wp-playground

Warn

Audited by Runlayer on Feb 21, 2026

Risk Level: MEDIUM
Scan Summary
Max Score
78%
Files
4
Flagged
4
Chunks
4
Flagged Files (4)
SKILL.mdHIGH
78.3%

Malicious tool definition detected

Tool: SKILL.md Description: --- name: wp-playground description: "Use for WordPress Playground workflows: fast disposable WP instances in the browser or locally via @wp-playground/cli (server, run-blueprint, build-snapshot), auto-mounting plugins/themes, switching WP/PHP versions, blueprints, and debugging (Xdebug)." compatibility: "Targets WordPress 6.9+ (PHP 7.2.24+). Playground CLI requires Node.js 20.18+; runs WP in WebAssembly with SQLite." --- # WordPress Playground ## When to use - Spin u

references/blueprints.mdHIGH
78.3%

Malicious tool definition detected

Tool: references/blueprints.md Description: ## Blueprint quick reference Blueprints are JSON recipes that describe how Playground should set up WordPress.

references/cli-commands.mdHIGH
78.3%

Malicious tool definition detected

Tool: references/cli-commands.md Description: ## Playground CLI command cheatsheet > Requires Node.js 20.18+ and npm/npx.

references/debugging.mdHIGH
78.3%

Malicious tool definition detected

Tool: references/debugging.md Description: ## Debugging WordPress Playground - Start CLI with Xdebug: `server --auto-mount --xdebug` (or `--enable-xdebug` depending on release).

Audit Metadata
Max File Score
78%
Classification
UNKNOWN_SERVER
Files Scanned
4
Files Flagged
4
Chunks Analyzed
4
Analyzed
Feb 21, 2026, 02:10 PM
Security Audit — runlayer — wp-playground