VXN Defense
Buskower Dorfstr. 36 · 16816 Buskow

Professionelle Security Tools

Werkzeuge, die ich selbst täglich einsetze.

Von Klaus Baumdick entwickelt

⭐ FLAGGSCHIFF-PRODUKT

WordPress Security Scanner

Version 2.3.1 · Letztes Update: 19. März 2026

Der Scanner, den ich entwickelt habe, weil mir die existierenden Lösungen nicht tief genug gingen. Über 100 verschiedene Sicherheitsprüfungen, Live-CVE-Abfragen und intelligente Schwachstellenanalyse - alles in einem Perl-Script.

🔐

100+ Prüfungen

Von SQL Injection bis XXE - wir testen alles

Live CVE-Datenbank

Echtzeit-Abgleich mit WPVulnerability API

🎯

Theme & Plugin Scan

Erkennt automatisch alle installierten Komponenten

📊

Detaillierte Berichte

HTML, JSON und maschinenlesbare Ausgabe

Perl LWP::UserAgent CVE-Datenbank JSON XML-RPC REST API
4.8/5 BEWERTUNG
5k+ Getestete Installationen
1270 CVE-FUNDE
# WordPress Security Scanner v2.3
# 100+ Sicherheitsprüfungen

my $target_url = "https://example.com";
my $scanner = WordPress::Security->new();

# Theme-Identifizierung
$scanner->identify_themes();

# CVE-Datenbank Abgleich
foreach my $plugin (@plugins) {
  check_cve($plugin);
}

[FOUND] Kritische Schwachstelle in Plugin
CVE-2025-3102 - SureTriggers < 1.0.79
WP-FUZZ

Dynamischer WordPress Fuzzer

Perl · Multi-Threading · 100+ Payloads

Mein persönlicher Fuzzer für die Tiefensuche. Während normale Scanner nur bekannte Pfade prüfen, injiziert WP-FUZZ gezielt Payloads in Parameter, Header und Endpunkte. Erkennt SQL Injection, XSS, LFI, Command Injection und mehr – oft bevor die Schwachstellen öffentlich bekannt werden.

🎯

8 Schwachstellen-Klassen

SQLi, XSS, LFI/RFI, Command Injection, Open Redirect, SSRF, NoSQL, Path Traversal

Multi-Threading

Parallelisierte Anfragen mit bis zu 20 Threads für schnelle Ergebnisse

🔍

Intelligente Endpunkt-Erkennung

Findet automatisch AJAX-Aktionen, REST-Endpunkte und PHP-Dateien

📊

Behavioral Analysis

Erkennt blinde Injections durch Timing- und Größenanalyse

Perl Parallel::ForkManager Time-based Detection Error-based SQLi XSS Payloads LFI/RFI Command Injection SSRF NoSQL
100+ PAYLOADS
🎯 8 VULN-TYPEN
⏱️ 0.5s DELAY
#!/usr/bin/perl
# WP-FUZZ - Advanced WordPress Fuzzer

my $fuzzer = WP::Fuzz->new(
    url => 'https://example.com',
    plugin => 'suretriggers',
    threads => 10
);

# Findet automatisch alle Endpunkte
$fuzzer->discover_endpoints();

[FOUND] 12 AJAX actions
[FOUND] 5 REST endpoints
[FOUND] 3 PHP files

# Fuzzing mit SQLi Payloads
my @results = $fuzzer->fuzz({
    param => 'id',
    payloads => "1' AND SLEEP(5)--"
});

[CRITICAL] SQL Injection in /wp-admin/admin-ajax.php
Parameter: action, Payload: 1' AND SLEEP(5)--

🔬 Technische Tiefe

🎯 Payload-Datenbank

  • SQL Injection: Zeitbasierte (SLEEP/WAITFOR), fehlerbasierte, UNION-basierte
  • XSS: Reflektiert, DOM-basiert, stored, Case-Sensitive Umgehungen
  • LFI/RFI: Path Traversal, PHP Wrapper, Datei-Inclusion
  • Command Injection: Direkte, blinde (zeitbasierte), encodierte

