wordpress

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [SAFE]: The skill provides detailed security hardening instructions, including the use of nonces, capability checks, and prepared statements to prevent vulnerabilities. It correctly warns against pasting secrets into dashboard editors and promotes environment-based configuration.\n- [EXTERNAL_DOWNLOADS]: Mentions fetching salts from api.wordpress.org, which is the official and well-known service for WordPress security keys.\n- [COMMAND_EXECUTION]: Includes a shell script (scripts/verify.sh) for static analysis. The script uses standard tools like find and grep to identify anti-patterns in code without modifying files. It is a read-only diagnostic utility.\n- [REMOTE_CODE_EXECUTION]: Suggests using npx to run @wordpress/create-block for scaffolding projects, which is a standard developer tool from a well-known organization.\n- [SAFE]: Encourages the use of Application Passwords for API authentication, promoting secure machine-to-machine communication over legacy password sharing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:38 PM
Security Audit — agent-trust-hub — wordpress