blogvault.net
Scanned May 19, 2026, 07:44 AM
Run a fresh audit — UpgradeSecurity Assessment
Key findings for blogvault.net
- 5 active vulnerabilities detected across 5 plugins.
- 1 plugin is outdated and should be updated.
- 1 plugin has been abandoned by the developer.
- 3 sensitive paths exposed to the public.
WordPress
Active Theme
Hosting Provider
Detected Plugins
5 total| Plugin | Vulnerabilities |
|---|---|
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor high confidence | |
Star Rating Block high confidence | None found |
Brevo – Email, SMS, Web Push, Chat, and more. medium confidence | None found |
kadence-conversions medium confidence | None found |
kadence-pro medium confidence | None found |
Unlock the full security analysis
Get the full breakdown of your site's security posture:
Security Report
- Full report for this site
- Every detected plugin & CVE
- Remediation guidance
- No re-audit after fixes
Report + Re-audit
- Everything in Security Report
- One complimentary re-audit within 90 days
- Verify your fixes actually closed the findings
- Clean-record badge for your site
Guided Remediation
- Everything in Report + Re-audit
- 15–30 min expert consult to triage findings
- Prioritized action plan for your site
- Optional partner handoff for fixes
One-time payment · Instant access · No subscription required
Not ready to buy? We'll send you a one-time free alert
if we detect a new vulnerability affecting your plugins.
One free alert · Continuous monitoring available with a paid plan
Security Posture
Security Headers
86/100No Content-Security-Policy header. Your site is more vulnerable to XSS attacks.
HSTS is enabled. Consider adding includeSubDomains for better protection.
Clickjacking protection is enabled.
TLS/SSL Certificate
Exposed Paths & Login Security
3 exposed3 security issues found — unlock to see which paths are exposed.
DNS & Email Security
SPF record with hard fail (-all) — strong email authentication.
DMARC policy is set to none — monitoring only, not enforcing.
DKIM record found for selector "google". Email signatures can be verified.
Certificate Transparency
548 certificates found · 16 subdomains discovered
Infrastructure
Server: nginx
X-Powered-By header is not exposed.
No WAF detected. Consider adding one for additional protection.
WordPress version 6.8.3 is exposed in the generator meta tag. Consider removing it.