What problem does it solve?
This Skill addresses the challenge of identifying easily exploitable vulnerabilities in church, religious organization, and non-profit websites, which are frequently low-budget, volunteer-maintained WordPress instances with minimal security hardening and no dedicated security teams, making them high-priority, low-effort targets for authorized penetration testing and reconnaissance.
Core Features & Use Cases
- Sector-specific domain discovery: Automatically identifies common naming patterns for religious organization domains including <churchname>.org, <city>fbc.org, and <denomination>-<city>.org structures via certificate transparency logs.
- Targeted WordPress recon workflows: Detects the most common high-severity flaws in this sector, including CORS credential reflection, open XMLRPC endpoints, exposed debug logs, outdated plugins, and accessible PHPInfo/config files.
- Pre-built attack chains: Includes validated exploit chains for common vulnerability combinations found in church sites, such as CORS + user enumeration leading to account takeover, and XMLRPC multicall brute force.
- Use Case: For a pentest engagement covering non-profit sector clients, use this Skill to quickly map all associated religious organization domains and scan them for unpatched WordPress vulnerabilities without manual configuration of generic recon tools.
Quick Start
Use the recon-churches skill to scan all identified church and religious organization domains for common WordPress security flaws including CORS misconfigurations, open XMLRPC endpoints, and exposed debug logs.