https://toolkit-tests.pages.dev/wp/wp-gold
HTTP 200 · redirected · endpoints — wp-json 404 · wp-login 404 · xmlrpc 404 · users 404
A read-only external inventory — what this site is running, inferred from HTTP responses and the homepage markup. Nothing was logged into, changed, or crawled. Confidence dots: high (header/definitive endpoint) · medium (markup heuristic) · low.
| Signal | Value | Basis |
|---|---|---|
| WordPress | yes | generator meta, wp-content paths |
| WP version | 6.5.2 | generator meta |
| Web server | cloudflare | Server header |
| Active theme | twentytwentyfour 6.5.2 | theme asset path |
| Caching | WP Rocket | plugin footprint |
| CDN | Cloudflare | CDN headers |
| Plugin slug | Version (from ?ver=) |
|---|---|
| contact-form-7 | 5.9.2 |
| wordpress-seo | 22.0 |
Only plugins that emit a front-end asset are visible from outside; this is a floor, not a full list.
WordPress inspector · wordpress-inspector verdict: DETECTED url: https://toolkit-tests.pages.dev/wp/wp-gold HTTP 200 · redirected captured: 2026-08-31T12:12:07.274Z endpoints: wp-json 404 · wp-login 404 · xmlrpc 404 · users 404 ENVIRONMENT WordPress: yes [high · generator meta, wp-content paths] WP version: 6.5.2 [high · generator meta] Web server: cloudflare [high · Server header] Active theme: twentytwentyfour 6.5.2 [med · theme asset path] Caching: WP Rocket [med · plugin footprint] CDN: Cloudflare [high · CDN headers] PLUGINS SEEN — 2 - contact-form-7 5.9.2 - wordpress-seo 22.0 SECURITY NOTES [ni] WP version 6.5.2 is publicly exposed (generator/readme) — makes targeted-CVE matching trivial. [ni] Security headers present: x-content-type-options, referrer-policy. WORDPRESS PLAYBOOK wiki disabled (--no-wiki)
wiki disabled (--no-wiki)