URL: https://nomoredebts.org/ [141.193.213.20]
Started: Mon Jul 28 09:22:00 2025
Interesting Finding(s):
Headers
| Interesting Entries:
| - x-powered-by: WP Engine
| - Accept-CH: Sec-CH-UA-Mobile
| - X-Nitro-Cache: MISS
| - X-Nitro-Disabled-Reason: url not allowed
| - X-Nitro-Disabled: 1
| - X-Cacheable: NO:NitroMISS
| - X-Cache-Group: normal
| - X-Orig-Cache-Control: no-cache
| - cf-cache-status: DYNAMIC
| - Server: cloudflare
| - CF-RAY: 9665b649fd212a9a-LAX
| - alt-svc: h3=":443"; ma=86400
| Found By: Headers (Passive Detection)
| Confidence: 100%
robots.txt found: https://nomoredebts.org/robots.txt
| Interesting Entries:
| - /wp-content/uploads/
| - /wp-content/et-cache/
| - /wp-admin/admin-ajax.php
| - /wp-includes/js/
| - /wp-includes/images/
| - /wp-content/plugins/
| - /wp-content/themes/
| - /wp-admin/
| - /readme.html
| - /trackback/
| - /refer/
| - /wp-includes/
| - /wp-content/cache/
| - /wp-content/cache/min/
| - /xmlrpc.php
| - /wp-
| - /feed/
| - */feed/
| - */trackback/
| - /cgi-bin/
| - /wp-login/
| - /wp-register/
| - */author
| - */tag
| - /*?
| - /*/feed$
| Found By: Robots Txt (Aggressive Detection)
| Confidence: 100%
XML-RPC seems to be enabled: https://nomoredebts.org/xmlrpc.php
| Found By: Link Tag (Passive Detection)
| Confidence: 30%
| References:
| - http://codex.wordpress.org/XML-RPC_Pingback_API
| - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_ghost_scanner/
| - https://www.rapid7.com/db/modules/auxiliary/dos/http/wordpress_xmlrpc_dos/
| - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_xmlrpc_login/
| - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_pingback_access/
This site has 'Must Use Plugins': https://nomoredebts.org/wp-content/mu-plugins/
| Found By: Direct Access (Aggressive Detection)
| Confidence: 80%
| Reference: http://codex.wordpress.org/Must_Use_Plugins
The external WP-Cron seems to be enabled: https://nomoredebts.org/wp-cron.php
| Found By: Direct Access (Aggressive Detection)
| Confidence: 60%
| References:
| - https://www.iplocation.net/defend-wordpress-from-ddos
| - https://github.com/wpscanteam/wpscan/issues/1299
WordPress version 6.8.1 identified (Outdated, released on 2025-04-30).
| Found By: Rss Generator (Passive Detection)
| - https://nomoredebts.org/feed, https://wordpress.org/?v=6.8.1
| - https://nomoredebts.org/comments/feed, https://wordpress.org/?v=6.8.1
WordPress theme in use: divi-child
| Location: https://nomoredebts.org/wp-content/themes/divi-child/
| Style URL: https://nomoredebts.org/wp-content/themes/divi-child/style.css?ver=4.27.4
| Style Name: CCS Divi Child Theme
| Style URI: https://www.elegantthemes.com/gallery/divi/
| Description: Divi Child Theme...
| Author: Josh Hunt - Credit Counselling Society
| Author URI: https://dev.mydebtsolution.ca/
|
| Found By: Css Style In Homepage (Passive Detection)
| Confirmed By: Css Style In 404 Page (Passive Detection)
|
| Version: 1.0.0 (80% confidence)
| Found By: Style (Passive Detection)
| - https://nomoredebts.org/wp-content/themes/divi-child/style.css?ver=4.27.4, Match: 'Version: 1.0.0'
Enumerating Users (via Passive and Aggressive Methods)
Brute Forcing Author IDs -: |=================================================|
User(s) Identified:
Garrett Johnson
| Found By: Rss Generator (Passive Detection)
| Confirmed By: Rss Generator (Aggressive Detection)
Josh Hunt
| Found By: Rss Generator (Passive Detection)
| Confirmed By: Rss Generator (Aggressive Detection)
ccs
| Found By: Wp Json Api (Aggressive Detection)
| - https://nomoredebts.org/wp-json/wp/v2/users/?per_page=100&page=1
charlenes
| Found By: Wp Json Api (Aggressive Detection)
| - https://nomoredebts.org/wp-json/wp/v2/users/?per_page=100&page=1
garrett-johnson
| Found By: Wp Json Api (Aggressive Detection)
| - https://nomoredebts.org/wp-json/wp/v2/users/?per_page=100&page=1
jlock
| Found By: Wp Json Api (Aggressive Detection)
| - https://nomoredebts.org/wp-json/wp/v2/users/?per_page=100&page=1
joshh
| Found By: Wp Json Api (Aggressive Detection)
| - https://nomoredebts.org/wp-json/wp/v2/users/?per_page=100&page=1
| Confirmed By: Oembed API - Author URL (Aggressive Detection)
| - https://nomoredebts.org/wp-json/oembed/1.0/embed?url=https://nomoredebts.org/&format=json
juliej
| Found By: Wp Json Api (Aggressive Detection)
| - https://nomoredebts.org/wp-json/wp/v2/users/?per_page=100&page=1
kevins
| Found By: Wp Json Api (Aggressive Detection)
| - https://nomoredebts.org/wp-json/wp/v2/users/?per_page=100&page=1
monika
| Found By: Wp Json Api (Aggressive Detection)
| - https://nomoredebts.org/wp-json/wp/v2/users/?per_page=100&page=1
searchbloom
| Found By: Wp Json Api (Aggressive Detection)
| - https://nomoredebts.org/wp-json/wp/v2/users/?per_page=100&page=1
yi
| Found By: Wp Json Api (Aggressive Detection)
| - https://nomoredebts.org/wp-json/wp/v2/users/?per_page=100&page=1
No WPScan API Token given, as a result vulnerability data has not been output.
You can get a free API token with 25 daily requests by registering at https://wpscan.com/register
Finished: Mon Jul 28 09:22:19 2025
Requests Done: 55
Cached Requests: 8
Data Sent: 27.251 KB
Data Received: 1.225 MB
Memory used: 187.047 MB
Elapsed time: 00:00:18