https://www.planning.go.ke
Scan complete
www.planning.go.ke
64 issues detected
Scanned 3 months ago
64
Total
1
Critical
2
High
50
Medium
WordPress version 5.5.14 detected
Plugin 'contact-form-7' v5.3.2: Contact Form 7 <= 6.0.5 - Order Replay Vulnerability
Plugin 'contact-form-7' v5.3.2: Contact Form 7 <= 5.8.3 - Authenticated (Editor+) Arbitrary File Upload
Plugin 'contact-form-7' v5.3.2: Contact Form 7 <= 5.9.4 - Unauthenticated Open Redirect
Plugin 'contact-form-7' v5.3.2: Contact Form 7 <= 5.3.1 - Arbitrary File Upload via Bypass
Plugin 'contact-form-7' v5.3.2: Contact Form 7 <= 5.9 - Reflected Cross-Site Scripting
Plugin 'revslider' v6.2.18: Slider Revolution < 6.7.11 - Authenticated (Author+) Stored Cross-Site Scripting via Add Layer class, id, and title Attributes
Plugin 'revslider' v6.2.18: Revolution Slider <= 6.6.12 - Author+ Remote Code Execution
Plugin 'revslider' v6.2.18: Slider Revolution < 6.6.15 - Authenticated (Contributor+) Stored Cross-Site Scripting
Plugin 'revslider' v6.2.18: Slider Revolution < 6.6.16 - Authenticated (Author+) Arbitrary File Upload
Plugin 'revslider' v6.2.18: Slider Revolution < 6.6.19 - Author+ Insecure Deserialization leading to RCE
Plugin 'revslider' v6.2.18: Revslider < 6.7.0 - Authenticated (Author+) Stored Cross-Site Scripting
Plugin 'revslider' v6.2.18: Slider Revolution < 6.7.8 - Authenticated (Author+) Stored Cross-Site Scripting via htmltag Parameter
Plugin 'revslider' v6.2.18: Slider Revolution < 6.7.37 - Authenticated (Contributor+) Arbitrary File Read via 'used_svg' and 'used_images'
Plugin 'simple-file-list' v5.5.14: Simple File List [simple-file-list] < 6.0.10
Plugin 'simple-file-list' v5.5.14: Simple File List [simple-file-list] < 6.1.10
Plugin 'pojo-accessibility' v1.0.0: Ally - WordPress Ally - Web Accessibility & Usability plugin <= 4.0.3 - Unauthenticated SQL Injection via URL Path vulnerability
Plugin 'pojo-accessibility' v1.0.0: One Click Accessibility <= 3.1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
Plugin 'pojo-accessibility' v1.0.0: Ally <= 4.0.2 - Missing Authorization
Plugin 'pojo-accessibility' v1.0.0: Ally - Web Accessibility & Usability <= 3.8.0 - Cross-Site Request Forgery to Plugin Settings Update
Plugin 'pojo-accessibility' v1.0.0: One Click Accessibility < 3.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
Plugin 'pojo-accessibility' v1.0.0: Ally - Web Accessibility & Usability < 3.8.1 - Cross-Site Request Forgery to Plugin Settings Update
Plugin 'pojo-accessibility' v1.0.0: Ally < 4.0.3 - Missing Authorization
Plugin 'pojo-accessibility' v1.0.0: Ally < 4.1.0 - Unauthenticated SQLi via URL Path
Plugin 'tablepress' v1.12: TablePress <= 1.14 - Authenticated (Author+) CSV Injection
Plugin 'tablepress' v1.12: TablePress <= 3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode_debug Parameter
Plugin 'tablepress' v1.12: PHPSpreadsheet Library < 2.3.0 - XXE Injection
Plugin 'tablepress' v1.12: TablePress – Tables in WordPress made easy <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
Plugin 'tablepress' v1.12: TablePress – Tables in WordPress made easy <= 2.3 - Authenticated (Author+) Server-Side Request Forgery via DNS Rebind
Plugin 'tablepress' v1.12: TablePress <= 2.2.4 - Authenticated(Author+) Server Side Request Forgery(SSRF) via _get_import_files
Plugin 'tablepress' v1.12: TablePress <= 3.1.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Multiple Parameters
Plugin 'tablepress' v1.12: TablePress – Tables in WordPress made easy <= 3.0.4 - Authenticated (Author+) Stored Cross-Site Scripting
Plugin 'tablepress' v1.12: TablePress <= 2.4.2 - Authenticated (Author+) Stored Cross-Site Scripting
