Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill instructs storing a long-lived WordPress application password in a plaintext local .env file under a predictable path, without file-permission guidance or secret-handling warnings. If the host is multi-user, backed up, synced, or otherwise exposed, those credentials can be reused to publish, modify, or deface site content via the WordPress API.
