https://tommyelectronics.pl
Scan complete
tommyelectronics.pl
29 issues detected
Scanned 1 month ago
29
Total
0
Critical
0
High
18
Medium
Plugin 'contact-form-7' v5.7.7: Contact Form 7 < 6.0.6 - Order Replay Vulnerability
Plugin 'contact-form-7' v5.7.7: Contact Form 7 [contact-form-7] < 5.9.5
Plugin 'contact-form-7' v5.7.7: Contact Form 7 [contact-form-7] < 5.9.2
Plugin 'contact-form-7' v5.7.7: Contact Form 7 [contact-form-7] < 5.8.4
Plugin 'elementor' v3.14.1: Elementor Website Builder - Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template vulnerability
Plugin 'cookie-notice' v2.4.9: Cookie Notice & Compliance for GDPR / CCPA <= 2.5.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Plugin 'cookie-notice' v2.4.9: Cookie Notice & Compliance for GDPR / CCPA <= 2.5.8 - Authenticated (Author+) Stored Cross-Site Scripting
Plugin 'cookie-notice' v2.4.9: Cookie Notice & Compliance for GDPR / CCPA <= 2.4.17.1 - Authenticated (Admin+) Stored Cross-Site Scripting
Plugin 'cookie-notice' v2.4.9: Cookie Notice & Compliance for GDPR / CCPA [cookie-notice] < 2.4.18 (closed)
Plugin 'elementor-pro' v3.14.1: Elementor Website Builder Pro – More than Just a Page Builder < 3.25.11 - Authenticated (Contributor+) Sensitive Information Exposure via Shortcode
Plugin 'elementor-pro' v3.14.1: Elementor Website Builder Pro < 3.21.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
Plugin 'elementor-pro' v3.14.1: Elementor Pro < 3.21.3 - Reflected Cross-Site Scripting
Plugin 'cf7-repeatable-fields' v1.1.1: Contact Form 7 - Repeatable Fields <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via field_group Shortcode
Plugin 'cf7-repeatable-fields' v1.1.1: Contact Form 7 – Repeatable Fields [cf7-repeatable-fields] < 2.0.2
WP_DEBUG is disabled (no PHP errors visible)
Missing security header: X-Frame-Options -- Prevents clickjacking attacks
How to fix: Add to .htaccess: Header always set X-Frame-Options "SAMEORIGIN" — prevents clickjacking attacks.
Missing security header: X-Content-Type-Options -- Prevents MIME-type sniffing
How to fix: Add to .htaccess: Header always set X-Content-Type-Options "nosniff" — prevents MIME-type sniffing.
Missing security header: Strict-Transport-Security -- Enforces HTTPS connections
How to fix: Add to .htaccess or nginx: Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"
Missing security header: Content-Security-Policy -- Controls resource loading
Missing security header: Referrer-Policy -- Controls referrer information
Missing security header: Permissions-Policy -- Controls browser feature access
SSL certificate valid (46 days remaining) — issued by Let's Encrypt
HTTP correctly redirects to HTTPS
Cookies missing security flags (HttpOnly): pll_language
How to fix: Set cookie security flags in wp-config.php: @ini_set("session.cookie_httponly", 1); @ini_set("session.cookie_secure", 1); @ini_set("session.cookie_samesite", "Lax");
WordPress license file exposed
/license.txt
REST API user enumeration blocked
wp-cron.php is publicly accessible (potential DDoS vector)
/wp-cron.php
How to fix: Disable WP-Cron in wp-config.php with define("DISABLE_WP_CRON", true) and use a real server cron job instead.
No external scripts detected
Checked against 11 blacklist services
We found critical security issues. Our experts can clean your site and fix all vulnerabilities within 24 hours.
Get Expert Cleanup — $49