All skills
automattic avatar

/wp-plugin-development

@95e374f official
by automatticautomattic/agent-skills211 stars
37

Use when developing WordPress plugins: architecture and hooks, activation/deactivation/uninstall, admin UI and Settings API, data storage, cron/tasks, security (nonces/capabilities/sanitization/escaping), and release packaging.

Use this Skill: https://skilld.dev/gh/automattic/agent-skills/wp-plugin-development

This session only. Nothing lands on disk.

referencesdata-and-cron.md

≈170 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Data storage, cron, and upgrades

Use this file when adding persistent storage, background jobs, or upgrade routines.

Data storage

  • Prefer Options API for small config/state.
  • Use custom tables only when needed; store schema version and provide upgrade paths.

Cron

  • Ensure tasks are idempotent (may run late or multiple times).
  • Provide a manual trigger path for debugging (WP-CLI or admin-only action).

Database safety note

If using $wpdb->prepare(), avoid building queries with concatenated user input. Recent WordPress versions support identifier placeholders (%i) but you must not assume it exists without checking capabilities or target versions.

Source: SKILL.md on GitHub

1 warning16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill provides guidance, references, and a non-malicious static analysis utility for WordPress plugin development. No security vulnerabilities or malicious behaviors were detected.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    7/8 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 95e374f. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 5 months ago.

Dormantupdated 9 months ago
Other metadata
compatibility
Targets WordPress 6.9+ (PHP 7.2.24+). Filesystem-based agent with bash + node. Some workflows require WP-CLI.
  • Security
  • wordpress
  • php
  • plugin-development
  • settings-api
  • hooks
  • wp-cli
  • activation-hooks
  • admin-ui
  • sanitization

README badge

README badge for automattic/agent-skills/wp-plugin-development

Develops WordPress plugins with guidance on architecture, hooks, lifecycle management, Settings API for admin UI, security patterns (nonces, capabilities, sanitization), and release packaging. Targets WordPress 6.9+ with PHP 7.2.24+, includes triage scripts and reference docs for common plugin tasks.

Generated from the current SKILL.md.

What WordPress and PHP versions does this skill target?
WordPress 6.9+ and PHP 7.2.24+. Target versions should be specified as input since they affect available APIs and placeholder support in $wpdb->prepare().
Does this skill work with multisite WordPress?
Yes. The skill supports both single-site and multisite setups; you should specify which when providing inputs.
What tools or commands does this skill require?
Filesystem-based workflow using bash and Node.js. Some workflows require WP-CLI for tasks like running migrations or cron jobs manually.
Does this skill handle plugin security (nonces, capabilities, sanitization)?
Yes. The skill covers the full security baseline: input validation/sanitization, output escaping, nonce and capability checks, and safe SQL with $wpdb->prepare().
Can this skill help with plugin activation, deactivation, and uninstall hooks?
Yes. The skill covers lifecycle management including activation/deactivation/uninstall behavior, migrations, schema versioning, and rewrite rule flushing.

Generated from the current SKILL.md. These answers refresh after source changes.