URL: https://radhotelgroup.com/ [31.193.136.102] Started: Mon Mar 23 15:27:21 2026 Interesting Finding(s): Headers | Interesting Entries: | - Server: Apache/2.4.29 | - Upgrade: h2 | Found By: Headers (Passive Detection) | Confidence: 100% robots.txt found: https://radhotelgroup.com/robots.txt | Interesting Entries: | - /wp-admin/ | - /wp-admin/admin-ajax.php | Found By: Robots Txt (Aggressive Detection) | Confidence: 100% XML-RPC seems to be enabled: https://radhotelgroup.com/xmlrpc.php | Found By: Direct Access (Aggressive Detection) | Confidence: 100% | References: | - http://codex.wordpress.org/XML-RPC_Pingback_API | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_ghost_scanner/ | - https://www.rapid7.com/db/modules/auxiliary/dos/http/wordpress_xmlrpc_dos/ | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_xmlrpc_login/ | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_pingback_access/ WordPress readme found: https://radhotelgroup.com/readme.html | Found By: Direct Access (Aggressive Detection) | Confidence: 100% This site seems to be a multisite | Found By: Direct Access (Aggressive Detection) | Confidence: 100% | Reference: http://codex.wordpress.org/Glossary#Multisite This site has 'Must Use Plugins': https://radhotelgroup.com/wp-content/mu-plugins/ | Found By: URLs In Homepage (Passive Detection) | Confidence: 100% | Confirmed By: Direct Access (Aggressive Detection), 80% confidence | Reference: http://codex.wordpress.org/Must_Use_Plugins Upload directory has listing enabled: https://radhotelgroup.com/wp-content/uploads/ | Found By: Direct Access (Aggressive Detection) | Confidence: 100% The external WP-Cron seems to be enabled: https://radhotelgroup.com/wp-cron.php | Found By: Direct Access (Aggressive Detection) | Confidence: 60% | References: | - https://www.iplocation.net/defend-wordpress-from-ddos | - https://github.com/wpscanteam/wpscan/issues/1299 WordPress version 5.4.2 identified (Insecure, released on 2020-06-10). | Found By: Most Common Wp Includes Query Parameter In Homepage (Passive Detection) | - https://radhotelgroup.com/wp-includes/css/dist/block-library/style.min.css?ver=5.4.2 | Confirmed By: Style Etag (Aggressive Detection) | - https://radhotelgroup.com/wp-admin/load-styles.php, Match: '5.4.2' WordPress theme in use: rad | Location: https://radhotelgroup.com/wp-content/themes/rad/ | Latest Version: 1.9 | Last Updated: 2017-08-01T00:00:00.000Z | Readme: https://radhotelgroup.com/wp-content/themes/rad/README.md | [31m[!][0m Directory listing is enabled | Style URL: https://radhotelgroup.com/wp-content/themes/rad/style.css | | Found By: Urls In Homepage (Passive Detection) | Confirmed By: Urls In 404 Page (Passive Detection) | | The version could not be determined. Enumerating Users (via Passive and Aggressive Methods) Brute Forcing Author IDs -: |=================================================| No Users Found. No WPScan API Token given, as a result vulnerability data has not been output. You can get a free API token with 25 daily requests by registering at https://wpscan.com/register Finished: Mon Mar 23 15:27:43 2026 Requests Done: 54 Cached Requests: 8 Data Sent: 12.898 KB Data Received: 462.983 KB Memory used: 185.387 MB Elapsed time: 00:00:21