Security Scan Results

https://interior.go.ke

Screenshot of https://interior.go.ke

interior.go.ke

F

Critical — Immediate Action Needed

36 issues detected

Scanned 3 months ago

36

Total

1

Critical

1

High

25

Medium

Medium

Plugin 'form-maker' v1.0.0: Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder [form-maker] < 1.15.20

Medium

Plugin 'form-maker' v1.0.0: Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder [form-maker] < 1.13.36

Medium

Plugin 'form-maker' v1.0.0: Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder [form-maker] < 1.6.6

Medium

Plugin 'form-maker' v1.0.0: Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder [form-maker] < 1.15.17

Medium

Plugin 'form-maker' v1.0.0: Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder [form-maker] < 1.15.20

Medium

Plugin 'form-maker' v1.0.0: Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder [form-maker] < 1.15.19

Medium

Plugin 'form-maker' v1.0.0: Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder [form-maker] < 1.15.20

Medium

Plugin 'form-maker' v1.0.0: Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder [form-maker] < 1.15.21

Medium

Plugin 'form-maker' v1.0.0: Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder [form-maker] < 1.13.40

Medium

Plugin 'form-maker' v1.0.0: Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder [form-maker] < 1.15.19

Medium

Plugin 'google-language-translator' v6.0.20: Translate WordPress &#8211; Google Language Translator [google-language-translator] < 6.0.20

Medium

Plugin 'google-language-translator' v6.0.20: Translate WordPress &#8211; Google Language Translator [google-language-translator] < 6.0.20

Medium

Plugin 'elementor' v0.2.1: Elementor Website Builder - Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template vulnerability

Medium

Plugin 'elementor' v0.2.1: Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 2.9.9 (closed)

Medium

Plugin 'elementor' v0.2.1: Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.1.4 (closed)

Medium

Plugin 'elementor' v0.2.1: Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 2.9.6 (closed)

Medium

Plugin 'elementor' v0.2.1: Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 2.9.14 (closed)

Medium

Plugin 'elementor' v0.2.1: Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 2.9.3 (closed)

Medium

Plugin 'elementor' v0.2.1: Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.1.4 (closed)

Medium

Plugin 'elementor' v0.2.1: Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 1.8.8 (closed)

Medium

Plugin 'elementor' v0.2.1: Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.0.14 (closed)

Medium

Plugin 'elementor' v0.2.1: Elementor Website Builder &#8211; More Than Just a Page Builder [elementor] < 3.1.4 (closed)

High

SSL certificate error -- site may have an invalid or expired certificate

Info

WP_DEBUG is disabled (no PHP errors visible)

Medium

Missing security header: X-Frame-Options -- Prevents clickjacking attacks

How to fix: Add to .htaccess: Header always set X-Frame-Options "SAMEORIGIN" — prevents clickjacking attacks.

Medium

Missing security header: X-Content-Type-Options -- Prevents MIME-type sniffing

How to fix: Add to .htaccess: Header always set X-Content-Type-Options "nosniff" — prevents MIME-type sniffing.

Medium

Missing security header: Strict-Transport-Security -- Enforces HTTPS connections

How to fix: Add to .htaccess or nginx: Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"

Info

Missing security header: Content-Security-Policy -- Controls resource loading

Info

Missing security header: Referrer-Policy -- Controls referrer information

Info

Missing security header: Permissions-Policy -- Controls browser feature access

Info

SSL certificate valid (59 days remaining) — issued by eMudhra Technologies Limited

Info

HTTP correctly redirects to HTTPS

Low

External JS from popular domain: translate.google.com (Tranco rank #1)

How to fix: This script is from a well-known domain (ranked in the top 100K globally). Likely legitimate, but verify it matches a service you intentionally added.

Low

External JS from popular domain: www.skynettechnologies.com (Tranco rank #37,266)

How to fix: This script is from a well-known domain (ranked in the top 100K globally). Likely legitimate, but verify it matches a service you intentionally added.

Low

2 external script(s) from popular domains (Tranco top 100K): www.skynettechnologies.com, translate.google.com

How to fix: These scripts are from globally popular domains. They are very likely legitimate services but were not in our curated whitelist.

Checked against 11 blacklist services

Spamhaus DBL
SURBL
URIBL
SpamEatingMonkey
Barracuda
SORBS
Invaluement
URLhaus
OpenPhish
Google Safe Browsing
VirusTotal (70+ engines)

How to fix: Your site is flagged as malicious. Request a review at Google Search Console after cleaning up.

Your site needs immediate attention

We found critical security issues. Our experts can clean your site and fix all vulnerabilities within 24 hours.

Get Expert Cleanup — $49
Scan another site