Capability
Other metadata
- compatibility
- Targets WordPress 7.0+ (PHP 7.4.0+). Filesystem-based agent with bash + node. Some workflows require WP-CLI.
Topics
- Security
- wordpress
- php
- plugin-development
- settings-api
- hooks
- wp-cli
- activation
- admin-ui
What it does
Guides plugin development for WordPress 6.9+ with architecture patterns, hook registration, activation/deactivation workflows, Settings API for admin UI, and security practices (nonces, capabilities, sanitization, SQL safety). Use this when building or refactoring WordPress plugins, setting up options storage, or packaging releases with WP-CLI and bash workflows.
Generated from the current SKILL.md.
Frequently asked
What WordPress and PHP versions does this skill target?
WordPress 6.9+ with PHP 7.2.24+. You should confirm your target versions before following the guidance, as some APIs and prepared statement placeholders vary by version.
Does this skill cover multisite WordPress?
The skill acknowledges multisite and single-site configurations as inputs you must specify, but does not provide detailed multisite-specific guidance. Consult the Plugin Handbook for multisite-specific hooks and options.
What security practices does this skill enforce?
Input validation/sanitization, nonces for CSRF prevention, capability checks for authorization, late escaping on output, and prepared statements for SQL queries. The skill provides a baseline but refers to the security reference for canonical detail.
Can I use this skill for custom post types and rewrite rules?
Yes. The skill covers activation hooks and flushing rewrite rules, but warns that these are fragile; rewrite rules should only flush after registering CPTs and only when necessary.
Does this skill require WP-CLI?
Some workflows require WP-CLI (particularly for cron tasks and manual admin operations), but it is not universally required. Check the referenced guidance for your specific task.
Generated from the current SKILL.md. These answers refresh after source changes.