CMS configuration issues: User Enumeration
The first two user ID's were tested to determine if user enumeration is possible.
ID User Login
1 0x0049 jordan
2 Rachel Ann Nunes rachel
It is recommended to rename the admin user account to reduce the chance of brute force attacks occurring. As this will reduce the chance of automated password attackers gaining access. However it is important to understand that if the author archives are enabled it is usually possible to enumerate all users within a WordPress installation.
Recommendations to improve website and website security, found through linting:
https://webhint.io/scanner/103802ac-5a0f-4b62-996d-168c5b4abf05Wait for a final verdict of an avast team member as they are the only ones to come and unblock,
we are just volunteers with relative knowledge of 3rd party cold recon website security analysis and error-hunting.
See
Detected jQuery libraries to be retired:
jquery 1.11.1 Found in https://ajax.googleapis.com/ajax/libs/jquery/1.11.1/jquery.min.js
Vulnerability info:
Medium 2432 3rd party CORS request may execute CVE-2015-9251
Medium CVE-2015-9251 11974 parseHTML() executes scripts in event handlers
Low CVE-2019-11358 jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution
I do not see the website being blocked by avast's at the moment.
polonus (volunteer 3rd party cold recon website security analyzer and website error-hunter)