Back to Free Tools

WordPress Stack Check

kohinoormills.com

D
kohinoormills.com
Check Complete

Results Summary

40 findings detected across kohinoormills.com.

8 components identified. WordPress detected: Yes.

Severity Breakdown

Total findings detected across all components. The public summary below groups findings by vulnerability type. To see every affected component in full detail, run a free scan on your own domain at vulnify.app/tools.

Critical1
High3
Medium27
Low2
Info7

Findings Overview

29 unique issues shown below, grouped from 40 total findings. When a vulnerability affects multiple components, it is listed once with the affected component count.

  • critical plugin: contact-form-7 has known vulnerability intelligence match

    Affects 8 components

    Detected version: 6.1.6 | Evidence quality: version-confirmed | Confidence score: 90 | Affected range: any to any | Patched version: true | CVE: n/a

    CVE: CVE-2020-35489CVE-2018-20979CVE-2025-3247CVE-2023-6449CVE-2024-4704

  • high plugin: devvn-image-hotspot has known vulnerability intelligence match

    Affects 2 components

    Detected version: 6.1.6 | Evidence quality: version-confirmed | Confidence score: 90 | Affected range: any to any | Patched version: true | CVE: CVE-2024-7656

    CVE: CVE-2024-7656CVE-2025-14445

  • high Content-Security-Policy header missing

    No CSP header detected. XSS impact surface is larger.

  • medium xmlrpc.php responded on the public WordPress surface

    Observed xmlrpc.php status 403. Restrict or disable xmlrpc unless a business-critical workflow still requires it.

  • medium REST API user-related routes appear discoverable from wp-json output

    The wp-json response referenced user endpoints. Review whether public user enumeration should be constrained on this site.

  • medium Public readme artifact disclosed WordPress core version evidence

    GET /readme.html responded with status 200 and exposed WordPress version clue 2.

  • medium WordPress installation or upgrade surfaces responded publicly

    HEAD /wp-admin/install.php -> 403; HEAD /wp-admin/upgrade.php -> 200.

  • medium Public plugin readme files confirmed additional version evidence

    contact-form-7 v6.1.6, devvn-image-hotspot v1.3.0

  • medium plugin: oxygen has known vulnerability intelligence match

    Detected version: 1.3.0 | Evidence quality: version-confirmed | Confidence score: 90 | Affected range: any to any | Patched version: true | CVE: CVE-2022-46841

    CVE: CVE-2022-46841

  • medium plugin: cf7-conditional-fields has known vulnerability intelligence match

    Affects 4 components

    Detected version: 4.9.1 | Evidence quality: version-confirmed | Confidence score: 90 | Affected range: any to any | Patched version: true | CVE: CVE-2023-47838

    CVE: CVE-2023-47838CVE-2024-5804CVE-2024-50412

  • medium Strict-Transport-Security (HSTS): missing

    Ensures the browser only connects over HTTPS

  • medium Content-Security-Policy (CSP): missing

    Prevents XSS and data injection attacks

  • medium X-Frame-Options: missing

    Prevents clickjacking attacks

  • medium X-Content-Type-Options: missing

    Prevents MIME-type sniffing

  • medium X-XSS-Protection: missing

    Legacy XSS protection (modern browsers use CSP)

  • medium Referrer-Policy: missing

    Controls how much referrer information is shared

  • medium Permissions-Policy: missing

    Controls browser features and APIs

  • medium [REDACTED]: missing

    Restricts Adobe Flash and PDF policies

  • medium Potentially sensitive paths are accessible

    /admin (200, admin-surface, confidence:medium), /wp-admin (200, admin-surface, confidence:medium)

  • medium Administrative entry surfaces responded publicly

    /admin (200), /wp-admin (200)

9 findings are grouped in this public summary

This public page groups findings by vulnerability type to avoid exposing sensitive configuration details about kohinoormills.com. To see the full breakdown including every affected component, version number, and remediation step, run a free scan on your own domain using Vulnify.

Run a Free Scan on kohinoormills.com

What the WordPress Stack Check Covers

This security profile for kohinoormills.com was generated by Vulnify. The check analyzes:

  • WordPress core version detection and known vulnerability lookup
  • Active theme identification and security assessment
  • Plugin inventory with version and CVE checks
  • Security headers and hardening controls
  • Exposed wp-config and sensitive file checks
  • XML-RPC and REST API exposure assessment

Prioritized Actions

  • highUpgrade vulnerable WordPress components
  • highAdd Content-Security-Policy (CSP) header
  • highAdd Strict-Transport-Security (HSTS) header
  • highAdd baseline CSP
  • highHarden cookies
  • highRestrict sensitive paths
  • highAdd edge-layer deny rules
  • mediumRestrict or disable xmlrpc.php
  • mediumReview REST API user exposure
  • mediumRemove public WordPress version artifacts
  • mediumConstrain public maintenance surfaces
  • mediumAdd X-Frame-Options header
  • mediumAdd X-Content-Type-Options header
  • mediumAdd Referrer-Policy header
  • mediumUse hardened cookie prefixes where possible

Run a Full Security Scan on kohinoormills.com

Check for XSS, SQL injection, CSRF, broken authentication, and 50+ additional security tests with a complete vulnerability assessment.

About This Check

This report was generated using Vulnify's free security tools. Results reflect the configuration at the time of the check. For ongoing monitoring, detailed remediation guidance, and vulnerability scanning across 50+ security tests, create a free Vulnify account.

Last checked:

Report abuse

If this page contains sensitive data, copyright issues, or should not be public, report it.