Automatic SQL injection and database takeover tool
api's get_option function doesn't lookup the right object