metallikaari.fi
Scanned Apr 19, 2026, 12:11 PM
Run a fresh audit — UpgradeSecurity Assessment
Key findings for metallikaari.fi
- No known vulnerabilities detected in installed plugins.
- 1 plugin is outdated and should be updated.
- 2 plugins have been abandoned by the developer.
- Security headers grade F — 4 important headers are missing.
- 1 sensitive path exposed to the public.
WordPress
Active Theme
Hosting Provider
Detected Plugins
11 total| Plugin | Vulnerabilities |
|---|---|
Elementor Website Builder – more than just a page builder high confidence | None found |
| None found | |
Xtoool Redirecter medium confidence | None found |
Search with Algolia Headless extention medium confidence | None found |
Ocean Extra medium confidence | None found |
Your full security report is ready
We found 11 plugins on this site. Unlock the complete analysis:
Security Report
- Full report for this site
- Every detected plugin & CVE
- Remediation guidance
- No re-audit after fixes
Report + Re-audit
- Everything in Security Report
- One complimentary re-audit within 90 days
- Verify your fixes actually closed the findings
- Clean-record badge for your site
Guided Remediation
- Everything in Report + Re-audit
- 15–30 min expert consult to triage findings
- Prioritized action plan for your site
- Optional partner handoff for fixes
One-time payment · Instant access · No subscription required
Not ready to buy? We'll send you a one-time free alert
if we detect a new vulnerability affecting your plugins.
One free alert · Continuous monitoring available with a paid plan
Security Posture
Security Headers
25/100No Content-Security-Policy header. Your site is more vulnerable to XSS attacks.
No HSTS header. Browsers can be tricked into using insecure HTTP connections.
No clickjacking protection. Your site can be embedded in malicious iframes.
TLS/SSL Certificate
Exposed Paths & Login Security
1 exposed1 security issues found — unlock to see which paths are exposed.
DNS & Email Security
SPF record with hard fail (-all) — strong email authentication.
DMARC policy is set to none — monitoring only, not enforcing.
DKIM record found for selector "selector1". Email signatures can be verified.
Certificate Transparency
86 certificates found · 1 subdomains discovered
Infrastructure
Server: nginx
Technology stack exposed: PHP/8.0.30, PleskLin. This header should be removed.
PHP 8.0.30 has reached end-of-life (2023-11-26). No longer receiving security patches.
No WAF detected. Consider adding one for additional protection.