Worth looking at
- PHP 7.4 no longer receives security updates
The PHP 7.4 line reached end of life on 28 November 2022. This site runs 7.4.33, the final release on that line.
- Vulnerabilities have been reported against PHP 7.4.33
Reported publicly against this exact version, the most serious rated high. They affect PHP 7.4.33 unless your host has backported the fixes — distribution packages often do, which makes this a question for your hosting provider rather than a conclusion about your site.
- Certificate expires soon
19 days remaining (expires 15.09.2026). The validity period suggests it is renewed by hand, so somebody has to remember.
- WordPress 6.4.3 is behind its own release line
The 6.4 line has since reached 6.4.5, which includes the security fixes released for it in the meantime.
- Server is slow to respond
First response took 1,840 ms.
- HSTS is not configured
Without it, a visitor typing the address can still be sent over plain HTTP first.
Working well
- HTTPS is available and HTTP redirects to it
- Certificate chain is complete and trusted
- Session cookies carry the Secure and HttpOnly flags
- robots.txt and sitemap.xml are present
- No mixed content on the homepage
Detected
WordPress 6.4.3PHP 7.4.33Nginx 1.18.0Cloudflare