WordPress Hardening
A defensive-security skill for diagnosing and hardening WordPress installations, with a focus on shared-hosting environments where one compromised sub can pivot across the whole account.
When to invoke
Trigger this skill when any of these signals appear:
wp-content/uploads/**/*.phpexists (uploads should never contain PHP)- Admin users you do not recognize, or
wp_usersentries with creation dates that don't match the site history wp-config.phpmodified
[Description truncada. Veja o README completo no GitHub.]