wp-mass-recon

Warn

Audited by Socket on Jul 31, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill: it is internally consistent as a mass WordPress recon tool, but it gives an AI agent offensive security capabilities, probes sensitive files at scale, and disables TLS verification. There is no strong evidence of malware or credential theft from the operator, yet the real-world scanning and exploit-recon footprint makes it dangerous.

Confidence: 93%Severity: 88%
AnomalyLOW
scripts/scanner.py

This module is an active web reconnaissance/scanner targeting likely WordPress deployments. It performs network probing via curl, enumerates exposed WordPress users, checks credentialed CORS misconfiguration using a hostile Origin (evil.com), probes XML-RPC for multicall, checks for open registration, and searches for exposed sensitive files/backup configs by keyword matching. It then writes detailed markdown/JSON reports including an exfiltration-style PoC snippet to 'https://evil.com'. While it does not show classic malware actions like local credential theft or persistence, its dual-use scanning/exploitation intent makes it security-relevant; unexpected inclusion in a dependency would be high concern.

Confidence: 78%Severity: 68%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:51 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fwp-mass-recon%2F@79a8818e6d62784b55500d01ace536d1920142cfcad3b987c55ecd20fe116ba4
Security Audit — socket — wp-mass-recon