Security Scan Results

https://drivefix.in

Screenshot of https://drivefix.in

drivefix.in

F

Critical — Immediate Action Needed

25 issues detected

Scanned 1 month ago

25

Total

0

Critical

5

High

7

Medium

Info

WordPress version 6.8.7 detected

High

Plugin 'elementor' v0.2.1: Elementor <= 3.18.1 - Authenticated(Contributor+) Arbitrary File Upload to Remote Code Execution via Template Import

High

Plugin 'elementor' v0.2.1: Elementor <= 3.19.0 - Authenticated(Contributor+) Arbitrary File Deletion and PHAR Deserialization

High

Plugin 'elementor' v0.2.1: Elementor Website Builder <= 1.7.12 - Missing Authorization

High

Plugin 'elementor' v0.2.1: Elementor Website Builder <= 2.7.4 - Arbitrary File Upload

High

Plugin 'elementor' v0.2.1: Elementor Website Builder <= 2.8.3 - Cross-Site Scripting

Medium

Plugin 'elementor' v0.2.1: Elementor <= 3.12.1 - Authenticated(Administrator+) SQL Injection via 'replace_urls'

Medium

Plugin 'elementor' v0.2.1: Elementor Website Builder <= 2.9.5 - Authorization Bypass

Medium

Plugin 'elementor' v0.2.1: Elementor Website Builder <= 3.16.4 - Missing Authorization to Arbitrary Attachment Read

Medium

Plugin 'elementor' v0.2.1: Elementor Website Builder <= 3.16.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via get_inline_svg()

Info

WP_DEBUG is disabled (no PHP errors visible)

Info

PHP 8.2.30 detected (supported version)

Low

X-Powered-By header exposed: PHP/8.2.30 — reveals server software

How to fix: Hide X-Powered-By header. In php.ini set expose_php = Off, or add Header unset X-Powered-By to .htaccess.

Medium

Missing security header: X-Frame-Options -- Prevents clickjacking attacks

How to fix: Add to .htaccess: Header always set X-Frame-Options "SAMEORIGIN" — prevents clickjacking attacks.

Medium

Missing security header: X-Content-Type-Options -- Prevents MIME-type sniffing

How to fix: Add to .htaccess: Header always set X-Content-Type-Options "nosniff" — prevents MIME-type sniffing.

Medium

Missing security header: Strict-Transport-Security -- Enforces HTTPS connections

How to fix: Add to .htaccess or nginx: Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"

Info

Missing security header: Referrer-Policy -- Controls referrer information

Info

2 of 6 security headers configured

Info

SSL certificate valid (59 days remaining) — issued by Let's Encrypt

Info

HTTP correctly redirects to HTTPS

Info

REST API user enumeration blocked

Low

External JS from popular domain: cdn.chatway.app (Tranco rank #27,479)

How to fix: This script is from a well-known domain (ranked in the top 100K globally). Likely legitimate, but verify it matches a service you intentionally added.

Info

1 trusted external script(s): www.googletagmanager.com (Google)

Low

1 external script(s) from popular domains (Tranco top 100K): cdn.chatway.app

How to fix: These scripts are from globally popular domains. They are very likely legitimate services but were not in our curated whitelist.

Checked against 11 blacklist services

Spamhaus DBL
SURBL
URIBL
SpamEatingMonkey
Barracuda
SORBS
Invaluement
URLhaus
OpenPhish
Google Safe Browsing
VirusTotal (70+ engines)

Your site needs immediate attention

We found critical security issues. Our experts can clean your site and fix all vulnerabilities within 24 hours.

Get Expert Cleanup — $49
Scan another site