Plugin 'js_composer' v6.2.0: WPBakery Page Builder < 8.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
Plugin 'js_composer' v6.2.0: WPBakery [js_composer] < 7.6
Plugin 'js_composer' v6.2.0: WPBakery [js_composer] < 6.13.0
Plugin 'js_composer' v6.2.0: WPBakery [js_composer] < 6.4.1
Plugin 'js_composer' v6.2.0: WPBakery Page Builder for WordPress < 8.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
Plugin 'js_composer' v6.2.0: WPBakery Page Builder < 8.5 - Authenticated (Author+) Stored Cross-Site Scripting via Grid Builder
Plugin 'js_composer' v6.2.0: WPBakery Page Builder < 8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Page Builder Elements
Theme 'porto' v5.5.1: Porto - Reflected Cross Site Scripting (XSS) vulnerability
Theme 'porto' v5.5.1: Porto <= 7.1.0 - Authenticated (Contributor+) Local File Inclusion via Post Meta
Theme 'porto' v5.5.1: Porto <= 7.1.0 - Unauthenticated Local File Inclusion via porto_ajax_posts
Theme 'porto' v5.5.1: Porto <= 7.6.2 - Reflected Cross-Site Scripting
WP_DEBUG is disabled (no PHP errors visible)
PHP 7.3.33 detected — end of life, no security updates
How to fix: Upgrade PHP to 8.2+ via your hosting control panel. Outdated PHP receives no security patches.
X-Powered-By header exposed: PHP/7.3.33 — reveals server software
How to fix: Hide X-Powered-By header. In php.ini set expose_php = Off, or add Header unset X-Powered-By to .htaccess.
Missing security header: X-Frame-Options -- Prevents clickjacking attacks
How to fix: Add to .htaccess: Header always set X-Frame-Options "SAMEORIGIN" — prevents clickjacking attacks.
Missing security header: X-Content-Type-Options -- Prevents MIME-type sniffing
How to fix: Add to .htaccess: Header always set X-Content-Type-Options "nosniff" — prevents MIME-type sniffing.
Missing security header: Strict-Transport-Security -- Enforces HTTPS connections
How to fix: Add to .htaccess or nginx: Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"
Missing security header: Content-Security-Policy -- Controls resource loading
Missing security header: Referrer-Policy -- Controls referrer information
Missing security header: Permissions-Policy -- Controls browser feature access
SSL certificate valid (231 days remaining) — issued by eMudhra Technologies Limited
HTTP correctly redirects to HTTPS
Cookies missing security flags (SameSite): __wpdm_client
How to fix: Set cookie security flags in wp-config.php: @ini_set("session.cookie_httponly", 1); @ini_set("session.cookie_secure", 1); @ini_set("session.cookie_samesite", "Lax");
Directory listing enabled: /wp-content/uploads/
/wp-content/uploads/
How to fix: Add "Options -Indexes" to your .htaccess file to prevent directory browsing.
User enumeration possible via REST API -- found: agacanja, fmiriti, mipango-akiba, pkibira
How to fix: Disable the REST API users endpoint with a plugin like Disable REST API or add a filter to block /wp/v2/users.
wp-cron.php is publicly accessible (potential DDoS vector)
/wp-cron.php
How to fix: Disable WP-Cron in wp-config.php with define("DISABLE_WP_CRON", true) and use a real server cron job instead.
Suspicious inline JavaScript: String.fromCharCode obfuscation
How to fix: Inspect this inline JavaScript carefully — obfuscated code can indicate malware injection.
Unknown external JavaScript from: checkitoutxx.com
How to fix: Review this script source. If it's legitimate (analytics, chat widget), no action needed. If unknown, investigate and remove.
1 trusted external script(s): www.google.com (Google)
Found 1 unknown external JS source(s): checkitoutxx.com
Checked against 11 blacklist services
We found critical security issues. Our experts can clean your site and fix all vulnerabilities within 24 hours.
Get Expert Cleanup — $49