hogum
themewant.com

themewant.com security report

Certificate, security headers, email authentication, DNS, registration, and exposed hosts — from public sources.

79risk

Critical

Exposed services or known CVEs need attention now.

1Critical
1High
5Medium
7Low
2Info
Collected 13.3sfrom cache
  1. Certificate Transparency34
  2. DNS resolution22
  3. Network ownership0
  4. CDN / WAF detection0
  5. Exposed ports & CVEs10
  6. Registration
  7. DNS posture2
  8. Email authentication2
  9. Certificate
  10. Security headers1
  11. Archived URLs
  12. Analysis16
  • noteFound 34 hostnames; this runtime allows 50 outbound requests per scan, so the 21 most likely to matter were resolved.
  • noteCertificate inspection is unavailable in this runtime.
  • noteNetwork ownership lookup is unavailable in this runtime; ASN and org are omitted.
  • noteCDN/WAF detection is unavailable in this runtime.
final https://themewant.com/status 200time 914msstack cloudflare · PHP/8.1.34 · WordPress 7.1
  • http:// redirects to https://
  • Strict-Transport-Security
  • Content-Security-Policy
    upgrade-insecure-requests
  • Clickjacking protection
  • X-Content-Type-Options
  • Referrer-Policy
  • Permissions-Policyoptional
  • security.txt publishedoptional — tells researchers where to report bugs
  • !Cookie PHPSESSID
    Secure · no HttpOnly · no SameSite
  • Receives mail via 2 servers
  • !SPFends in ~all
    v=spf1 include:spf.titan.email ~all
  • !DMARCp=none
    v=DMARC1;p=none;
  • !MTA-STSinbound mail can be downgraded to plaintext
Archived URLs

Endpoints the Wayback Machine has kept — config files, backups, scripts. Slow to fetch, so it is here on request.