🔍 Erkennungsmethoden

  • Time-based: Erkennt blinde Injections durch Antwortzeit-Analyse
  • Error-based: Extrahiert Datenbank-Fehlermeldungen
  • Pattern Matching: Erkennt reflektierte Payloads und sensitive Daten
  • Behavioral Analysis: Vergleicht mit Baseline für Anomalien

📋 Beispiel-Fund

[CRITICAL] SQL Injection in SureTriggers < 1.0.79
URL: https://example.com/wp-admin/admin-ajax.php
Parameter: action
Payload: 1' AND SLEEP(5)--
Evidence: Response time: 5.2s (Baseline: 0.3s)
CVE: CVE-2025-3102
➜ Unauthenticated Admin Account Creation möglich!
🔍

Plugin-Scan

Spezifisches Plugin fuzzen – findet AJAX-Aktionen, PHP-Dateien und REST-Endpunkte automatisch.

perl wp_fuzz.pl --url=... --plugin=suretriggers
🌐

Generic-Modus

Testet generische WordPress-Endpunkte wie Suchparameter, REST API und Admin-AJAX.

perl wp_fuzz.pl --url=... --generic

High-Speed-Modus

Multi-Threading mit bis zu 20 parallelen Prozessen für schnelle Ergebnisse.

perl wp_fuzz.pl --url=... --threads=20 --delay=0.1
🌐 NEU IN VERSION 2.3

REST API & GraphQL Scanner

Erweiterte API-Sicherheitsprüfungen

Moderne WordPress-Installationen nutzen REST APIs und oft auch GraphQL. Unser Scanner prüft auf offene Endpunkte, Introspection-Schwachstellen, JWT-Token-Leaks und CORS-Misconfigurationen.

🔍

GraphQL Introspection

Erkennt offene Schemas und Query-Möglichkeiten

🔐

JWT-Token Analyse

Prüft auf unsignierte Tokens und LocalStorage-Leaks

🌍

CORS-Testing

Wildcard Origins und Credentials-Misconfigurations

📡

User Enumeration

Prüft auf offene Benutzer-Endpoints

# REST API Security Check
my @endpoints = (
  '/wp-json/wp/v2/users',
  '/wp-json/wp/v2/posts',
  '/?graphql'
);

foreach my $endpoint (@endpoints) {
  my $response = $ua->get($url);
  if ($response->content =~ /user_email/) {
    warn "User Data Leak!";
  }
}

[VULN] GraphQL Introspection enabled!
🕵️ AUS DER PRAXIS FÜR DIE PRAXIS

OSINT Collection

Tools für Open Source Intelligence

Eine Sammlung von Scripts, die ich für OSINT-Recherchen entwickelt habe. Von Metadata-Extraktion bis zu DNS-Analyse – ideal für Pentester und Sicherheitsforscher.

🌐

DNS Enumeration

SPF, DMARC, DKIM und Subdomain-Scans

📄

Metadata Extractor

Analysiert öffentliche Dokumente auf verborgene Daten

🔎

GitHub Dorking

Findet versehentlich veröffentlichte Credentials

📊

Social Media Intelligence

SOCMINT für Unternehmensrecherchen

#!/bin/bash
# DNS Security Check

echo "Prüfe SPF Record..."
dig TXT example.com | grep "v=spf1"

echo "Prüfe DMARC..."
dig TXT _dmarc.example.com

[WARNING] Kein DMARC Record gefunden
[INFO] SPF mit -all vorhanden

Aktuelle CVE-Funde aus der Praxis

Mit meinem Scanner identifizierte Schwachstellen

CVE-2025-3102
SureTriggers Plugin < 1.0.79 - Unauthenticated Admin Account Creation
CRITICAL
CVE-2025-3077
Betheme < 27.5 - Stored XSS for Author+
HIGH
CVE-2024-5394
Alone Theme < 4.0 - Missing Authorization
CRITICAL
CVE-2024-9012
Elementor < 3.12.0 - File Upload Bypass
CRITICAL
CVE-2024-1111
Avada Theme < 7.11.0 - Reflected XSS
HIGH
CVE-2024-2222
WooCommerce < 6.5.0 - SQL Injection
CRITICAL

