html
| # | Finding | Severity | Remediation effort |
|---|---|---|---|
| 1 | Debug log publicly accessible (612 MB) | 🔴 urgent | 5 minutes |
| 2 | Plugin with known vulnerability (CVE-2026-08151*) | 🔴 urgent | 10 minutes |
| 3 | Editorial team enumerable via API (3 names) | 🟠 medium | 15 minutes |
| 4 | XML-RPC enabled, no login lockout | 🟠 medium | 10 minutes |
| 5 | DMARC not enforced (p=none) | ⚪ info | 15 minutes |
| 6 | Security headers missing | ⚪ info | 5 minutes |
Overall impression: A fundamentally solid TLS configuration and an up-to-date CMS version. You should close two findings this week: they fall into the category of “an attacker can find this with two clicks from outside”. Both can be remediated in under 15 minutes.
Your error log is publicly available on the web. Anyone , even without logging in , can download it. It contains complete file paths on your server, PHP error messages with line numbers and parts of the internal plugin structure. On shared hosting, this is the map for the next step of an attack. In addition: with 612 MB of pull volume per request, you risk your transfer volume quotas.
wp-config.php replace the following:define('WP_DEBUG', false);
define('WP_DEBUG_DISPLAY', false);
define('WP_DEBUG_LOG', false);
⏱ Effort: approx. 5 minutes · We will verify the fix for you free of charge.
The plugin “Newsletter Pro” in version 9.3.3 has a publicly documented vulnerability (CVSS 7.1): When newsletter forms are displayed, scripts can be injected and executed without authentication. Your installed version can be clearly identified from the public version file.
The interface of your CMS outputs all user accounts with slug and display name. Attackers use exactly this list as a target register for targeted phishing e-mails and password-spray attacks.
XML-RPC is enabled with “multicall”: this allows hundreds of login attempts to be bundled into a single request. As your login page also does not display a failure limit, there is currently no effective login throttling.
.htaccess:<Files "xmlrpc.php"> Require all denied </Files>⏱ Effort: 10 minutes
SPF and DKIM are present and correct. However, the DMARC policy is set to “none” , spoofed emails in your company name would not be blocked as forgeries by the recipient. Recommendation: after a monitoring phase, change to p=quarantine instead.
X-Content-Type-Options, X-Frame-Options and Referrer-Policy are missing. Individually minor, together they significantly hinder click-based attacks and MIME confusion. Four lines in the .htaccess file are sufficient.
TLS 1.3 with a strong cipher suite · TLS 1.0/1.1 rejected · Certificate valid until 18.02.2027 (automatic renewal detected) · HSTS active · Clean HTTP-to-HTTPS redirect · No backup traces (26 standard paths checked) · No directory listings · uploads/includes protected · CMS core up to date · SPF+DKIM present · 9 of 15 test groups passed without findings.
Run a real scan: the basic result is free. You receive the detailed report with all fix snippets for 99 €. You only pay if we actually find something.
Start free scanThis demo report uses fictional data only. This page does not set cookies and does not load third-party scripts.