Security Scan Results

https://preprod.agencelec.fr

Screenshot of https://preprod.agencelec.fr

preprod.agencelec.fr

C

Fair — Some Issues Found

27 issues detected

Scanned 4 months ago

27

Total

0

Critical

0

High

14

Medium

Info

WordPress version 6.9.1 detected

Medium

Plugin 'elementor' v1.0.0: Elementor < 3.1.4 - Authenticated Stored Cross-Site Scripting (XSS) in Image Box Widget

Medium

Plugin 'elementor' v1.0.0: Elementor < 3.1.4 - Authenticated Stored Cross-Site Scripting (XSS) in Column Element

Medium

Plugin 'elementor' v1.0.0: Elementor < 3.1.4 - Authenticated Stored Cross-Site Scripting (XSS) in Heading Widget

Medium

Plugin 'elementor' v1.0.0: Elementor < 3.1.4 - Authenticated Stored Cross-Site Scripting (XSS) in Divider Widget

Medium

Plugin 'elementor' v1.0.0: Elementor < 3.1.4 - Authenticated Stored Cross-Site Scripting (XSS) in Accordion Widget

Medium

Plugin 'elementor' v1.0.0: Elementor < 3.1.4 - Authenticated Stored Cross-Site Scripting (XSS) in Icon Box Widget

Medium

Plugin 'elementor' v1.0.0: Elementor Website Builder < 3.12.2 - Admin+ SQLi

Medium

Plugin 'elementor' v1.0.0: Elementor < 3.5.6 - DOM Reflected Cross-Site Scripting

Medium

Plugin 'elementor' v1.0.0: Elementor Page Builder < 2.8.4 - Cross-Site Scripting (XSS)

Medium

Plugin 'mousewheel-smooth-scroll' v1.1.19: MouseWheel Smooth Scroll <= 5.6 - Plugin's Setting Update via Cross-Site Request Forgery

Info

WP_DEBUG is disabled (no PHP errors visible)

Medium

Missing security header: X-Content-Type-Options -- Prevents MIME-type sniffing

How to fix: Add to .htaccess: Header always set X-Content-Type-Options "nosniff" — prevents MIME-type sniffing.

Medium

Missing security header: Strict-Transport-Security -- Enforces HTTPS connections

How to fix: Add to .htaccess or nginx: Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"

Info

Missing security header: Content-Security-Policy -- Controls resource loading

Info

Missing security header: Referrer-Policy -- Controls referrer information

Info

Missing security header: Permissions-Policy -- Controls browser feature access

Info

1 of 6 security headers configured

Info

SSL certificate valid (71 days remaining) — issued by Let's Encrypt

Info

HTTP correctly redirects to HTTPS

Info

WordPress readme exposed (version info)

/readme.html

Info

WordPress license file exposed

/license.txt

Medium

User enumeration possible via REST API -- found: ad-agencelec

How to fix: Disable the REST API users endpoint with a plugin like Disable REST API or add a filter to block /wp/v2/users.

Low

wp-cron.php is publicly accessible (potential DDoS vector)

/wp-cron.php

How to fix: Disable WP-Cron in wp-config.php with define("DISABLE_WP_CRON", true) and use a real server cron job instead.

Medium

Suspicious inline JavaScript: heavy unicode-escaped strings (9000 occurrences)

How to fix: Inspect this inline JavaScript carefully — obfuscated code can indicate malware injection.

Info

No external scripts detected

Checked against 11 blacklist services

Spamhaus DBL
SURBL
URIBL
SpamEatingMonkey
Barracuda
SORBS
Invaluement
URLhaus
OpenPhish
Google Safe Browsing
VirusTotal (70+ engines)

Want to find hidden issues?

This surface scan checks what's publicly visible. A deep scan connects via SSH to check file integrity, database injections, and hidden backdoors.

Run Deep Scan — $1
Scan another site