WordPress Penetration Testing

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is an explicit offensive penetration-testing playbook for WordPress containing detailed, actionable exploitation steps (enumeration, brute-force, webshell creation, reverse shells, Metasploit usage). For legitimate, authorized security testing it is coherent with its stated purpose; however, it provides step-by-step weaponization guidance that enables credential harvesting, remote code execution, persistence, and data exfiltration. The document recommends techniques that weaken security (disabling TLS checks, proxy/anonymize) and shows how to create/upload backdoors. If used without written authorization it is illegal and malicious. From a supply-chain perspective there is no hidden obfuscation or encoded payloads in this file itself, but the described flows and sinks are high-risk. Overall this is a high-risk, dual-use offensive skill: acceptable only for authorized security professionals with strict controls. Exercise strong operational and legal safeguards before using these instructions.

Confidence: 85%Severity: 75%
Audit Metadata
Analyzed At
Feb 27, 2026, 11:48 PM
Package URL
pkg:socket/skills-sh/johnkmcleod9%2Fantigravity-skills-workflows%2Fwordpress-penetration-testing%2F@b187065b582f62b4acb2bbaa070e3839f71d9bcf