wordpress-penetration-testing

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This document is an actionable WordPress penetration-testing playbook that contains concrete, high-impact offensive techniques: enumeration, credential brute-force (including XML-RPC multicall), plugin/theme-based persistence, PHP webshell and reverse shell payloads, and evasion tactics (Tor/proxies, disabling TLS). In an authorized test context it is appropriate; however, it is highly dual-use and materially enables unauthorized compromise and data exfiltration if misused. Recommend treating this content as high-risk: enforce strict authorization, operational controls, and prefer sanitized examples (non-functional payloads) or explicit safeguards in shared repositories.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 27, 2026, 11:22 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fwordpress-penetration-testing%2F@d118e5a596326229eef330b98ba8034dca843f5a