https://naylinoo.infinityfree.me
Scan complete
naylinoo.infinityfree.me
20 issues detected
Scanned 1 month ago
20
Total
4
Critical
1
High
5
Medium
WP_DEBUG is disabled (no PHP errors visible)
Missing security header: X-Frame-Options -- Prevents clickjacking attacks
How to fix: Add to .htaccess: Header always set X-Frame-Options "SAMEORIGIN" — prevents clickjacking attacks.
Missing security header: X-Content-Type-Options -- Prevents MIME-type sniffing
How to fix: Add to .htaccess: Header always set X-Content-Type-Options "nosniff" — prevents MIME-type sniffing.
Missing security header: Strict-Transport-Security -- Enforces HTTPS connections
How to fix: Add to .htaccess or nginx: Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"
Missing security header: Content-Security-Policy -- Controls resource loading
Missing security header: Referrer-Policy -- Controls referrer information
Missing security header: Permissions-Policy -- Controls browser feature access
SSL certificate expires in 21 days
How to fix: Your SSL certificate expires soon. Set up auto-renewal or renew manually.
HTTP does not redirect to HTTPS
How to fix: Add a redirect rule in .htaccess or your host's SSL settings to force HTTP → HTTPS.
Debug log exposed
/wp-content/debug.log
WordPress readme exposed (version info)
/readme.html
WordPress license file exposed
/license.txt
Database backup file exposed
/backup.sql
How to fix: Delete this backup file immediately — it may contain database credentials or sensitive data.
Database dump file exposed
/database.sql
How to fix: Delete this backup file immediately — it may contain database credentials or sensitive data.
Database dump file exposed
/dump.sql
How to fix: Delete this backup file immediately — it may contain database credentials or sensitive data.
Database dump file exposed
/db.sql
How to fix: Delete this backup file immediately — it may contain database credentials or sensitive data.
REST API user enumeration blocked
wp-cron.php is publicly accessible (potential DDoS vector)
/wp-cron.php
How to fix: Disable WP-Cron in wp-config.php with define("DISABLE_WP_CRON", true) and use a real server cron job instead.
No external scripts detected
Checked against 11 blacklist services
We found critical security issues. Our experts can clean your site and fix all vulnerabilities within 24 hours.
Get Expert Cleanup — $49