elementor-mcp-wordpress-builder

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The core capability is coherent with the skill's purpose, and the primary API target is the user's own WordPress site. Risk comes from the recommended unpinned npx proxy, credential forwarding to third-party code, and cross-publisher trust plus stale endpoint documentation; this is more risky than a simple docs skill, but not fundamentally incompatible with its stated purpose.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Sep 16, 2026, 10:34 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fmcp-skills%2Felementor-mcp-wordpress-builder%2F@9d833fd309b1db015d6e5ce8f443b0a5c96ff027935045f6dc61c8ec71e212a5
Security Audit — socket — elementor-mcp-wordpress-builder