All skills
michtio avatar

/craft-plugins

@44a2800

Index and router for plugin-specific Craft CMS 5 guidance — configuration, Twig API, PHP API, migrations, deployment, and pitfalls for the plugins this pack documents. Triggers whenever a task names one of these plugins in ANY context (build, configure, style, render, query, import, migrate, deploy, cache, debug): Formie (forms, submissions, File Upload, form in a migration, notifications, translations), SEOmatic (meta, sitemaps, JSON-LD, SEO field), Blitz (static/page caching, purge), Feed Me (XML/JSON/CSV import), Imager-X (transforms, srcset, quick syntax, named transforms, Power Pack, pppicture, ppimg), ImageOptimize (OptimizedImages), CKEditor (rich text, nested entries), Sprig (reactive, htmx), Element API (JSON endpoints), Retour (redirects, 404s), Navigation (nav menus), Hyper (link field), Colour Swatches, Password Policy (HIBP), Typogrify, Cache Igniter, Knock Knock (staging password), Elements Panel (N+1 debug), Sherlock (security scan), Amazon SES (SES/SNS bounce), Embedded Assets (oEmbed), Timeloop (recurring dates), Vite (craft.vite.*, asset bundling), Warp (passwordless login, magic link, one-time code/OTP, passkeys, WebAuthn, craft.warp, member sessions). Also load for passwordless or magic-link auth with NO plugin named. Always load when a task names one of these plugins — read references/<plugin>.md first. Do NOT trigger for Craft core with no plugin named (craftcms), template architecture (craft-site), or content modeling (craft-content-modeling).

Use this Skill: https://skilld.dev/gh/michtio/craftcms-claude-skills/craft-plugins

This session only. Nothing lands on disk.

referencesknock-knock.md

≈536 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Knock Knock

Site-wide password protection by Verbb. Locks the entire front-end behind a password prompt — ideal for staging, client preview, and pre-launch sites. Simple config-file driven, no database tables.

verbb/knock-knock — Free

Documentation

Common Pitfalls

  • Leaving Knock Knock enabled in production — the most common mistake. Use environment-aware config to ensure it's only active on staging/preview.
  • Not excluding health check or webhook URLs — external services (uptime monitors, CI/CD webhooks, n8n) get blocked by the password wall. Exclude their paths.
  • Forgetting that Knock Knock uses a cookie — once authenticated, the cookie persists. If you change the password, existing authenticated sessions remain valid until the cookie expires.

Config File

// config/knock-knock.php
use craft\helpers\App;

return [
    '*' => [
        'enabled' => false,
        'password' => App::env('KNOCK_KNOCK_PASSWORD'),
        'loginPath' => 'knock-knock/who-is-there',
        'template' => '',                    // Custom template path (optional)
        'forcedRedirect' => '',              // Redirect after login (optional)

        // URLs that bypass the password wall
        'unprotectedUrls' => [
            'api/.*',                        // API endpoints
            'actions/.*',                    // Craft action URLs
            'webhooks/.*',                   // Webhook endpoints
        ],
    ],
    'staging' => [
        'enabled' => true,
    ],
    'production' => [
        'enabled' => false,
    ],
];

Environment Setup

Add to .env on staging only:

KNOCK_KNOCK_PASSWORD=clientPreview2025

Custom Login Template

Override the default login page with your own template:

'template' => '_knock-knock/login',

Then create templates/_knock-knock/login.twig with your branded login form.

Pair With

  • Blitz — Knock Knock checks run before Blitz serves cached pages, so protected sites work correctly with static caching.

Source: SKILL.md on GitHub

No alerts16d3 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The 'craft-plugins' skill is a technical reference and router for Craft CMS 5 plugins. It provides guidance on configuration, Twig and PHP APIs, and best practices for popular extensions in the Craft ecosystem. The skill consists of documentation files that describe legitimate plugin behaviors and does not contain any malicious code, obfuscation, or security vulnerabilities.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

Signed by skilld at 44a2800. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 weeks ago.

Activeupdated last month

README badge

README badge for michtio/craftcms-claude-skills/craft-plugins