All skills
wordpress avatar

/wp-plugin-development

@20324d2 official
by wordpresswordpress/agent-skills2.2k stars
327

Use when developing WordPress plugins: architecture and hooks, activation/deactivation/uninstall, admin UI and Settings API, data storage, cron/tasks, security (nonces/capabilities/sanitization/escaping), and release packaging.

Use this Skill: https://skilld.dev/gh/wordpress/agent-skills/wp-plugin-development

This session only. Nothing lands on disk.

referencesdebugging.md

≈140 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Debugging quick routes

Plugin doesn’t load / fatal errors

  • Confirm correct plugin main file and header.
  • Check PHP error logs and WP_DEBUG_LOG.
  • If the repo is a site repo, confirm you edited the correct plugin under wp-content/plugins/.

Activation hook surprises

  • Hooks must be registered at top-level.
  • Activation runs in a special context; avoid assuming other hooks already ran.

Settings not saving

  • Confirm register_setting() is called.
  • Confirm the option group matches the form.
  • Confirm capability checks and nonces.

Source: SKILL.md on GitHub

1 warning9d5 checks · Risk SAFE
  • Gen Agent Trust Hub9d

    This skill provides a structured workflow and discovery tools for WordPress plugin development, emphasizing security best practices. No malicious behaviors or security risks were identified.

  • Socket9d

    No alerts

  • Snyk9d

    Risk: LOW · No issues

  • Runlayer7mo

    6/8 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 20324d2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 3 months ago
Other metadata
compatibility
Targets WordPress 7.0+ (PHP 7.4.0+). Filesystem-based agent with bash + node. Some workflows require WP-CLI.
  • Security
  • wordpress
  • php
  • plugin-development
  • settings-api
  • hooks
  • wp-cli
  • activation
  • admin-ui

README badge

README badge for wordpress/agent-skills/wp-plugin-development

Guides plugin development for WordPress 6.9+ with architecture patterns, hook registration, activation/deactivation workflows, Settings API for admin UI, and security practices (nonces, capabilities, sanitization, SQL safety). Use this when building or refactoring WordPress plugins, setting up options storage, or packaging releases with WP-CLI and bash workflows.

Generated from the current SKILL.md.

What WordPress and PHP versions does this skill target?
WordPress 6.9+ with PHP 7.2.24+. You should confirm your target versions before following the guidance, as some APIs and prepared statement placeholders vary by version.
Does this skill cover multisite WordPress?
The skill acknowledges multisite and single-site configurations as inputs you must specify, but does not provide detailed multisite-specific guidance. Consult the Plugin Handbook for multisite-specific hooks and options.
What security practices does this skill enforce?
Input validation/sanitization, nonces for CSRF prevention, capability checks for authorization, late escaping on output, and prepared statements for SQL queries. The skill provides a baseline but refers to the security reference for canonical detail.
Can I use this skill for custom post types and rewrite rules?
Yes. The skill covers activation hooks and flushing rewrite rules, but warns that these are fragile; rewrite rules should only flush after registering CPTs and only when necessary.
Does this skill require WP-CLI?
Some workflows require WP-CLI (particularly for cron tasks and manual admin operations), but it is not universally required. Check the referenced guidance for your specific task.

Generated from the current SKILL.md. These answers refresh after source changes.