please remove MAL:url from site

it was hacked with script injection but now is a clear site
http://www.altuofianco.it/
scaned with http://www.urlvoid.com/scan/altuofianco.it/ No active threats were reported by the scanning engines.

You can report a URL here: https://www.avast.com/report-a-url.php

Something to fix: http://retire.insecurity.today/#!/scan/093f0e4748d0b029b080a1c6274e15631fb4590247e421a1606cdb854994328b

Outdated wordpress > https://sitecheck.sucuri.net/results/www.altuofianco.it

Outdated is not bad thinks is a lot of plugins and themes thad dont support udated wordpress so it cant be updated

Using a outdated Wordpres version sure is bad as security flaws are not patched.

Vulnerable library :
http://retire.insecurity.today/#!/scan/96112f7e8cbfe1188f1ec7902be8b513159ce0181550528ba4eee183deeb6caa

Outdated software :
Wordpress 4.5.2 Version does not appear to be latest 4.6.1 - update now.
contact-form-7 4.4.1 latest release (4.5.1)

Security risk due to bad configuration :
Warning User Enumeration is possible
The first two user ID’s were tested to determine if user enumeration is possible.
ID User Login
1 None
2 None altuofianco

Warning Directory Indexing Enabled

Browser difference and link to blacklisted domain :
https://www.websicherheit.at/website-malware-viren-scanner/?url=www.altuofianco.it

Blacklisted :
https://www.virustotal.com/en/url/ff24c658dba7fde90fcf412a730d5367e418a6ea6f56280d7dc684fe9fcc9851/analysis/1477727276/

Blacklisting on that ASN for spreading malware :
http://urlquery.net/report.php?id=1477727329959

@radulet,

What Pondus and Eddy state here, means the site is insecure (less secure). URLquery dot net does not alert that site!
Why Avast blocks it is for an Avast Team Member to explain, as we here are volunteers with relevant knowledge,
but only Avast Team Members can unblock your site or clear the blacklisting status.

Main thing found is cloaking. There is a difference of 712 bytes between the version of the page you serve to Chrome and the version you serve to GoogleBot. This probably means some code is running on your site that’s trying to hide from browsers but make Google think there’s something else on the page. See: http://isithacked.com/check/http%3A%2F%2Fwww.altuofianco.it%2F
This is just like Eddy mentioned as detected by the Bruce Jackson site scan results (website malware / virus scan).

See how this works through onto e.g. duniacargo dot com code: http://www.domxssscanner.com/scan?url=http%3A%2F%2Fwww.altuofianco.it%2Fwp-content%2Fthemes%2Fenfold%2Fjs%2Fhtml5shiv.js
Re: -http://www.mythemedetector.com/camyno-child-wordpress-website-template-36822/deepandsunshine.com-11792679

For the raw and dirty general WordPress issues see: https://hackertarget.com/wordpress-security-scan/ results,
if you wanna see again what Eddy detailed out.

Furthermore there are issues with same origin here:

Stylesheet item:
Tag Result

Missing SRI hash

A meagre F-Status here: https://observatory.mozilla.org/analyze.html?host=www.altuofianco.it
and DNS issues: http://www.dnsinspect.com/altuofianco.it/1477740829

So there is certainly room for security improvements on website security. Update, patch and mitigate.

polonus (volunteer website security analyst and website error-hunter)

[b]Blacklisting for spreading malware [/b]: http://urlquery.net/report.php?id=1477727329959
Eddy ... where in urlQuery do you see this?

altuofianco[.]it is now unblocked, but please, radulet, update to the latest version or it is only a matter of time before it is blocked again.