New audit

dechambersclub.com

Scanned Apr 6, 2026, 09:32 PM

Re-scan — Upgrade
92
A · Safe
25
Plugins Detected
2
Active Vulnerabilities
1
Outdated Plugins
0
Abandoned

Security Assessment

Key findings for dechambersclub.com

  • 2 active vulnerabilityies detected across 25 plugins.
  • 1 plugin is outdated and should be updated.
  • Security headers grade F — 3 important headers are missing.
  • Active theme "aardvark" has 1 known vulnerability.

WordPress

Version 6.9.4
Core installation

Active Theme

aardvark v4.6
Up to date1 active vuln

Hosting Provider

WordPress.com (Automattic)
Infrastructure

Detected Plugins

25 total
PluginVulnerabilities
None found
BuddyPress
BuddyPress
high confidence
None found
None found
bbPress
bbPress
high confidence
None found
Gutenberg
Gutenberg
high confidence
None found
1 vulnerability found in 20 hidden plugins

Your full security report is ready

We found 25 plugins on this site. Unlock the complete analysis:

All 25 detected plugins
CVE details & patch status
Security header analysis
Exposed paths & TLS audit
DNS & email security
CT log subdomain discovery

One-time payment · Instant access · No subscription required

Not ready to buy? We'll send you a one-time free alert

if we detect a new vulnerability affecting your plugins.

One free alert · Continuous monitoring available with a paid plan

Security Posture

F
Security Headers
A
TLS/SSL
A
Exposed Paths
B
Email Security

Security Headers

33/100
Content-Security-Policy

CSP is configured, helping prevent XSS and injection attacks.

Strict-Transport-Security

No HSTS header. Browsers can be tricked into using insecure HTTP connections.

X-Frame-Options

No clickjacking protection. Your site can be embedded in malicious iframes.

3 more checks — unlock full report to see all

TLS/SSL Certificate

Issuer
R12
Expires
85 days
Protocol
TLSv1.3
Wildcard
No

Exposed Paths & Login Security

0 exposed

No critical paths exposed. Unlock for the full breakdown.

DNS & Email Security

SPF

SPF record with soft fail (~all) — good email authentication.

DMARC

DMARC policy is set to none — monitoring only, not enforcing.

DKIM

No DKIM record found for common selectors. Email authenticity cannot be verified (or uses a non-standard selector).

Certificate Transparency

16 certificates found · 1 subdomains discovered

Infrastructure

Server Software

Server: LiteSpeed

X-Powered-By

Technology stack exposed: PHP/8.2.27. This header should be removed.

PHP Version

PHP 8.2.27 is supported.

Web Application Firewall

No WAF detected. Consider adding one for additional protection.

WP Version Exposed

WordPress version 6.9.4 is exposed in the generator meta tag. Consider removing it.