New audit

tm-tieto.fi

Scanned Apr 6, 2026, 08:35 PM

Re-scan — Upgrade
93
A · Safe
2
Plugins Detected
1
Active Vulnerabilities
1
Outdated Plugins
0
Abandoned

Security Assessment

Key findings for tm-tieto.fi

  • 1 active vulnerability detected across 2 plugins.
  • 1 plugin is outdated and should be updated.
  • Security headers grade F — 4 important headers are missing.
  • 1 sensitive path exposed to the public.
  • Active theme "salient" has 1 known vulnerability.

WordPress

Version 6.9.4
Core installation

Active Theme

salient v16.2.2
Outdated1 active vuln

Hosting Provider

Cloudflare
Infrastructure

Detected Plugins

2 total
PluginVulnerabilities
LiteSpeed Cache
LiteSpeed Cache
medium confidence
None found
None found

Unlock the full security analysis

Get the full breakdown of your site's security posture:

All 2 detected plugins
CVE details & patch status
Security header analysis
Exposed paths & TLS audit
DNS & email security
CT log subdomain discovery

One-time payment · Instant access · No subscription required

Security Posture

F
Security Headers
A
TLS/SSL
B
Exposed Paths
B
Email Security

Security Headers

17/100
Content-Security-Policy

No Content-Security-Policy header. Your site is more vulnerable to XSS attacks.

Strict-Transport-Security

No HSTS header. Browsers can be tricked into using insecure HTTP connections.

X-Frame-Options

No clickjacking protection. Your site can be embedded in malicious iframes.

3 more checks — unlock full report to see all

TLS/SSL Certificate

Issuer
R12
Expires
60 days
Protocol
TLSv1.3
Wildcard
No

Exposed Paths & Login Security

1 exposed

1 security issues found — unlock to see which paths are exposed.

DNS & Email Security

SPF

SPF record with hard fail (-all) — strong email authentication.

DMARC

DMARC policy is set to none — monitoring only, not enforcing.

DKIM

DKIM record found for selector "selector1". Email signatures can be verified.

Certificate Transparency

111 certificates found

Infrastructure

Server Software

Server: nginx

X-Powered-By

Technology stack exposed: PHP/8.3.30, PleskLin. This header should be removed.

PHP Version

PHP 8.3.30 is supported.

Web Application Firewall

No WAF detected. Consider adding one for additional protection.

WP Version Exposed

WordPress version 6.9.4 is exposed in the generator meta tag. Consider removing it.