https://drivefix.in
Scan complete
drivefix.in
25 issues detected
Scanned 1 month ago
25
Total
0
Critical
5
High
7
Medium
WordPress version 6.8.7 detected
Plugin 'elementor' v0.2.1: Elementor <= 3.18.1 - Authenticated(Contributor+) Arbitrary File Upload to Remote Code Execution via Template Import
Plugin 'elementor' v0.2.1: Elementor <= 3.19.0 - Authenticated(Contributor+) Arbitrary File Deletion and PHAR Deserialization
Plugin 'elementor' v0.2.1: Elementor Website Builder <= 1.7.12 - Missing Authorization
Plugin 'elementor' v0.2.1: Elementor Website Builder <= 2.7.4 - Arbitrary File Upload
Plugin 'elementor' v0.2.1: Elementor Website Builder <= 2.8.3 - Cross-Site Scripting
Plugin 'elementor' v0.2.1: Elementor <= 3.12.1 - Authenticated(Administrator+) SQL Injection via 'replace_urls'
Plugin 'elementor' v0.2.1: Elementor Website Builder <= 2.9.5 - Authorization Bypass
Plugin 'elementor' v0.2.1: Elementor Website Builder <= 3.16.4 - Missing Authorization to Arbitrary Attachment Read
Plugin 'elementor' v0.2.1: Elementor Website Builder <= 3.16.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via get_inline_svg()
WP_DEBUG is disabled (no PHP errors visible)
PHP 8.2.30 detected (supported version)
X-Powered-By header exposed: PHP/8.2.30 — reveals server software
How to fix: Hide X-Powered-By header. In php.ini set expose_php = Off, or add Header unset X-Powered-By to .htaccess.
Missing security header: X-Frame-Options -- Prevents clickjacking attacks
How to fix: Add to .htaccess: Header always set X-Frame-Options "SAMEORIGIN" — prevents clickjacking attacks.
Missing security header: X-Content-Type-Options -- Prevents MIME-type sniffing
How to fix: Add to .htaccess: Header always set X-Content-Type-Options "nosniff" — prevents MIME-type sniffing.
Missing security header: Strict-Transport-Security -- Enforces HTTPS connections
How to fix: Add to .htaccess or nginx: Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"
Missing security header: Referrer-Policy -- Controls referrer information
2 of 6 security headers configured
SSL certificate valid (59 days remaining) — issued by Let's Encrypt
HTTP correctly redirects to HTTPS
REST API user enumeration blocked
External JS from popular domain: cdn.chatway.app (Tranco rank #27,479)
How to fix: This script is from a well-known domain (ranked in the top 100K globally). Likely legitimate, but verify it matches a service you intentionally added.
1 trusted external script(s): www.googletagmanager.com (Google)
1 external script(s) from popular domains (Tranco top 100K): cdn.chatway.app
How to fix: These scripts are from globally popular domains. They are very likely legitimate services but were not in our curated whitelist.
Checked against 11 blacklist services
We found critical security issues. Our experts can clean your site and fix all vulnerabilities within 24 hours.
Get Expert Cleanup — $49