← new scan
~/scans/djihane621.wpchef.site.report
⇣ export pdf
target djihane621.wpchef.site
resolved109.234.165.150
scanned 2026-09-14 14:06:00
modules 7 of 7 completed
// overall risk
MEDIUM Risk
9 issues across 7 modules — 4 medium, 5 low
0 critical
0 high
4 medium
5 low
0 ok
01
WHOIS & DNS
DNS records retrieved — SPF & DMARC present
· LOW
// whois
registrar NameCheap, Inc.
created 2019-04-06
expires 2029-04-06
updated 2026-03-07
nameserver ns1.o2switch.net
nameserver ns2.o2switch.net
status client transfer prohibited
// dns records
A 109.234.165.150
www A 109.234.165.150
MX 0 mail.wpchef.site
NS ns1.o2switch.net
NS ns2.o2switch.net
// ip whois (1)
109.234.165.150 SSL unavailable for this endpoint, order a key at https://members.ip-api.com/ whois ↗
// lookup on dnsarchive.net
// email security
// findings (7)
  • ok SPF record present
  • ok DMARC record present
  • ok 1 MX record(s) configured
  • · low No CAA records — any certificate authority can issue certs for this domain
  • · low No MTA-STS DNS record at _mta-sts — inbound mail can be downgraded
  • · low No TLS-RPT record at _smtp._tls — no visibility into TLS delivery failures
  • · low Certificate Transparency: 1117 subdomain(s) ever issued certs — abassemayousse.wpchef.site, abaudino.wpchef.site, abettinger.wpchef.site, abironneau.wpchef.site, abladou.wpchef.site, aborto.wpchef.site (+1111 more)
02
SSL / TLS Certificate
Valid certificate, expires in 81 days — TLSv1.3
OK
// raw output
issuer YR2
subject djihane621.wpchef.site
valid from Sep 07 06:11:51 2026 UTC
valid to Dec 06 06:11:50 2026 UTC
tls version TLSv1.3
// findings (3)
  • ok Certificate valid for 81 more days
  • ok TLS 1.3 in use — best available protocol
  • ok HTTP redirects to HTTPS in 1 hop(s)
03
CMS Detection
WordPress detected — 3 plugins found
OK
// raw output
platform WordPress
theme astra
plugins 3 detected
plugin.01 astra-sites
plugin.02 elementor
plugin.03 header-footer-elementor
xmlrpc.php not accessible
login path /wp-login.php
user enum protected
// findings (1)
  • ok WordPress hardening looks reasonable
04
Security Headers
All 7 security headers present
MEDIUM
// raw output
HSTS ok (max-age=63072000; includeSubDomains; pre)
CSP ok (upgrade-insecure-requests;)
X-Frame-Options ok (SAMEORIGIN)
X-Content-Type-Options ok (nosniff)
Referrer-Policy ok (strict-origin-when-cross-origin)
Permissions-Policy ok (accelerometer=(), autoplay=(), camera=())
Cross-Origin-Opener ok (unsafe-none)
// findings (12)
  • ok Referrer-Policy is configured
  • ok X-Frame-Options is configured
  • ok Permissions-Policy is configured
  • ok X-Content-Type-Options is configured
  • ok Content-Security-Policy is configured
  • ok Strict-Transport-Security is configured
  • ok Cross-Origin-Opener-Policy is configured
  • medium CSP weakness — no default-src or script-src — falls back to permissive defaults
  • medium CSP weakness — no frame-ancestors — clickjacking only protected by X-Frame-Options
  • medium CSP weakness — no object-src — should be set to 'none'
  • medium CSP weakness — no base-uri — base tag injection unrestricted
  • · low No /.well-known/security.txt — researchers cannot find a contact for vulnerability reports
05
Raw HTTP Headers
HTTP/3 · 18 headers · o2switch-PowerBoost-v3
OK
// detected
HTTP/3 HTTP/3 (QUIC) in use — fastest available protocol, low latency and connection migration
Brotli compression Response is Brotli-compressed — best compression ratio for text content
// raw headers (18)
status HTTP/3 200
date Mon, 14 Sep 2026 14:05:42 GMT
link <https://djihane621.wpchef.site/wp-json/>; rel="https://api.w.org/", <https://dj…
vary Accept-Encoding
server o2switch-PowerBoost-v3
content-type text/html; charset=UTF-8
referrer-policy strict-origin-when-cross-origin
x-frame-options SAMEORIGIN
content-encoding br
permissions-policy accelerometer=(), autoplay=(), camera=(), cross-origin-isolated=(), display-capt…
x-content-type-options nosniff
content-security-policy upgrade-insecure-requests;
strict-transport-security max-age=63072000; includeSubDomains; preload
cross-origin-opener-policy unsafe-none
access-control-allow-headers Content-Type, Authorization
access-control-allow-methods GET,POST
cross-origin-resource-policy cross-origin
x-permitted-cross-domain-policiesnone
// findings (2)
  • ok HTTP/3 enabled — best available
  • ok Brotli (br) compression active
06
External JS Libraries
No external JS libraries detected
OK
// raw output
external scripts 0 detected
// findings (1)
  • ok No third-party JavaScript files loaded
07
Malware & Blocklists
Clean — not present on any monitored blocklist
OK
// raw output
Google Safe Browsing clean
VirusTotal clean
injected scripts 0 detected
malware patterns 0 matches
// findings (3)
  • ok Google Safe Browsing — clean
  • ok VirusTotal — clean
  • ok No malware signatures found across monitored blocklists
// end of report · djihane621.wpchef.site · 2026-09-14 14:06:00 ↻ scan again