Security Scan Results

https://experience-tours.ro

Screenshot of https://experience-tours.ro

experience-tours.ro

C

Fair — Some Issues Found

21 issues detected

Scanned 3 months ago

21

Total

0

Critical

0

High

10

Medium

Info

WordPress version 6.8.5 detected

Medium

Plugin 'lottier-wpbakery' v1.1.7: Lottier for WPBakery <= 1.1.7 - Missing Authorization

Medium

Plugin 'wc-product-table-lite' v4.6.2: Product Table and List Builder for WooCommerce Lite <= 4.6.2 - Unauthenticated Time-Based SQL Injection via 'search' Parameter

Medium

Plugin 'woocommerce' v10.3.5: WooCommerce - Arbitrary Admin User Creation via CSRF vulnerability

Medium

Plugin 'thegem-elements' v1.0: TheGem Theme Elements (for WPBakery) <= 5.11.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Medium

Plugin 'thegem-elements' v1.0: TheGem Theme Elements (for WPBakery) <= 5.10.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Medium

Plugin 'thegem-elements' v1.0: TheGem Theme Elements (for WPBakery) <= 5.10.5.1 - Unauthenticated Local File Inclusion

Info

WP_DEBUG is disabled (no PHP errors visible)

Info

PHP 8.4.19 detected (supported version)

Low

X-Powered-By header exposed: PHP/8.4.19 — reveals server software

How to fix: Hide X-Powered-By header. In php.ini set expose_php = Off, or add Header unset X-Powered-By to .htaccess.

Medium

Missing security header: X-Frame-Options -- Prevents clickjacking attacks

How to fix: Add to .htaccess: Header always set X-Frame-Options "SAMEORIGIN" — prevents clickjacking attacks.

Medium

Missing security header: X-Content-Type-Options -- Prevents MIME-type sniffing

How to fix: Add to .htaccess: Header always set X-Content-Type-Options "nosniff" — prevents MIME-type sniffing.

Medium

Missing security header: Strict-Transport-Security -- Enforces HTTPS connections

How to fix: Add to .htaccess or nginx: Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"

Info

Missing security header: Content-Security-Policy -- Controls resource loading

Info

Missing security header: Referrer-Policy -- Controls referrer information

Info

Missing security header: Permissions-Policy -- Controls browser feature access

Info

SSL certificate valid (71 days remaining) — issued by Let's Encrypt

Medium

HTTP does not redirect to HTTPS

How to fix: Add a redirect rule in .htaccess or your host's SSL settings to force HTTP → HTTPS.

Info

REST API user enumeration blocked

Info

No external scripts detected

Checked against 11 blacklist services

Spamhaus DBL
SURBL
URIBL
SpamEatingMonkey
Barracuda
SORBS
Invaluement
URLhaus
OpenPhish
Google Safe Browsing
VirusTotal (70+ engines)

Want to find hidden issues?

This surface scan checks what's publicly visible. A deep scan connects via SSH to check file integrity, database injections, and hidden backdoors.

Run Deep Scan — $1
Scan another site