wordpress-penetration-testing

Fail

Audited by Socket on Sep 6, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

High-risk offensive security skill. Its capabilities are internally consistent with WordPress penetration testing, and the WPScan token flow appears to use the official service, but the skill materially enables scanning, brute-force attacks, exploitation, webshell/reverse-shell deployment, and TLS-check disabling. This is not confirmed malware, but it is a dangerous pentesting skill that should be treated as vulnerable/high risk.

Confidence: 89%Severity: 82%
MalwareHIGH
references/detailed-guide.md

This fragment is an explicit, end-to-end WordPress intrusion/exploitation playbook. It includes weaponized payloads (PHP webshell executing $_GET['cmd'], reverse-shell instructions to attacker-controlled LHOST) and actionable chaining of enumeration, brute-force login, and post-auth shell installation (theme editor/plugin upload and Metasploit guidance). In a supply-chain security context, it is best treated as malicious content with maximal security risk rather than legitimate code. No benign dependency functionality is evidenced.

Confidence: 90%Severity: 100%
Audit Metadata
Analyzed At
Sep 6, 2026, 08:29 AM
Package URL
pkg:socket/skills-sh/sickn33%2Fagentic-awesome-skills%2Fwordpress-penetration-testing%2F@adc30eafc8a80f756d1d216d04efd1b83548f4e7f122242439503ce5147177bd
Security Audit — socket — wordpress-penetration-testing