Lizenzoptionen

Privat
€9.99 Monat
  • WordPress Scanner Basis
  • 30 Sicherheitsprüfungen
  • CVE-Datenbank mit Cache
  • JSON & Text Reports
Jetzt nutzen
Enterprise
€199 /Monat
  • Alle Professional-Features
  • 3000 Sicherheitsprüfungen
  • Individuelle Anpassungen
  • On-Premise Installation
  • SLA mit Reaktionszeit
  • Schulungen inklusive
  • Direkter Kontakt zu Klaus
Anfragen

Maßgeschneiderte Security-Tools

Sie benötigen ein individuelles Sicherheitstool für Ihre Infrastruktur? Klaus Baumdick entwickelt maßgeschneiderte Lösungen – von kleinen Scripts bis zu komplexen Security-Frameworks.

🔍 Beispiel-Report WordPress Security Scanner

====================================================================== WORDPRESS SECURITY SCAN REPORT ====================================================================== Scan-ID : 20260319_080442 Ziel : https://www.stoerti.com Scan-Zeit : Thu Mar 19 08:04:42 2026 Status : ABGESCHLOSSEN ---------------------------------------------------------------------- ZUSAMMENFASSUNG ---------------------------------------------------------------------- Kritisch : 0 Hoch : 2 Mittel : 53 Niedrig : 4 Warnungen : 1 Information : 13 ---------------------------------------------------------------------- THEMES ---------------------------------------------------------------------- Theme: minimalistblogger - author: ThemeEverest - css_url: //www.stoerti.com/wp-content/themes/minimalistblogger/css/font-awesome.min.css?ver=6.9.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/themes/minimalistblogger/css/font-awesome.min.css?ver=6.9.4 - detected_from: css_link - full_name: MinimalistBlogger - has_readme: 1 - theme_uri: https://superbthemes.com/minimalistblogger/minimalistblogger-info/ - version: 9.1 Theme: dark-minimalistblogger - author: Superbthemescom - css_url: //www.stoerti.com/wp-content/themes/dark-minimalistblogger/style.css?ver=6.9.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/themes/dark-minimalistblogger/style.css?ver=6.9.4 - detected_from: css_link - full_name: Dark Minimalistblogger - has_readme: 1 - theme_uri: https://superbthemes.com/child-theme/dark-minimalistblogger/ - version: 3.1 Gefundene Plugins: wordpress-popular-posts, contact-form-7-image-captcha, woocommerce, book-preview-for-woocommerce, contact-form-7, eventprime-event-calendar-management, superb-blocks, superb-social-share-and-follow-buttons, wp-stats-manager, woocommerce-germanized, stop-user-enumeration, * ---------------------------------------------------------------------- SICHERHEITS-SCORE: 0/100 ---------------------------------------------------------------------- 🚨 UNGENÜGEND - Kritische Sicherheitslücken! ---------------------------------------------------------------------- SCHWACHSTELLEN ---------------------------------------------------------------------- [high] Mögliche Prototype Pollution Schwachstelle URL: https://www.stoerti.com/?__proto__[admin]=true [high] jquery . ist anfällig für Prototype Pollution ---------------------------------------------------------------------- WARNUNGEN ---------------------------------------------------------------------- * Fehlender Security Header: X-XSS-Protection - XSS-Schutz * Trackbacks/Pingbacks sind aktiviert - Kann für DDOS-Angriffe missbraucht werden URL: //www.stoerti.com/wp-trackback.php" target="_blank" class="report-link">https://www.stoerti.com/wp-trackback.php * CSP fehlen wichtige Direktiven (default-src oder script-src) * Kein SPF Record gefunden - E-Mail Spoofing möglich * Kein DMARC Record gefunden * CSP fehlt default-src - Unvollständiger Schutz * CSP fehlt script-src - Unvollständiger Schutz * CSP fehlt object-src - Unvollständiger Schutz * Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant URL: //www.stoerti.com/wp-content/plugins/wordpress-popular-posts/assets/js/wpp.min.js?ver=7.3.8" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/wordpress-popular-posts/assets/js/wpp.min.js?ver=7.3.8 * Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant URL: //www.stoerti.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1" target="_blank" class="report-link">https://www.stoerti.