https://dobschat.io
Scan complete
dobschat.io
28 issues detected
Scanned 3 months ago
28
Total
0
Critical
0
High
14
Medium
Plugin 'jet-search' v1.0.0: Multiple Plugins by Crocoblock <= (Various Versions) - Cross-Site Request Forgery
Plugin 'jet-search' v1.0.0: JetSearch <= 3.5.10 - Unauthenticated SQL Injection
Plugin 'jet-search' v1.0.0: JetSearch <= 3.5.10.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Plugin 'jet-search' v1.0.0: JetSearch <= 3.5.10 - Reflected Cross-Site Scripting
Plugin 'jet-search' v1.0.0: JetSearch <= 3.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
Plugin 'jet-search' v1.0.0: Multiple Plugins by Crocoblock <= (Various Versions) - Missing Authorization
Plugin 'jet-search' v1.0.0: JetSearch <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Plugin 'jet-search' v1.0.0: JetSearch <= 3.5.16 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP_DEBUG is disabled (no PHP errors visible)
PHP 8.4.18 detected (supported version)
X-Powered-By header exposed: PHP/8.4.18 — reveals server software
How to fix: Hide X-Powered-By header. In php.ini set expose_php = Off, or add Header unset X-Powered-By to .htaccess.
Missing security header: X-Frame-Options -- Prevents clickjacking attacks
How to fix: Add to .htaccess: Header always set X-Frame-Options "SAMEORIGIN" — prevents clickjacking attacks.
Missing security header: X-Content-Type-Options -- Prevents MIME-type sniffing
How to fix: Add to .htaccess: Header always set X-Content-Type-Options "nosniff" — prevents MIME-type sniffing.
Missing security header: Content-Security-Policy -- Controls resource loading
Missing security header: Referrer-Policy -- Controls referrer information
Missing security header: Permissions-Policy -- Controls browser feature access
1 of 6 security headers configured
SSL certificate valid (45 days remaining) — issued by Let's Encrypt
HTTP correctly redirects to HTTPS
WordPress license file exposed
/license.txt
User enumeration possible via REST API -- found: dobschat
How to fix: Disable the REST API users endpoint with a plugin like Disable REST API or add a filter to block /wp/v2/users.
wp-cron.php is publicly accessible (potential DDoS vector)
/wp-cron.php
How to fix: Disable WP-Cron in wp-config.php with define("DISABLE_WP_CRON", true) and use a real server cron job instead.
External JS from popular domain: cdn.by.wonderpush.com (Tranco rank #20,716)
How to fix: This script is from a well-known domain (ranked in the top 100K globally). Likely legitimate, but verify it matches a service you intentionally added.
Suspicious inline JavaScript: unescape() usage
How to fix: Inspect this inline JavaScript carefully — obfuscated code can indicate malware injection.
Suspicious inline JavaScript: unescape() usage
How to fix: Inspect this inline JavaScript carefully — obfuscated code can indicate malware injection.
Suspicious inline JavaScript: unescape() usage
How to fix: Inspect this inline JavaScript carefully — obfuscated code can indicate malware injection.
1 external script(s) from popular domains (Tranco top 100K): cdn.by.wonderpush.com
How to fix: These scripts are from globally popular domains. They are very likely legitimate services but were not in our curated whitelist.
Checked against 11 blacklist services
We found critical security issues. Our experts can clean your site and fix all vulnerabilities within 24 hours.
Get Expert Cleanup — $49