Security Scan Results

https://foodbanksmississauga.ca

C

Fair — Some Issues Found

19 issues detected

Scanned 4 months ago

19

Total

0

Critical

0

High

9

Medium

Medium

Plugin 'google-language-translator' v6.0.20: Google Language Translator < 6.0.20 - Missing Authorization to Notice Dismissal

Medium

Plugin 'svg-support' v2.5.8: SVG Support <= 2.5.10 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

Medium

Plugin 'svg-support' v2.5.8: SVG Support <= 2.5.8 - Stored Cross-Site Scripting via Vulnerability Dependency

Medium

Plugin 'svg-support' v2.5.8: SVG Support < 2.5.8 - Author+ Cross-Site Scripting via SVG

Info

WP_DEBUG is disabled (no PHP errors visible)

Medium

Missing security header: X-Frame-Options -- Prevents clickjacking attacks

How to fix: Add to .htaccess: Header always set X-Frame-Options "SAMEORIGIN" — prevents clickjacking attacks.

Medium

Missing security header: X-Content-Type-Options -- Prevents MIME-type sniffing

How to fix: Add to .htaccess: Header always set X-Content-Type-Options "nosniff" — prevents MIME-type sniffing.

Medium

Missing security header: Strict-Transport-Security -- Enforces HTTPS connections

How to fix: Add to .htaccess or nginx: Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"

Info

Missing security header: Content-Security-Policy -- Controls resource loading

Info

Missing security header: Referrer-Policy -- Controls referrer information

Info

Missing security header: Permissions-Policy -- Controls browser feature access

Info

SSL certificate valid (83 days remaining) — issued by Let's Encrypt

Medium

HTTP redirect does not point to HTTPS

How to fix: Add a redirect rule in .htaccess or your host's SSL settings to force HTTP → HTTPS.

Medium

User enumeration possible via REST API -- found: candybox, daisythemississaugafoodbank-org, jenna, kate-carveth, meghannicholls

How to fix: Disable the REST API users endpoint with a plugin like Disable REST API or add a filter to block /wp/v2/users.

Low

External JS from popular domain: translate.google.com (Tranco rank #1)

How to fix: This script is from a well-known domain (ranked in the top 100K globally). Likely legitimate, but verify it matches a service you intentionally added.

Low

External JS from popular domain: static.mobilemonkey.com (Tranco rank #68,367)

How to fix: This script is from a well-known domain (ranked in the top 100K globally). Likely legitimate, but verify it matches a service you intentionally added.

Info

1 trusted external script(s): www.google.com (Google)

Low

2 external script(s) from popular domains (Tranco top 100K): translate.google.com, static.mobilemonkey.com

How to fix: These scripts are from globally popular domains. They are very likely legitimate services but were not in our curated whitelist.

Checked against 11 blacklist services

Spamhaus DBL
SURBL
URIBL
SpamEatingMonkey
Barracuda
SORBS
Invaluement
URLhaus
OpenPhish
Google Safe Browsing
VirusTotal (70+ engines)

Want to find hidden issues?

This surface scan checks what's publicly visible. A deep scan connects via SSH to check file integrity, database injections, and hidden backdoors.

Run Deep Scan — $1
Scan another site