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1 * Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant URL: //www.stoerti.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1" target="_blank" class="report-link">https://www.stoerti.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1 * Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant URL: //www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/js/eventprime-event-calendar-management-public.js?ver=4.3.1.0" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/js/eventprime-event-calendar-management-public.js?ver=4.3.1.0 * Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant URL: //www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/js/jquery.toast.min.js?ver=4.3.1.0" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/js/jquery.toast.min.js?ver=4.3.1.0 * Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant URL: //www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/js/toast-message.js?ver=4.3.1.0" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/js/toast-message.js?ver=4.3.1.0 * Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant URL: //www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/js/ep-common-script.js?ver=4.3.1.0" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/js/ep-common-script.js?ver=4.3.1.0 * Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant URL: //www.stoerti.com/wp-content/plugins/stop-user-enumeration/frontend/js/frontend.js?ver=1.7.7" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/stop-user-enumeration/frontend/js/frontend.js?ver=1.7.7 * Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant URL: //www.stoerti.com/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.9.5.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.9.5.4 * Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant URL: //www.stoerti.com/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=9.5.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=9.5.4 * Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant URL: //www.stoerti.com/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.9.5.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.9.5.4 * Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant URL: //www.stoerti.com/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=9.5.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=9.5.4 * Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant URL: //www.stoerti.com/wp-content/plugins/book-preview-for-woocommerce/assets/js/wbps-script.js?ver=1773904112" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/book-preview-for-woocommerce/assets/js/wbps-script.js?ver=1773904112 * Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant URL: //www.stoerti.com/wp-includes/js/dist/hooks.min.js?ver=dd5603f07f9220ed27f1" target="_blank" class="report-link">https://www.stoerti.com/wp-includes/js/dist/hooks.min.js?ver=dd5603f07f9220ed27f1 * Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant URL: //www.stoerti.com/wp-includes/js/dist/i18n.min.js?ver=c26c3dc7bed366793375" target="_blank" class="report-link">https://www.stoerti.com/wp-includes/js/dist/i18n.min.js?ver=c26c3dc7bed366793375 * Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant URL: //www.stoerti.com/wp-content/plugins/contact-form-7/includes/swv/js/index.js?ver=6.1.5" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/contact-form-7/includes/swv/js/index.js?ver=6.1.5 * Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant URL: //www.stoerti.com/wp-content/plugins/contact-form-7/includes/js/index.js?ver=6.1.5" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/contact-form-7/includes/js/index.js?ver=6.1.5 * Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant URL: //www.stoerti.com/wp-content/themes/minimalistblogger/js/navigation.js?ver=20170823" target="_blank" class="report-link">https://www.stoerti.com/wp-content/themes/minimalistblogger/js/navigation.js?ver=20170823 * Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant URL: //www.stoerti.com/wp-content/themes/minimalistblogger/js/skip-link-focus-fix.js?ver=20170823" target="_blank" class="report-link">https://www.stoerti.com/wp-content/themes/minimalistblogger/js/skip-link-focus-fix.js?ver=20170823 * Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant URL: //www.stoerti.com/wp-content/themes/minimalistblogger/js/script.js?ver=20160720" target="_blank" class="report-link">https://www.stoerti.com/wp-content/themes/minimalistblogger/js/script.js?ver=20160720 * Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant URL: //www.stoerti.com/wp-content/plugins/woocommerce/assets/js/flexslider/jquery.flexslider.min.js?ver=2.7.2-wc.9.5.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/woocommerce/assets/js/flexslider/jquery.flexslider.min.js?ver=2.7.2-wc.9.5.4 * Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant URL: //www.stoerti.com/wp-content/themes/minimalistblogger/js/accessibility.js?ver=20160720" target="_blank" class="report-link">https://www.stoerti.com/wp-content/themes/minimalistblogger/js/accessibility.js?ver=20160720 * Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant URL: //www.stoerti.com/wp-content/plugins/woocommerce/assets/js/sourcebuster/sourcebuster.min.js?ver=9.5.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/woocommerce/assets/js/sourcebuster/sourcebuster.min.js?ver=9.5.4 * Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant URL: //www.stoerti.com/wp-content/plugins/woocommerce/assets/js/frontend/order-attribution.min.js?ver=9.5.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/woocommerce/assets/js/frontend/order-attribution.min.js?ver=9.5.4 * Externes Stylesheet ohne Subresource Integrity URL: //www.stoerti.com/wp-content/plugins/contact-form-7-image-captcha/css/cf7ic-style.css?ver=3.3.7" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/contact-form-7-image-captcha/css/cf7ic-style.css?ver=3.3.7 * Externes Stylesheet ohne Subresource Integrity URL: //www.stoerti.com/wp-includes/css/dist/block-library/style.min.css?ver=6.9.4" target="_blank" class="report-link">https://www.stoerti.com/wp-includes/css/dist/block-library/style.min.css?ver=6.9.4 * Externes Stylesheet ohne Subresource Integrity URL: //www.stoerti.com/wp-content/plugins/woocommerce/assets/client/blocks/wc-blocks.css?ver=wc-9.5.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/woocommerce/assets/client/blocks/wc-blocks.css?ver=wc-9.5.4 * Externes Stylesheet ohne Subresource Integrity URL: //www.stoerti.com/wp-content/plugins/book-preview-for-woocommerce/assets/css/wbps-style.css?ver=1773904112" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/book-preview-for-woocommerce/assets/css/wbps-style.css?ver=1773904112 * Externes Stylesheet ohne Subresource Integrity URL: //www.stoerti.com/wp-content/plugins/contact-form-7/includes/css/styles.css?ver=6.1.5" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/contact-form-7/includes/css/styles.css?ver=6.1.5 * Externes Stylesheet ohne Subresource Integrity URL: //www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/css/eventprime-event-calendar-management-public.css?ver=4.3.1.0" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/css/eventprime-event-calendar-management-public.css?ver=4.3.1.0 * Externes Stylesheet ohne Subresource Integrity URL: //www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/css/em-front-common-utility.css?ver=4.3.1.0" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/css/em-front-common-utility.css?ver=4.3.1.0 * Externes Stylesheet ohne Subresource Integrity URL: //www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/css/ep-material-fonts-icon.css?ver=4.3.1.0" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/css/ep-material-fonts-icon.css?ver=4.3.1.0 * Externes Stylesheet ohne Subresource Integrity URL: //www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/css/jquery.toast.min.css?ver=4.3.1.0" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/css/jquery.toast.min.css?ver=4.3.1.0 * Externes Stylesheet ohne Subresource Integrity URL: //www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/css/em-front-common-utility.css?ver=4.3.1.0" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/css/em-front-common-utility.css?ver=4.3.1.0 * Externes Stylesheet ohne Subresource Integrity URL: //www.stoerti.com/wp-content/plugins/superb-blocks/assets/css/patterns.min.css?ver=3.7.1" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/superb-blocks/assets/css/patterns.min.css?ver=3.7.1 * Externes Stylesheet ohne Subresource Integrity URL: //www.stoerti.com/wp-content/plugins/superb-blocks/assets/css/enhancements.min.css?ver=3.7.1" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/superb-blocks/assets/css/enhancements.min.css?ver=3.7.1 * Externes Stylesheet ohne Subresource Integrity URL: //www.stoerti.com/wp-content/plugins/superb-social-share-and-follow-buttons//assets/css/frontend.css?ver=1.2.5" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/superb-social-share-and-follow-buttons//assets/css/frontend.css?ver=1.2.5 * Externes Stylesheet ohne Subresource Integrity URL: //www.stoerti.com/wp-content/plugins/superb-social-share-and-follow-buttons//assets/lato/styles.css?ver=1.2.5" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/superb-social-share-and-follow-buttons//assets/lato/styles.css?ver=1.2.5 * Externes Stylesheet ohne Subresource Integrity URL: //www.stoerti.com/wp-content/plugins/woocommerce/assets/css/woocommerce-layout.css?ver=9.5.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/woocommerce/assets/css/woocommerce-layout.css?ver=9.5.4 * Externes Stylesheet ohne Subresource Integrity URL: //www.stoerti.com/wp-content/plugins/woocommerce/assets/css/woocommerce-smallscreen.css?ver=9.5.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/woocommerce/assets/css/woocommerce-smallscreen.css?ver=9.5.4 * Externes Stylesheet ohne Subresource Integrity URL: //www.stoerti.com/wp-content/plugins/woocommerce/assets/css/woocommerce.css?ver=9.5.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/woocommerce/assets/css/woocommerce.css?ver=9.5.4 * Externes Stylesheet ohne Subresource Integrity URL: //www.stoerti.com/wp-content/plugins/wp-stats-manager/css/style.css?ver=1.2" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/wp-stats-manager/css/style.css?ver=1.2 * Externes Stylesheet ohne Subresource Integrity URL: //www.stoerti.com/wp-content/plugins/wordpress-popular-posts/assets/css/wpp.css?ver=7.3.8" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/wordpress-popular-posts/assets/css/wpp.css?ver=7.3.8 * Externes Stylesheet ohne Subresource Integrity URL: //www.stoerti.com/wp-content/themes/minimalistblogger/style.css?ver=6.9.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/themes/minimalistblogger/style.css?ver=6.9.4 * Externes Stylesheet ohne Subresource Integrity URL: //www.stoerti.com/wp-content/themes/minimalistblogger/css/font-awesome.min.css?ver=6.9.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/themes/minimalistblogger/css/font-awesome.min.css?ver=6.9.4 * Externes Stylesheet ohne Subresource Integrity URL: //www.stoerti.com/wp-content/themes/dark-minimalistblogger/style.css?ver=6.9.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/themes/dark-minimalistblogger/style.css?ver=6.9.4 * Externes Stylesheet ohne Subresource Integrity URL: //www.stoerti.com/wp-content/plugins/woocommerce-germanized/build/static/layout-styles.css?ver=3.20.7" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/woocommerce-germanized/build/static/layout-styles.css?ver=3.20.7 * COEP mit schwacher Konfiguration: unsafe-none; report-to='default' * COOP mit schwacher Konfiguration: unsafe-none ---------------------------------------------------------------------- EMPFEHLUNGEN ---------------------------------------------------------------------- 🔴 Hohe Priorität: - Hochriskante Schwachstellen schnellstmöglich beheben - Alle Komponenten updaten 📋 Allgemeine Empfehlungen: - Regelmäßige Updates durchführen - Backups erstellen - HTTPS erzwingen - Security Headers implementieren - XML-RPC deaktivieren wenn nicht benötigt ====================================================================== SCAN ABGESCHLOSSEN ======================================================================