recon-daycare

Detect exposed minor PII and WordPress vulnerabilities in daycare websites.

1.1k|191|Updated Jun 24, 2026
One-click install
npx skills add https://github.com/uphiago/recon-skills --skill recon-daycare
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-daycare
Source: https://github.com/uphiago/recon-skills/tree/main/redteam/recon-daycare
Command: npx skills add https://github.com/uphiago/recon-skills --skill recon-daycare

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Daycare and childcare organization websites frequently operate with minimal security investment, storing highly sensitive minor PII (child names, parent contact details, medical info) on underprotected WordPress or custom PHP stacks, making them high-risk targets for unauthorized data access during authorized security assessments.

Core Features & Use Cases

  • Sector-specific domain discovery: Identifies daycare-related domains using common naming conventions, crt.sh queries, and targeted Google dorks tailored to the childcare sector.
  • Prioritized PII exposure checks: Scans for exposed contact form submissions, enrollment records, photo galleries, and debug logs containing sensitive minor and parent data.
  • WordPress-focused recon and vulnerability scanning: Detects common WordPress misconfigurations, unpatched plugins, CORS flaws, and XMLRPC vulnerabilities prevalent on daycare sites.
  • Use case: For a penetration test of a local preschool's web assets, use this skill to quickly locate exposed enrollment PDFs with child PII and unpatched WordPress plugins that could lead to full site compromise.

Quick Start

Use the recon-daycare skill to perform a complete authorized security assessment of the target daycare organization domain, including PII exposure checks and WordPress vulnerability scanning.

Frequently Asked Questions about recon-daycare

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I scan a daycare website for exposed child PII and enrollment records?

To scan for exposed child PII in daycare websites, you can run automated checks targeting exposed contact form submissions, enrollment records, and photo galleries. This process identifies sensitive minor and parent data left unprotected on undersecured servers.

What is the best way to find WordPress vulnerabilities on a preschool's website?

Finding WordPress vulnerabilities on preschool websites involves scanning for common misconfigurations, unpatched plugins, CORS flaws, and XMLRPC issues. This targets the minimal security controls typically found on shared hosting environments used by daycares.

How do I locate daycare-related domains using sector recon techniques?

Locating daycare-related domains uses sector recon techniques like crt.sh queries and targeted Google dorks tailored to childcare naming conventions. This discovers preschool and early-education targets for authorized penetration testing engagements.

Can I use automated reconnaissance to find exposed debug logs on childcare websites?

Yes, you can use automated reconnaissance to find exposed debug logs on childcare websites. The scanning process specifically targets these logs alongside enrollment PDFs to uncover sensitive minor data left exposed by custom PHP stacks.

Do I need authorization to run security checks on early-education organization websites?

Yes, you need explicit authorization to run security checks on early-education organization websites. This reconnaissance is designed strictly for authorized penetration testing engagements targeting daycare domains to identify exposed sensitive medical info and PII.