WordPress Penetration Testing

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is an explicit offensive pentesting guide for WordPress that honestly documents discovery, enumeration, brute-force, and exploitation techniques including webshells and reverse shells. The capabilities align with the stated purpose of penetration testing (so the content is coherent), but the inclusion of ready-made exploit code (PHP webshell, reverse shell), high-throughput brute-force guidance, and detection-evasion techniques creates a high potential for abuse if used without strict authorization. This makes the skill 'suspicious' from a supply-chain perspective: its functionality is legitimate in authorized testing contexts but dangerous if distributed or invoked without controls. Recommend restricting access, adding clear mandatory authorization checks and logging requirements, and removing or gating explicit exploitation payload templates in public/shared skills.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Feb 16, 2026, 10:27 AM
Package URL
pkg:socket/skills-sh/jpropato%2Fsiba%2Fwordpress-penetration-testing%2F@4cf530691c3c96269e04bb8e19db455b02ad6c15