recon-moving-companies

Scan moving company websites for WordPress misconfigurations and exposed customer PII.

1.1k|191|Updated Jun 24, 2026
One-click install
npx skills add https://github.com/uphiago/recon-skills --skill recon-moving-companies
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-moving-companies
Source: https://github.com/uphiago/recon-skills/tree/main/redteam/recon-moving-companies
Command: npx skills add https://github.com/uphiago/recon-skills --skill recon-moving-companies

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Moving and relocation company websites frequently store sensitive customer personally identifiable information (PII) and have unpatched WordPress misconfigurations that generic recon tools often miss, leaving exposed data and exploitable vulnerabilities undetected.

Core Features & Use Cases

  • Sector-Targeted Domain Discovery: Finds moving company, relocation service, and logistics domains using common naming patterns and certificate transparency logs.
  • PII and Form Data Hunting: Locates exposed quote request submissions, customer inventory lists, and move details stored in upload directories and debug logs.
  • WordPress and CRM Recon: Checks for common WordPress vulnerabilities, open XMLRPC endpoints, CORS misconfigurations, and exposed customer tracking portals integrated with moving CRM tools.
  • Use Case: For example, during an authorized penetration test of a regional moving company, this skill can identify an exposed debug log containing customer names, addresses, phone numbers, and move dates, as well as a directory listing with exported quote CSV files.

Quick Start

Use the recon-moving-companies skill to run full sector-specific reconnaissance on the target moving company domain and compile a report of all exposed sensitive data, vulnerable endpoints, and CMS misconfigurations.

Frequently Asked Questions about recon-moving-companies

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I find exposed PII on moving company websites during a pentest?

To find exposed PII on moving company websites, you can scan target domains for exposed quote request submissions, customer inventory lists, and move details stored in upload directories and debug logs. This identifies sensitive customer data leaks.

What is sector recon for WordPress sites and when do I need it?

Sector recon for WordPress sites is the targeted discovery of domains using certificate transparency logs and naming patterns. You need it when authorized penetration testing requires identifying vulnerabilities and exposed data within a specific industry like moving services.

How do I enumerate moving CRM integrations and customer tracking portals?

You can enumerate moving CRM integrations and customer tracking portals by checking target domains for exposed CRM endpoints and misconfigurations. This process maps integrated customer tracking systems and identifies unauthorized access points.

Does this approach find common WordPress plugin vulnerabilities on logistics domains?

Yes, this approach finds common WordPress plugin vulnerabilities on logistics domains by scanning for misconfigurations, open XMLRPC endpoints, and CORS issues. It detects unpatched flaws that generic recon tools often miss on moving company websites.

What is the best way to check WordPress misconfigurations on relocation service websites?

The best way to check WordPress misconfigurations on relocation service websites is to perform targeted sector recon. This identifies open XMLRPC endpoints, CORS misconfigurations, and exposed debug logs containing exported customer quote CSV files.

Can I use sector recon for moving company domains running on shared hosting?

Yes, you can use sector recon for moving company domains running on shared hosting. It is specifically designed to identify WordPress misconfigurations and exposed customer data typical of moving industry domains hosted on shared infrastructure.