elementor-mcp-wordpress-builder

Fail

Audited by Snyk on Jun 22, 2026

Risk Level: CRITICAL
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The prompt explicitly shows inserting Application Passwords / base64-encoded "Authorization" headers and environment variables (WP_USERNAME, WP_APP_PASSWORD) into JSON/config files, which would require an agent to output secret values verbatim and thus poses an exfiltration risk.

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.70). The URLs point to a third‑party GitHub repo/user (msrbuilds), an associated npm package scope and custom domains/subdomains used to distribute a WordPress plugin and proxy — which is common practice but poses a moderate-to-high risk because the upstream account and packages are not known/verified (GitHub releases and npx installs from unvetted authors can deliver arbitrary code), while some URLs (WordPress/Elementor docs, WordPress mcp-adapter) are legitimate and reduce overall risk.

Issues (2)

W007
HIGH

Insecure credential handling detected in skill instructions.

E005
CRITICAL

Suspicious download URL detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 22, 2026, 12:52 AM
Issues
2
Security Audit — snyk — elementor-mcp-wordpress-builder