https://www.moroccan.vacations

Analyzed on February 28, 2026, 11:51 p.m. Click "Rescan Website" to get the latest data

Analysis Successful
Network Information
IP Address: 192.169.87.146
IP WHOIS Information:
  • ASN: 46475
  • ASN Description: LIMESTONENETWORKS - Limestone Networks, Inc., US
  • Country: US
  • Description: Limestone Networks, Inc.
  • CIDR: 192.169.80.0/20
Domain Information
DNS Records
Learn about DNS Records
A Records (IPv4 Addresses)
Domain IP Address
www.moroccan.vacations 192.169.87.146
CNAME Records (Aliases)
Domain Alias
www.moroccan.vacations moroccan.vacations.
MX Records (Mail Servers)
Priority Mail Server
0 moroccan.vacations.
TXT Records
Domain Text Record
www.moroccan.vacations "v=spf1 ip4:192.169.87.146 ip4:74.63.204.87 +a +mx ~all"
Services Detected (0 found)
Blocklisting Status
Learn about Blocklisting Status
Overall Status: CLEAN No blocklisting detected
Services Checked: 2
VirusTotal: CLEAN
Domain is clean according to 0 scanners
No threats detected by any security scanner
Google Safe Browsing: CLEAN
Domain is not blocklisted by Google Safe Browsing
No threats detected
Hosting Information
Provider: Unknown (none confidence)
Detection Method: No match found
SSL/TLS Security
Learn about SSL/TLS Security
TLS Version: TLSv1.3
SSL Certificate:
  • Certificate Type: DV (Domain Validated - Basic Security)
  • Subject: *.moroccan.vacations
  • Certificate Authority (CA): R12
    Let's Encrypt
    US
  • Valid From: Jan 14 23:41:02 2026 GMT
  • Valid Until: Apr 14 23:41:01 2026 GMT
  • Serial Number: 0545D8C1077EEDDC89B0F55FF6D6A8D336E0
SSL Certificate Expiring Soon!
Your SSL certificate expires in 44 days.
Please renew your certificate before Apr 14 23:41:01 2026 GMT to avoid service interruption.
Content Management System
CMS Detected: WordPress
Active Theme: Divi
Themes

1

Plugins

5

WordPress Security Analysis
FAILED
Learn about WordPress Security Analysis
XMLRPC.php Security Test FAILED

XMLRPC.php is accessible and vulnerable

HTTP Status: 200

Recommendation: Protect xmlrpc.php via firewall rules or disable it completely. Consider using security plugins or server-level blocking.
WP-Login.php Security Test FAILED

WP-Login page is accessible without CAPTCHA protection

HTTP Status: 200

Recommendation: Implement CAPTCHA protection on wp-login.php and consider using a firewall to block brute force attacks.
User Enumeration Test PASSED

User enumeration is properly protected

Test Results:

Endpoint: https://www.moroccan.vacations/wp-json/wp/v2/users

Status: PASSED

Message: Endpoint properly protected (HTTP 401)

HTTP Status: 401

Endpoint: https://www.moroccan.vacations/?rest_route=/wp/v2/users

Status: PASSED

Message: Endpoint properly protected (HTTP 401)

HTTP Status: 401

Recommendation: WordPress REST API user enumeration is properly secured.
Failed Security Tests:
  • XMLRPC
  • WP-Login
Security Headers Analysis
Need help understanding security headers? View our comprehensive documentation to learn about each header and how to implement them.
Present Security Headers

No security headers detected

Missing Security Headers
Strict-Transport-Security
X-Content-Type-Options
X-Frame-Options
X-XSS-Protection
Referrer-Policy
Content-Security-Policy
Permissions-Policy
Cross-Origin-Embedder-Policy
Cross-Origin-Opener-Policy
Cross-Origin-Resource-Policy
External JavaScripts Detected
Only scripts from different domains are shown
Domain Script URL Type
cdn.amcharts.com https://cdn.amcharts.com/lib/version/4.10.29/core.js?ver=1.6.27 External
cdn.amcharts.com https://cdn.amcharts.com/lib/version/4.10.29/maps.js?ver=1.6.27 External
cdn.amcharts.com https://cdn.amcharts.com/lib/version/4.10.29/themes/animated.js?ver=1.6.27 External
cdn.amcharts.com https://cdn.amcharts.com/lib/4/geodata/moroccoHigh.js?ver=1.6.27 External
cdn.amcharts.com https://cdn.amcharts.com/lib/4/geodata/moroccoHigh.js Inline Reference
HTTP Headers
Learn about HTTP Headers
HTTP Response Code
200 OK - Request successful
HTTP Protocol Version
Excellent! Your website is using HTTP/2

Your website is using a modern HTTP protocol version, which provides better performance and security features.

Information Disclosure: Server Version

Header: server
Value: LiteSpeed

Server Type: LiteSpeed

The Server header reveals server version information, which can be used by attackers to identify vulnerabilities.
Gzip Compression Enabled 👍

Great! This site is using Gzip compression to improve performance and reduce bandwidth usage.

Header Value
date Sat, 28 Feb 2026 23:51:34 GMT
etag "13351-1772182023;gz"
link <https://www.moroccan.vacations/wp-json/>; rel="https://api.w.org/", <https://www.moroccan.vacations/wp-json/wp/v2/pages/10142>; rel="alternate"; title="JSON"; type="application/json", <https://www.moroccan.vacations/>; rel=shortlink
vary Accept-Encoding,User-Agent
server LiteSpeed
alt-svc h3=":443"; ma=2592000, h3-29=":443"; ma=2592000, h3-Q050=":443"; ma=2592000, h3-Q046=":443"; ma=2592000, h3-Q043=":443"; ma=2592000, quic=":443"; ma=2592000; v="43,46"
expires Sat, 27 Feb 2027 08:47:03 GMT
content-type text/html; charset=UTF-8
http_version HTTP/2
cache-control max-age=0, no-cache, must-revalidate
content-length 67411
content-encoding gzip
x-litespeed-cache hit
Service Disclaimer

Free Service: This website security analyzer is provided as a free service to help website owners and administrators identify potential security issues and improve their website's security posture.

Donations: We welcome and appreciate donations to help us maintain and improve this service. Your support helps us keep this tool free and continuously enhance its capabilities.

Affiliate Links: We may use affiliate links for various security services, hosting providers, and security tools mentioned throughout this analysis. If you choose to purchase any of these services through our links, we may receive a small commission at no additional cost to you. This helps support the development and maintenance of this free service.

Support Our Service

Help us keep this tool free and improve it further

Please wait, running the scan...
This may take a few moments