Outdated, exposed, unmonitored
- 52known vulnerabilities in susanrockefeller.com’s WordPress 4.9.1 — including 9 rated critical or high severity.
- 39known vulnerabilities in musingsmag.com’s WordPress 5.5.3 — including SQL injection and code execution flaws.
- •nginx 1.10.3 (released January 2017) serves both sites — version exposed in every HTTP response. Current stable is 1.31.
- •The PHP session cleanup timer was never started — the server filled its file index and couldn’t create new files, breaking SSL renewal and all updates.
Exposed and unhardened
- 0security headers on either site — no Content-Security-Policy, no X-Frame-Options, no Strict-Transport-Security, no X-Content-Type-Options.
- •The REST API exposes user accounts publicly on both sites — names and slugs visible to anyone.
- •No TLS 1.3 support — both sites max out at TLS 1.2. Modern browsers work, but security scanners flag it.
- •Server software versions are exposed in every HTTP response — nginx version, OS, and PHP session cookies are visible to any visitor.
Migrate to managed hosting
- 1Move both sites to Kinsta — managed WordPress hosting with automatic updates, daily backups, free SSL, and 24/7 monitoring.
- 2Update WordPress core and plugins during migration, testing for breaking changes in a staging environment.
- 3Decommission the DO droplets once migration is verified — eliminating the unpatched attack surface entirely.