URL: https://www.pedromagno.com/ [2001:41d0:301:2::31] Started: Mon Dec 22 13:46:14 2025 Interesting Finding(s): Headers | Interesting Entries: | - Server: OVHcloud | - X-Powered-By: PHP/8.4 | - Permissions-Policy: private-state-token-redemption=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com"), private-state-token-issuance=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com") | Found By: Headers (Passive Detection) | Confidence: 100% XML-RPC seems to be enabled: https://www.pedromagno.com/xmlrpc.php | Found By: Direct Access (Aggressive Detection) | Confidence: 100% | References: | - http://codex.wordpress.org/XML-RPC_Pingback_API | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_ghost_scanner/ | - https://www.rapid7.com/db/modules/auxiliary/dos/http/wordpress_xmlrpc_dos/ | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_xmlrpc_login/ | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_pingback_access/ WordPress readme found: https://www.pedromagno.com/readme.html | Found By: Direct Access (Aggressive Detection) | Confidence: 100% Upload directory has listing enabled: https://www.pedromagno.com/wp-content/uploads/ | Found By: Direct Access (Aggressive Detection) | Confidence: 100% The external WP-Cron seems to be enabled: https://www.pedromagno.com/wp-cron.php | Found By: Direct Access (Aggressive Detection) | Confidence: 60% | References: | - https://www.iplocation.net/defend-wordpress-from-ddos | - https://github.com/wpscanteam/wpscan/issues/1299 WordPress version 6.9 identified (Latest, released on 2025-12-02). | Found By: Rss Generator (Aggressive Detection) | - https://pedromagno.com/feed/, https://wordpress.org/?v=6.9 | - https://pedromagno.com/comments/feed/, https://wordpress.org/?v=6.9 The main theme could not be detected. Enumerating Users (via Passive and Aggressive Methods) Brute Forcing Author IDs -: |============================================ No WPScan API Token given, as a result vulnerability data has not been output. You can get a free API token with 25 daily requests by registering at https://wpscan.com/register Finished: Mon Dec 22 13:47:30 2025 Requests Done: 43 Cached Requests: 5 Data Sent: 14.761 KB Data Received: 155.494 KB Memory used: 146.965 MB Elapsed time: 00:01:15 Scan Aborted: Max Scan Duration Reached