Security Scan Results

https://helpcode.org

Screenshot of https://helpcode.org

helpcode.org

C

Fair — Some Issues Found

26 issues detected

Scanned 4 months ago

26

Total

0

Critical

0

High

14

Medium

Medium

Plugin 'give' v2.30.0: GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 3.20.0

Medium

Plugin 'give' v2.30.0: GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 4.6.1

Medium

Plugin 'give' v2.30.0: GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 4.6.1

Medium

Plugin 'give' v2.30.0: GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 4.6.0

Medium

Plugin 'give' v2.30.0: GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 4.3.1

Medium

Plugin 'give' v2.30.0: GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 3.22.2

Medium

Plugin 'give' v2.30.0: GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 3.22.1

Medium

Plugin 'give' v2.30.0: GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 3.16.2

Medium

Plugin 'give' v2.30.0: GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 3.16.4

Medium

Plugin 'give' v2.30.0: GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 3.19.0

Medium

Plugin '3d-flipbook-dflip-lite' v2.3.65: Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer <= 2.3.65 - DOM-Based Reflected Cross-Site Scripting via 'pdf-source'

Info

WP_DEBUG is disabled (no PHP errors visible)

Info

Missing security header: Content-Security-Policy -- Controls resource loading

Info

Missing security header: Referrer-Policy -- Controls referrer information

Info

Missing security header: Permissions-Policy -- Controls browser feature access

Info

3 of 6 security headers configured

Info

SSL certificate valid (82 days remaining) — issued by Google Trust Services

Info

HTTP correctly redirects to HTTPS

Medium

Cookies missing security flags (HttpOnly): pll_language

How to fix: Set cookie security flags in wp-config.php: @ini_set("session.cookie_httponly", 1); @ini_set("session.cookie_secure", 1); @ini_set("session.cookie_samesite", "Lax");

Medium

User enumeration possible via REST API -- found: adele-daniele, adima, alessandro-grassini, alessia-arcolaci, andreaschiano

How to fix: Disable the REST API users endpoint with a plugin like Disable REST API or add a filter to block /wp/v2/users.

Low

wp-cron.php is publicly accessible (potential DDoS vector)

/wp-cron.php

How to fix: Disable WP-Cron in wp-config.php with define("DISABLE_WP_CRON", true) and use a real server cron job instead.

Low

External JS from popular domain: ecommerce.nexi.it (Tranco rank #33,979)

How to fix: This script is from a well-known domain (ranked in the top 100K globally). Likely legitimate, but verify it matches a service you intentionally added.

Medium

Suspicious inline JavaScript: heavy unicode-escaped strings (78 occurrences)

How to fix: Inspect this inline JavaScript carefully — obfuscated code can indicate malware injection.

Info

1 trusted external script(s): www.google.com (Google)

Low

1 external script(s) from popular domains (Tranco top 100K): ecommerce.nexi.it

How to fix: These scripts are from globally popular domains. They are very likely legitimate services but were not in our curated whitelist.

Checked against 11 blacklist services

Spamhaus DBL
SURBL
URIBL
SpamEatingMonkey
Barracuda
SORBS
Invaluement
URLhaus
OpenPhish
Google Safe Browsing
VirusTotal (70+ engines)

Want to find hidden issues?

This surface scan checks what's publicly visible. A deep scan connects via SSH to check file integrity, database injections, and hidden backdoors.

Run Deep Scan — $1
Scan another site