Back to Free Tools

WordPress Stack Check

vulnerable.lab.netclick.tech

D
vulnerable.lab.netclick.tech
Check Complete

Results Summary

23 findings detected across vulnerable.lab.netclick.tech.

2 components identified. WordPress detected: Yes.

Severity Breakdown

Total findings detected across all components. The public summary below groups findings by vulnerability type. To see every affected component in full detail, run a free scan on your own domain at vulnify.app/tools.

Critical1
High3
Medium10
Low2
Info7

Findings Overview

23 unique issues shown below, grouped from 23 total findings. When a vulnerability affects multiple components, it is listed once with the affected component count.

  • critical Potentially sensitive paths are accessible

    /m/vulnerable/wp/wp-admin (200, admin-surface, confidence:medium), /m/vulnerable/wp/wp-config.php.bak (200, sensitive-artifact, confidence:high), /m/vulnerable/wp/wp-content/debug.log (200, diagnostic-surface, confidence:high), /m/vulnerable/wp/xmlrp…

  • high Strict-Transport-Security (HSTS): missing

    Ensures the browser only connects over HTTPS

  • high Content-Security-Policy (CSP): missing

    Prevents XSS and data injection attacks

  • high Content-Security-Policy header missing

    No CSP header detected. XSS impact surface is larger.

  • medium xmlrpc.php responded on the public WordPress surface

    Observed xmlrpc.php status 404. Restrict or disable xmlrpc unless a business-critical workflow still requires it.

  • medium WordPress installation or upgrade surfaces responded publicly

    HEAD /wp-admin/install.php -> 404; HEAD /wp-admin/upgrade.php -> 404.

  • medium X-Frame-Options: missing

    Prevents clickjacking attacks

  • medium X-Content-Type-Options: missing

    Prevents MIME-type sniffing

  • medium X-XSS-Protection: missing

    Legacy XSS protection (modern browsers use CSP)

  • medium Referrer-Policy: missing

    Controls how much referrer information is shared

  • medium Permissions-Policy: missing

    Controls browser features and APIs

  • medium [REDACTED]: missing

    Restricts Adobe Flash and PDF policies

  • medium Different start URLs resolve to different final destinations

    https://vulnerable.lab.netclick.tech/m/vulnerable/wp/ | http://vulnerable.lab.netclick.tech/m/vulnerable/wp/

  • medium Administrative entry surfaces responded publicly

    /m/vulnerable/wp/wp-admin (200), /m/vulnerable/admin (200), /m/vulnerable/wp-admin (200)

  • low WordPress component footprint detected

    Detected 2 core/theme/plugin component signal(s) from public asset paths.

  • low wp-cron.php responded on the public surface

    Observed wp-cron.php status 404. This endpoint is often abused for nuisance traffic or workload amplification if left unconstrained.

  • info WordPress footprint signals detected

    WordPress signal count: 4. Confirm the target is a live WordPress frontend URL.

  • info Broader WordPress route coverage completed

    Sampled 7 frontend route(s) plus public WordPress endpoints for deeper evidence.

  • info TLS grade: A+

    Protocol: TLSv1.3; Cipher: TLS_AES_256_GCM_SHA384 (TLSv1.3)

  • info No Set-Cookie headers observed

    No cookies were set on this response.

3 findings are grouped in this public summary

This public page groups findings by vulnerability type to avoid exposing sensitive configuration details about vulnerable.lab.netclick.tech. To see the full breakdown including every affected component, version number, and remediation step, run a free scan on your own domain using Vulnify.

Run a Free Scan on vulnerable.lab.netclick.tech

What the WordPress Stack Check Covers

This security profile for vulnerable.lab.netclick.tech was generated by Vulnify. The check analyzes:

  • WordPress core version detection and known vulnerability lookup
  • Active theme identification and security assessment
  • Plugin inventory with version and CVE checks
  • Security headers and hardening controls
  • Exposed wp-config and sensitive file checks
  • XML-RPC and REST API exposure assessment

Prioritized Actions

  • highAdd Content-Security-Policy (CSP) header
  • highAdd Strict-Transport-Security (HSTS) header
  • highAdd baseline CSP
  • highHarden cookies
  • highRestrict sensitive paths
  • highAdd edge-layer deny rules
  • mediumRestrict or disable xmlrpc.php
  • mediumConstrain public maintenance surfaces
  • mediumAdd X-Frame-Options header
  • mediumAdd X-Content-Type-Options header
  • mediumAdd Referrer-Policy header
  • mediumUse hardened cookie prefixes where possible
  • mediumStandardize canonical redirect destination

Run a Full Security Scan on vulnerable.lab.netclick.tech

Check for XSS, SQL injection, CSRF, broken authentication, and 50+ additional security tests with a complete vulnerability assessment.

About This Check

This report was generated using Vulnify's free security tools. Results reflect the configuration at the time of the check. For ongoing monitoring, detailed remediation guidance, and vulnerability scanning across 50+ security tests, create a free Vulnify account.

Last checked:

Report abuse

If this page contains sensitive data, copyright issues, or should not be public, report it.