elementor-mcp-wordpress-builder
Fail
Audited by Snyk on Jun 22, 2026
Risk Level: CRITICAL
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The prompt explicitly shows inserting Application Passwords / base64-encoded "Authorization" headers and environment variables (WP_USERNAME, WP_APP_PASSWORD) into JSON/config files, which would require an agent to output secret values verbatim and thus poses an exfiltration risk.
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.70). The URLs point to a third‑party GitHub repo/user (msrbuilds), an associated npm package scope and custom domains/subdomains used to distribute a WordPress plugin and proxy — which is common practice but poses a moderate-to-high risk because the upstream account and packages are not known/verified (GitHub releases and npx installs from unvetted authors can deliver arbitrary code), while some URLs (WordPress/Elementor docs, WordPress mcp-adapter) are legitimate and reduce overall risk.
Issues (2)
W007
HIGHInsecure credential handling detected in skill instructions.
E005
CRITICALSuspicious download URL detected in skill instructions.
Audit Metadata