Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The guide instructs users to place a WordPress username and application password directly into persistent OpenClaw configuration, but it does not give concrete guidance on secret handling, file permissions, redaction, or avoiding accidental exposure through logs, screenshots, backups, or version control. Because these credentials grant authenticated access to the target WordPress site, leakage could enable unauthorized API actions against site content and administrative endpoints permitted to that account.
