medium
WordPress version 6.9.4 detected
Plugin 'svg-support' v2.5.8: SVG Support <= 2.5.10 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
Plugin 'svg-support' v2.5.8: SVG Support <= 2.5.8 - Stored Cross-Site Scripting via Vulnerability Dependency
Plugin 'svg-support' v2.5.8: SVG Support < 2.5.8 - Author+ Cross-Site Scripting via SVG
WP_DEBUG is disabled (no PHP errors visible)
6 of 6 security headers configured
SSL certificate valid (31 days remaining) — issued by Google Trust Services
HTTP correctly redirects to HTTPS
WordPress license file exposed
/license.txt
REST API user enumeration blocked
wp-cron.php is publicly accessible (potential DDoS vector)
/wp-cron.php
How to fix: Disable WP-Cron in wp-config.php with define("DISABLE_WP_CRON", true) and use a real server cron job instead.
1 trusted external script(s): www.googletagmanager.com (Google)
Checked against 11 blacklist services
Your site passed the surface scan. For complete peace of mind, a deep scan checks file integrity, database injections, and hidden backdoors at the server level.
Run Deep Scan — $1