elementor-mcp-wordpress-builder
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The core capability is coherent with the skill's purpose, and the primary API target is the user's own WordPress site. Risk comes from the recommended unpinned npx proxy, credential forwarding to third-party code, and cross-publisher trust plus stale endpoint documentation; this is more risky than a simple docs skill, but not fundamentally incompatible with its stated purpose.
Confidence: 88%Severity: 72%
Audit Metadata