An evolving recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh
-
Updated
Jul 25, 2026 - Python
An evolving recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh
Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.
WPScan rewritten in Python + some WPSeku ideas
The vulnerable version of WordPress that is updated monthly.
Advanced web security scanner with 49 modules, evasion engine, and CVE database.
Professional Agent Skill for building, auditing, testing, and releasing modern WordPress plugins with Codex, Cursor, and Claude Code.
Concluded research prototype — do not install. Final finding: github.com/dknauss/Sudo/blob/main/docs/finding.md
Useful plugin that will scan your theme templates for malicious injections. Automatically. Every day. For more blog security.
A command line took to check the WPScan Vulnerability Database via API to identify the security issues of WordPress plugins installed.
A wordpress security auditor! Audit your wordpress application for security issues with even 1 request.
WPAUDIT: Advanced WordPress security auditing suite & vulnerability scanner. Automates pentesting with Nmap, WPScan, Nuclei, SQLMap. Comprehensive reports. Ideal for ethical hackers & Kali Linux.
AI SKILL.md files
Apache configuration and useful functions for more secure and performant Wordpress sites.
wordpress security best practice
fail2ban setup for centminmod.com LEMP stack with CSF Firewall
Prevents users from being logged into the same WordPress site from multiple places.
Advanced use of WPScan (WordPress Security Scanner) with other tools like nmap, nikto, owasp-zap, ids for ethnical Hackers
Audit, clean, and harden a WordPress site end to end, with an AI agent (Claude/Cursor/Codex/MCP or SSH). Detects & removes hidden malware — cloaking, backdoors, database injection — scores your security posture, and hardens safely. Free, open-source (AGPL-3.0).
Simple Bash Script For Collecting Wordpress Username
Add a description, image, and links to the wordpress-security topic page so that developers can more easily learn about it.
To associate your repository with the wordpress-security topic, visit your repo's landing page and select "manage topics."