{"repo":"notmike101/Wordpress-Admin-Persistence-Plugin","free":true,"listed":false,"github":"https://github.com/notmike101/Wordpress-Admin-Persistence-Plugin","clone":"git clone https://github.com/notmike101/Wordpress-Admin-Persistence-Plugin.git","description":"A WordPress plugin designed for educational purposes, demonstrating techniques used in plugin-based persistence and evasion, to aid in security research and training.​","language":"PHP","stars":21,"topics":["educational","persistence","plugin-security","red-team","security-research","wordpress"],"license":"GPL-3.0","category":"self-hosted-apps","readme_excerpt":"Wordpress Admin Persistence Plugin (Educational Purposes Only) Legal & Ethical Disclaimer This plugin is intended strictly for educational use in controlled environments. It demonstrates how WordPress plugins can be abused to maintain persistent administrative access, load unauthorized code, and hide user accounts—behaviors commonly found in malicious plugins. Misuse may violate laws and ethical guidelines. The authors accept no responsibility for unauthorized or malicious use. Do not use this plugin on systems you do not own or have explicit permission to test. Why This Exists Many developers and site owners trust plugins without understanding the access they grant. This project was created to demonstrate how certain plugin structures can be misused to create hidden admin accounts, load arbitrary code, and maintain stealth access - all without leaving obvious traces . This tool was built to: - Demonstrate abuse potential in WordPress's plugin architecture - Encourage thorough review of plugin code and permissions - Educate developers and defenders on plugin-level persistence and stealth techniques It is not intended for exploitation, but to raise awareness and support ethical research. What This Plugin Demonstrates This plugin simulates common WordPress security threats by showcasing: - Hidden creation of an administrator account - Stealth plugin loading from a designated folder ( ./plugins/ ) - Obfuscation of users and plugins in the admin dashboard - A URL-based \"kill swit","default_branch":null,"files":null,"tree":[],"storefront":"/r/notmike101","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/notmike101/Wordpress-Admin-Persistence-Plugin/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}