https://www.bcn.nl
Scan complete
www.bcn.nl
14 issues detected
Scanned 4 weeks ago
14
Total
0
Critical
0
High
1
Medium
WP_DEBUG is disabled (no PHP errors visible)
PHP 8.3.30 detected (supported version)
X-Powered-By header exposed: PHP/8.3.30 — reveals server software
How to fix: Hide X-Powered-By header. In php.ini set expose_php = Off, or add Header unset X-Powered-By to .htaccess.
Missing security header: Permissions-Policy -- Controls browser feature access
5 of 6 security headers configured
SSL certificate valid (67 days remaining) — issued by Google Trust Services
HTTP correctly redirects to HTTPS
Cookies missing security flags (HttpOnly): pll_language
How to fix: Set cookie security flags in wp-config.php: @ini_set("session.cookie_httponly", 1); @ini_set("session.cookie_secure", 1); @ini_set("session.cookie_samesite", "Lax");
WordPress license file exposed
/license.txt
REST API user enumeration blocked
wp-cron.php is publicly accessible (potential DDoS vector)
/wp-cron.php
How to fix: Disable WP-Cron in wp-config.php with define("DISABLE_WP_CRON", true) and use a real server cron job instead.
External JS from popular domain: cmp.osano.com (Tranco rank #3,790)
How to fix: This script is from a well-known domain (ranked in the top 100K globally). Likely legitimate, but verify it matches a service you intentionally added.
1 external script(s) from popular domains (Tranco top 100K): cmp.osano.com
How to fix: These scripts are from globally popular domains. They are very likely legitimate services but were not in our curated whitelist.
Checked against 11 blacklist services
Your site passed the surface scan. For complete peace of mind, a deep scan checks file integrity, database injections, and hidden backdoors at the server level.
Run Deep Scan — $1