https://dvos.org
Scan complete
dvos.org
31 issues detected
Scanned 6 days ago
31
Total
0
Critical
5
High
14
Medium
Plugin 'LayerSlider' v6.5.1: LayerSlider <= 7.7.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Plugin 'LayerSlider' v6.5.1: LayerSlider <= 7.1.1 - Admin+ Stored Cross-Site Scripting
Plugin 'LayerSlider' v6.5.1: LayerSlider <= 7.7.9 - Cross-Site Request Forgery
Plugin 'revslider' v5.4.5.1: Slider Revolution < 6.6.19 - Authenticated (Author+) PHP Object Injection
Plugin 'revslider' v5.4.5.1: Slider Revolution <= 6.6.15 - Authenticated (Author+) Arbitrary File Upload
Plugin 'revslider' v5.4.5.1: Slider Revolution <= 6.6.12 - Authenticated (Administrator+) Arbitrary File Upload
Plugin 'revslider' v5.4.5.1: Slider Revolution <= 6.7.36 - Authenticated (Contributor+) Arbitrary File Read via 'used_svg' and 'used_images'
Plugin 'revslider' v5.4.5.1: Slider Revolution <= 6.7.37 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Read
Plugin 'js_composer' v7.6: WPBakery <= 7.7 - Authenticated (Author+) Local File Inclusion
Plugin 'js_composer' v7.6: WPBakery Page Builder <= 8.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Page Builder Elements
Plugin 'js_composer' v7.6: WPBakery Page Builder for WordPress <= 8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Plugin 'js_composer' v7.6: WPBakery Page Builder <= 8.4.1 - Authenticated (Author+) Stored Cross-Site Scripting via Grid Builder
Plugin 'js_composer' v7.6: WPBakery <= 7.7 - Authenticated (Author+) Stored Cross-Site Scripting
WP_DEBUG is disabled (no PHP errors visible)
PHP 7.4.33 detected — end of life, no security updates
How to fix: Upgrade PHP to 8.2+ via your hosting control panel. Outdated PHP receives no security patches.
X-Powered-By header exposed: PHP/7.4.33 — reveals server software
How to fix: Hide X-Powered-By header. In php.ini set expose_php = Off, or add Header unset X-Powered-By to .htaccess.
Missing security header: X-Frame-Options -- Prevents clickjacking attacks
How to fix: Add to .htaccess: Header always set X-Frame-Options "SAMEORIGIN" — prevents clickjacking attacks.
Missing security header: X-Content-Type-Options -- Prevents MIME-type sniffing
How to fix: Add to .htaccess: Header always set X-Content-Type-Options "nosniff" — prevents MIME-type sniffing.
Missing security header: Strict-Transport-Security -- Enforces HTTPS connections
How to fix: Add to .htaccess or nginx: Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"
Missing security header: Content-Security-Policy -- Controls resource loading
Missing security header: Referrer-Policy -- Controls referrer information
Missing security header: Permissions-Policy -- Controls browser feature access
SSL certificate valid (67 days remaining) — issued by Let's Encrypt
HTTP correctly redirects to HTTPS
WordPress readme exposed (version info)
/readme.html
WordPress license file exposed
/license.txt
User enumeration possible via REST API -- found: aznparkranger
How to fix: Disable the REST API users endpoint with a plugin like Disable REST API or add a filter to block /wp/v2/users.
wp-cron.php is publicly accessible (potential DDoS vector)
/wp-cron.php
How to fix: Disable WP-Cron in wp-config.php with define("DISABLE_WP_CRON", true) and use a real server cron job instead.
Suspicious inline JavaScript: unescape() usage
How to fix: Inspect this inline JavaScript carefully — obfuscated code can indicate malware injection.
No external scripts detected
Checked against 11 blacklist services
We found critical security issues. Our experts can clean your site and fix all vulnerabilities within 24 hours.
Get Expert Cleanup — $49