WordPress Penetration Testing

Warn

Audited by Socket on Feb 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This SKILL.md is a comprehensive and operationally detailed WordPress penetration testing guide that includes explicit, copy-paste exploitation payloads (PHP webshell, bash reverse shell), plugin/theme backdoor instructions, XML-RPC multicall brute-force examples, and guidance for evasion (proxy/Tor, disabling TLS checks). There is no sign of obfuscated or covertly malicious code embedded in the file itself, nor evidence of third-party exfiltration services, but the content directly enables unauthorized compromise if used without explicit written authorization. Treat as high-risk offensive content: restrict distribution, require proof of authorization and operational safeguards, and consider removing or gating directly runnable reverse-shell/webshell snippets from versions accessible to untrusted users.

Confidence: 75%Severity: 80%
Audit Metadata
Analyzed At
Feb 15, 2026, 09:01 PM
Package URL
pkg:socket/skills-sh/zebbern%2Fclaude-code-guide%2Fwordpress-penetration-testing%2F@d36fe284f355c8716e4d1cd1c2b07899684ce77a