All skills
automattic avatar

/wp-plugin-development

@95e374f official
by automatticautomattic/agent-skills211 stars
37

Use when developing WordPress plugins: architecture and hooks, activation/deactivation/uninstall, admin UI and Settings API, data storage, cron/tasks, security (nonces/capabilities/sanitization/escaping), and release packaging.

Use this Skill: https://skilld.dev/gh/automattic/agent-skills/wp-plugin-development

This session only. Nothing lands on disk.

referencesstructure.md

≈101 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Plugin structure and loading

Use this file when introducing or refactoring a plugin architecture.

Core concepts

  • Main plugin file contains the plugin header and bootstraps the plugin.
  • Prefer predictable init:
    • minimal boot file
    • a loader/class that registers hooks
    • admin-only code behind admin hooks

Upstream reference:

Source: SKILL.md on GitHub

1 warning16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill provides guidance, references, and a non-malicious static analysis utility for WordPress plugin development. No security vulnerabilities or malicious behaviors were detected.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    7/8 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 95e374f. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 5 months ago.

Dormantupdated 9 months ago
Other metadata
compatibility
Targets WordPress 6.9+ (PHP 7.2.24+). Filesystem-based agent with bash + node. Some workflows require WP-CLI.
  • Security
  • wordpress
  • php
  • plugin-development
  • settings-api
  • hooks
  • wp-cli
  • activation-hooks
  • admin-ui
  • sanitization

README badge

README badge for automattic/agent-skills/wp-plugin-development

Develops WordPress plugins with guidance on architecture, hooks, lifecycle management, Settings API for admin UI, security patterns (nonces, capabilities, sanitization), and release packaging. Targets WordPress 6.9+ with PHP 7.2.24+, includes triage scripts and reference docs for common plugin tasks.

Generated from the current SKILL.md.

What WordPress and PHP versions does this skill target?
WordPress 6.9+ and PHP 7.2.24+. Target versions should be specified as input since they affect available APIs and placeholder support in $wpdb->prepare().
Does this skill work with multisite WordPress?
Yes. The skill supports both single-site and multisite setups; you should specify which when providing inputs.
What tools or commands does this skill require?
Filesystem-based workflow using bash and Node.js. Some workflows require WP-CLI for tasks like running migrations or cron jobs manually.
Does this skill handle plugin security (nonces, capabilities, sanitization)?
Yes. The skill covers the full security baseline: input validation/sanitization, output escaping, nonce and capability checks, and safe SQL with $wpdb->prepare().
Can this skill help with plugin activation, deactivation, and uninstall hooks?
Yes. The skill covers lifecycle management including activation/deactivation/uninstall behavior, migrations, schema versioning, and rewrite rule flushing.

Generated from the current SKILL.md. These answers refresh after source changes.