https://dmv.ca.gov
Scan complete
dmv.ca.gov
18 issues detected
Scanned 4 months ago
18
Total
5
Critical
2
High
2
Medium
WP_DEBUG is disabled (no PHP errors visible)
Missing security header: X-Content-Type-Options -- Prevents MIME-type sniffing
How to fix: Add to .htaccess: Header always set X-Content-Type-Options "nosniff" — prevents MIME-type sniffing.
Missing security header: Referrer-Policy -- Controls referrer information
Missing security header: Permissions-Policy -- Controls browser feature access
3 of 6 security headers configured
SSL certificate valid (317 days remaining) — issued by Sectigo Limited
HTTP correctly redirects to HTTPS
Cookies missing security flags (HttpOnly, SameSite, Secure): AWSALB, AWSALBCORS
How to fix: Set cookie security flags in wp-config.php: @ini_set("session.cookie_httponly", 1); @ini_set("session.cookie_secure", 1); @ini_set("session.cookie_samesite", "Lax");
Git repository exposed
/.git/config
Environment file exposed
/.env
Debug log exposed
/wp-content/debug.log
Backup of wp-config.php exposed (may contain DB credentials)
/wp-config.php.bak
How to fix: Delete this backup file immediately — it may contain database credentials or sensitive data.
Editor recovery of wp-config.php exposed
/wp-config.php.save
How to fix: Delete this backup file immediately — it may contain database credentials or sensitive data.
Old copy of wp-config.php exposed
/wp-config.php.old
How to fix: Delete this backup file immediately — it may contain database credentials or sensitive data.
htpasswd file exposed (may contain hashed passwords)
/.htpasswd
How to fix: Delete this backup file immediately — it may contain database credentials or sensitive data.
REST API user enumeration blocked
No external scripts detected
Checked against 11 blacklist services
We found critical security issues. Our experts can clean your site and fix all vulnerabilities within 24 hours.
Get Expert Cleanup — $49