wordpress-setup — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited wordpress-setup (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Connect to a WordPress site and verify working access via WP-CLI or REST API. Produces a verified connection config ready for content management and Elementor editing.
wp --versionIf not installed, guide the user:
# macOS/Linux
curl -O https://raw.githubusercontent.com/wp-cli/builds/gh-pages/phar/wp-cli.phar
chmod +x wp-cli.phar
sudo mv wp-cli.phar /usr/local/bin/wpAlso ensure the SSH extension is available (needed for remote sites):
wp package install wp-cli/ssh-commandOption A: WP-CLI over SSH (preferred)
wp --ssh=user@hostname/path/to/wordpress option get siteurlCommon patterns:
wp --ssh=user@hostname/www/sitename/public option get siteurlwp --ssh=user@hostname/public_html option get siteurlTest with a simple command first:
wp --ssh=user@host/path core versionOption B: REST API with Application Password
If SSH isn't available:
https://example.com/wp-admin/profile.php (or use browser automation)Test the connection:
curl -s https://example.com/wp-json/wp/v2/posts?per_page=1 \
-u "username:xxxx xxxx xxxx xxxx xxxx xxxx" | jq '.[0].title'For WP-CLI SSH — create a wp-cli.yml in the project root:
ssh:
sitename:
cmd: ssh -o StrictHostKeyChecking=no %pseudotty% user@hostname %cmd%
url: /path/to/wordpressThen use: wp @sitename option get siteurl
For REST API — store in .dev.vars:
WP_SITE_URL=https://example.com
WP_USERNAME=admin
WP_APP_PASSWORD=xxxx xxxx xxxx xxxx xxxx xxxxEnsure .dev.vars is in .gitignore. For cross-project use, store in your preferred secrets manager (environment variable, 1Password CLI, etc.).
Run a comprehensive check:
# Site info
wp @sitename option get siteurl
wp @sitename option get blogname
# Content access
wp @sitename post list --post_type=page --posts_per_page=5 --fields=ID,post_title,post_status
# Plugin status (check for Elementor)
wp @sitename plugin status elementor
# Theme info
wp @sitename theme statusCreate wordpress.config.json for other skills to reference:
{
"site": "example.com",
"siteUrl": "https://example.com",
"accessMethod": "ssh",
"sshAlias": "sitename",
"wpPath": "/path/to/wordpress",
"hasElementor": true,
"elementorVersion": "3.x.x"
}| Symptom | Fix |
|---|---|
Permission denied (publickey) | Check SSH key: ssh -v user@host |
wp: command not found via SSH | WP-CLI not in remote PATH — use full path: /usr/local/bin/wp |
Error: This does not appear to be a WordPress installation | Wrong path — check wp-path argument |
| Timeout on large operations | Add --ssh=user@host/path --allow-root or increase SSH timeout |
Define aliases in ~/.wp-cli/config.yml for frequently-accessed sites:
@client1:
ssh: [email protected]/www/public
@client2:
ssh: [email protected]/www/client2/publicThen: wp @client1 post list
?_=${timestamp} cache bustershow_in_rest: true to appear in APIreferences/wp-cli-essentials.md — SSH alias patterns, common flags, and troubleshooting~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.