All skills
wordpress avatar

/wp-plugin-development

@20324d2 official
by wordpresswordpress/agent-skills2.2k stars
327

Use when developing WordPress plugins: architecture and hooks, activation/deactivation/uninstall, admin UI and Settings API, data storage, cron/tasks, security (nonces/capabilities/sanitization/escaping), and release packaging.

Use this Skill: https://skilld.dev/gh/wordpress/agent-skills/wp-plugin-development

This session only. Nothing lands on disk.

SKILL.md

≈63 tokens always: the name and description. ≈898 when used: this file. ≈1.2k more on demand in 6 files.

WP Plugin Development

When to use

Use this skill for plugin work such as:

  • creating or refactoring plugin structure (bootstrap, includes, namespaces/classes)
  • adding hooks/actions/filters
  • activation/deactivation/uninstall behavior and migrations
  • adding settings pages / options / admin UI (Settings API)
  • security fixes (nonces, capabilities, sanitization/escaping, SQL safety)
  • packaging a release (build artifacts, readme, assets)

Inputs required

  • Repo root + target plugin(s) (path to plugin main file if known).
  • Where this plugin runs: single site vs multisite; WP.com conventions if applicable.
  • Target WordPress + PHP versions (affects available APIs and placeholder support in $wpdb->prepare()).

Procedure

0) Triage and locate plugin entrypoints

  1. Run triage:
    • node skills/wp-project-triage/scripts/detect_wp_project.mjs
  2. Detect plugin headers (deterministic scan):
    • node skills/wp-plugin-development/scripts/detect_plugins.mjs

If this is a full site repo, pick the specific plugin under wp-content/plugins/ or mu-plugins/ before changing code.

1) Follow a predictable architecture

Guidelines:

  • Keep a single bootstrap (main plugin file with header).
  • Avoid heavy side effects at file load time; load on hooks.
  • Prefer a dedicated loader/class to register hooks.
  • Keep admin-only code behind is_admin() (or admin hooks) to reduce frontend overhead.

See:

  • references/structure.md

2) Hooks and lifecycle (activation/deactivation/uninstall)

Activation hooks are fragile; follow guardrails:

  • register activation/deactivation hooks at top-level, not inside other hooks
  • flush rewrite rules only when needed and only after registering CPTs/rules
  • uninstall should be explicit and safe (uninstall.php or register_uninstall_hook)

See:

  • references/lifecycle.md

3) Settings and admin UI (Settings API)

Prefer Settings API for options:

  • register_setting(), add_settings_section(), add_settings_field()
  • sanitize via sanitize_callback

See:

  • references/settings-api.md

4) Security baseline (always)

Before shipping:

  • Validate/sanitize input early; escape output late.
  • Use nonces to prevent CSRF and capability checks for authorization.
  • Avoid directly trusting $_POST / $_GET; use wp_unslash() and specific keys.
  • Use $wpdb->prepare() for SQL; avoid building SQL with string concatenation.

See:

  • references/security.md

5) Data storage, cron, migrations (if needed)

  • Prefer options for small config; custom tables only if necessary.
  • For cron tasks, ensure idempotency and provide manual run paths (WP-CLI or admin).
  • For schema changes, write upgrade routines and store schema version.

See:

  • references/data-and-cron.md

Verification

  • Plugin activates with no fatals/notices.
  • Settings save and read correctly (capability + nonce enforced).
  • Uninstall removes intended data (and nothing else).
  • Run repo lint/tests (PHPUnit/PHPCS if present) and any JS build steps if the plugin ships assets.

Failure modes / debugging

  • Activation hook not firing:
    • hook registered incorrectly (not in main file scope), wrong main file path, or plugin is network-activated
  • Settings not saving:
    • settings not registered, wrong option group, missing capability, nonce failure
  • Security regressions:
    • nonce present but missing capability checks; or sanitized input not escaped on output

See:

  • references/debugging.md

Escalation

For canonical detail, consult the Plugin Handbook and security guidelines before inventing patterns.

Source: SKILL.md on GitHub

1 warning9d5 checks · Risk SAFE
  • Gen Agent Trust Hub9d

    This skill provides a structured workflow and discovery tools for WordPress plugin development, emphasizing security best practices. No malicious behaviors or security risks were identified.

  • Socket9d

    No alerts

  • Snyk9d

    Risk: LOW · No issues

  • Runlayer7mo

    6/8 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 20324d2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 3 months ago
Other metadata
compatibility
Targets WordPress 7.0+ (PHP 7.4.0+). Filesystem-based agent with bash + node. Some workflows require WP-CLI.
  • Security
  • wordpress
  • php
  • plugin-development
  • settings-api
  • hooks
  • wp-cli
  • activation
  • admin-ui

README badge

README badge for wordpress/agent-skills/wp-plugin-development

Guides plugin development for WordPress 6.9+ with architecture patterns, hook registration, activation/deactivation workflows, Settings API for admin UI, and security practices (nonces, capabilities, sanitization, SQL safety). Use this when building or refactoring WordPress plugins, setting up options storage, or packaging releases with WP-CLI and bash workflows.

Generated from the current SKILL.md.

What WordPress and PHP versions does this skill target?
WordPress 6.9+ with PHP 7.2.24+. You should confirm your target versions before following the guidance, as some APIs and prepared statement placeholders vary by version.
Does this skill cover multisite WordPress?
The skill acknowledges multisite and single-site configurations as inputs you must specify, but does not provide detailed multisite-specific guidance. Consult the Plugin Handbook for multisite-specific hooks and options.
What security practices does this skill enforce?
Input validation/sanitization, nonces for CSRF prevention, capability checks for authorization, late escaping on output, and prepared statements for SQL queries. The skill provides a baseline but refers to the security reference for canonical detail.
Can I use this skill for custom post types and rewrite rules?
Yes. The skill covers activation hooks and flushing rewrite rules, but warns that these are fragile; rewrite rules should only flush after registering CPTs and only when necessary.
Does this skill require WP-CLI?
Some workflows require WP-CLI (particularly for cron tasks and manual admin operations), but it is not universally required. Check the referenced guidance for your specific task.

Generated from the current SKILL.md. These answers refresh after source changes.