wp-mass-recon
Audited by Socket on Jul 31, 2026
2 alerts found:
SecurityAnomalySUSPICIOUS/HIGH-RISK skill: it is internally consistent as a mass WordPress recon tool, but it gives an AI agent offensive security capabilities, probes sensitive files at scale, and disables TLS verification. There is no strong evidence of malware or credential theft from the operator, yet the real-world scanning and exploit-recon footprint makes it dangerous.
This module is an active web reconnaissance/scanner targeting likely WordPress deployments. It performs network probing via curl, enumerates exposed WordPress users, checks credentialed CORS misconfiguration using a hostile Origin (evil.com), probes XML-RPC for multicall, checks for open registration, and searches for exposed sensitive files/backup configs by keyword matching. It then writes detailed markdown/JSON reports including an exfiltration-style PoC snippet to 'https://evil.com'. While it does not show classic malware actions like local credential theft or persistence, its dual-use scanning/exploitation intent makes it security-relevant; unexpected inclusion in a dependency would be high concern.