bodymass.gr
Scanned May 16, 2026, 09:02 AM
Run a fresh audit — UpgradeSecurity Assessment
Key findings for bodymass.gr
- No known vulnerabilities detected in installed plugins.
- 41 plugins have been abandoned by the developer.
- 1 sensitive path exposed to the public.
WordPress
Active Theme
Hosting Provider
Detected Plugins
50 total| Plugin | Vulnerabilities |
|---|---|
Slek Gateway for WooCommerce medium confidence | None found |
Gallery Carousel Without JetPack medium confidence | None found |
Slim Jetpack medium confidence | None found |
Viva Payments – Viva Wallet WooCommerce Payment Gateway medium confidence | None found |
Payment Integration Wompi – El Salvador medium confidence | None found |
Your full security report is ready
We found 50 plugins on this site. Unlock the complete analysis:
Security Report
- Full report for this site
- Every detected plugin & CVE
- Remediation guidance
- No re-audit after fixes
Report + Re-audit
- Everything in Security Report
- One complimentary re-audit within 90 days
- Verify your fixes actually closed the findings
- Clean-record badge for your site
Guided Remediation
- Everything in Report + Re-audit
- 15–30 min expert consult to triage findings
- Prioritized action plan for your site
- Optional partner handoff for fixes
One-time payment · Instant access · No subscription required
Not ready to buy? We'll send you a one-time free alert
if we detect a new vulnerability affecting your plugins.
One free alert · Continuous monitoring available with a paid plan
Security Posture
Security Headers
79/100No Content-Security-Policy header. Your site is more vulnerable to XSS attacks.
HSTS is enabled. Consider adding includeSubDomains for better protection.
Clickjacking protection is enabled.
TLS/SSL Certificate
Exposed Paths & Login Security
1 exposed1 security issues found — unlock to see which paths are exposed.
DNS & Email Security
SPF record with hard fail (-all) — strong email authentication.
DMARC policy is set to quarantine — good protection against spoofing.
DKIM record found for selector "default". Email signatures can be verified.
Infrastructure
Server: LiteSpeed
X-Powered-By header is not exposed.
No WAF detected. Consider adding one for additional protection.