Please remove my website the Avast blacklist


Please remove my website from the Avast blacklist.

This is a false-positive and there is 0 malicious/phishing code on this website, domain, or IP.

I have already submitted this website in

This is defaming and causing harm to my business and this is not acceptable. We are not a harmful phishing or a malicious website.

My email is [redacted]

Thank you

Tyler Trowbridge

Outdated Software Detected ( Wordpress )

Also update the CMS plug-ins, a liability allways:
WordPress Plugins
The following plugins were detected by reading the HTML source of the WordPress sites front page.

wordpress-seo 9.3 latest release (12.8.1)
contact-form-7 5.1.6 latest release (5.1.6)
Plugins are a source of many security vulnerabilities within WordPress installations, always keep them updated to the latest version available and check the developers plugin page for information about security related updates and fixes.

There are likely more plugins installed than those listed here as the detection method used here is passive. While these results give an indication of the status of plugin updates, a more comprehensive assessment should be undertaken by brute forcing the plugin paths using a dedicated tool.

Mitigate with recommendations here:

JQuery library to retire:
jquery 1.12.4 Found in -
Vulnerability info:
Medium 2432 3rd party CORS request may execute CVE-2015-9251
Medium CVE-2015-9251 11974 parseHTML() executes scripts in event handlers
Low CVE-2019-11358 jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, …) because of Object.prototype pollution

JS error -
ReferenceError: grecaptcha is not defined

Adblockers block 25% of ads on website…

polonus (volunteer 3rd party cold recon website security analyst and website error-hunter)

Quote from one of the other threads.

22/tcp open ssh OpenSSH 6.7p1 Debian 5+deb8u8 (protocol 2.0)


Nmap scan report for (
Host is up (0.021s latency).
rDNS record for
Not shown: 997 filtered ports
[b]22/tcp  open  ssh      OpenSSH 6.7p1 Debian 5+deb8u8 (protocol 2.0)[/b]
| ssh-hostkey: 
|   1024 6e:8b:22:0c:3e:63:6d:dd:59:80:9e:49:ed:84:67:b8 (DSA)
|_  2048 fc:c3:ae:4a:53:e7:ec:33:c6:5b:42:d8:c6:4f:d9:f3 (RSA)
80/tcp  open  http     nginx
|_http-favicon: Unknown favicon MD5: D41D8CD98F00B204E9800998ECF8427E
| http-methods: 
|_  Supported Methods: POST OPTIONS
|_http-title: Did not follow redirect to
443/tcp open  ssl/http nginx
|_http-generator: Powered by WPBakery Page Builder - drag and drop page builder for WordPress.
| http-methods: 
|_  Supported Methods: GET HEAD
|_http-title: House Painters | $375 Residential Paint Special
| ssl-cert: Subject:
| Subject Alternative Name:
| Issuer: commonName=Let's Encrypt Authority X3/organizationName=Let's Encrypt/countryName=US
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2020-01-07T19:10:09
| Not valid after:  2020-04-06T19:10:09
| MD5:   a50b 8238 7267 6977 9b03 37aa c747 f2a9
|_SHA-1: ca38 8d8e 0c56 b852 cc31 8ea2 2f8c 310c 00b2 5b5f
|_ssl-date: TLS randomness does not represent time
| tls-alpn: 
|   h2
|_  http/1.1
| tls-nextprotoneg: 
|   h2
|_  http/1.1
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose
Running: Linux 3.X|4.X
OS CPE: cpe:/o:linux:linux_kernel:3.13 cpe:/o:linux:linux_kernel:4.2
OS details: Linux 3.13 or 4.2
Uptime guess: 44.171 days (since Tue Dec 03 16:47:30 2019)
Network Distance: 14 hops
TCP Sequence Prediction: Difficulty=262 (Good luck!)
IP ID Sequence Generation: All zeros
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

You’re running on Debian 5?! We’re into Debian 11. Your operating system was released in 2009. It’s not fit to be public facing, under ANY circumstance. It’s old, outdated and EXTREMELY vulnerable to attack. The same issues are present on the other sites, which isn’t surprising… given they’re on the same box. Take the website down, and update the host. You are asking to be hacked with an OS like that. We don’t see OSes that out of date in HackTheBox.

There are literal pages of local priv esc for your host on exploit-DB that would be used in combination with an outdated WP install and plugins. Let me rephrase, you’re not asking, you’re on your knees begging for an attacker to come along and abuse the websites.

Site not being blocked.

The URL provided does not appear to be detected by Avast. Could you send us a screenshot of the detection message you are receiving?