All skills
wordpress avatar

/wp-plugin-development

@20324d2 official
by wordpresswordpress/agent-skills2.2k stars
327

Use when developing WordPress plugins: architecture and hooks, activation/deactivation/uninstall, admin UI and Settings API, data storage, cron/tasks, security (nonces/capabilities/sanitization/escaping), and release packaging.

Use this Skill: https://skilld.dev/gh/wordpress/agent-skills/wp-plugin-development

This session only. Nothing lands on disk.

referencesdata-and-cron.md

≈170 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Data storage, cron, and upgrades

Use this file when adding persistent storage, background jobs, or upgrade routines.

Data storage

  • Prefer Options API for small config/state.
  • Use custom tables only when needed; store schema version and provide upgrade paths.

Cron

  • Ensure tasks are idempotent (may run late or multiple times).
  • Provide a manual trigger path for debugging (WP-CLI or admin-only action).

Database safety note

If using $wpdb->prepare(), avoid building queries with concatenated user input. Recent WordPress versions support identifier placeholders (%i) but you must not assume it exists without checking capabilities or target versions.

Source: SKILL.md on GitHub

1 warning9d5 checks · Risk SAFE
  • Gen Agent Trust Hub9d

    This skill provides a structured workflow and discovery tools for WordPress plugin development, emphasizing security best practices. No malicious behaviors or security risks were identified.

  • Socket9d

    No alerts

  • Snyk9d

    Risk: LOW · No issues

  • Runlayer7mo

    6/8 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 20324d2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 3 months ago
Other metadata
compatibility
Targets WordPress 7.0+ (PHP 7.4.0+). Filesystem-based agent with bash + node. Some workflows require WP-CLI.
  • Security
  • wordpress
  • php
  • plugin-development
  • settings-api
  • hooks
  • wp-cli
  • activation
  • admin-ui

README badge

README badge for wordpress/agent-skills/wp-plugin-development

Guides plugin development for WordPress 6.9+ with architecture patterns, hook registration, activation/deactivation workflows, Settings API for admin UI, and security practices (nonces, capabilities, sanitization, SQL safety). Use this when building or refactoring WordPress plugins, setting up options storage, or packaging releases with WP-CLI and bash workflows.

Generated from the current SKILL.md.

What WordPress and PHP versions does this skill target?
WordPress 6.9+ with PHP 7.2.24+. You should confirm your target versions before following the guidance, as some APIs and prepared statement placeholders vary by version.
Does this skill cover multisite WordPress?
The skill acknowledges multisite and single-site configurations as inputs you must specify, but does not provide detailed multisite-specific guidance. Consult the Plugin Handbook for multisite-specific hooks and options.
What security practices does this skill enforce?
Input validation/sanitization, nonces for CSRF prevention, capability checks for authorization, late escaping on output, and prepared statements for SQL queries. The skill provides a baseline but refers to the security reference for canonical detail.
Can I use this skill for custom post types and rewrite rules?
Yes. The skill covers activation hooks and flushing rewrite rules, but warns that these are fragile; rewrite rules should only flush after registering CPTs and only when necessary.
Does this skill require WP-CLI?
Some workflows require WP-CLI (particularly for cron tasks and manual admin operations), but it is not universally required. Check the referenced guidance for your specific task.

Generated from the current SKILL.md. These answers refresh after source changes.