All skills
wordpress avatar

/wp-plugin-development

@20324d2 official
by wordpresswordpress/agent-skills2.2k stars
327

Use when developing WordPress plugins: architecture and hooks, activation/deactivation/uninstall, admin UI and Settings API, data storage, cron/tasks, security (nonces/capabilities/sanitization/escaping), and release packaging.

Use this Skill: https://skilld.dev/gh/wordpress/agent-skills/wp-plugin-development

This session only. Nothing lands on disk.

referencessecurity.md

≈385 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Security guardrails (plugin work)

Use this file when making security fixes or when handling any input/output.

Nonces + permissions

  • Nonces help prevent CSRF, not authorization.
  • Always pair nonces with capability checks (current_user_can() or a more specific capability).

Upstream reference:

Sanitization and escaping

Golden rule:

  • sanitize/validate on input, escape on output.

Practical rules:

  • never process the entire $_POST / $_GET array; read explicit keys
  • use wp_unslash() before sanitizing when needed
  • use prepared statements for SQL; avoid interpolating user input into queries

Output escaping contexts

Escape at output, using the function that matches the context:

  • HTML text: esc_html()
  • HTML attribute: esc_attr()
  • URL: esc_url()
  • textarea: esc_textarea()
  • JavaScript strings: esc_js()

For JSON data, prefer wp_json_encode() and pass data through WordPress script APIs such as wp_add_inline_script() or wp_localize_script().

For user-provided HTML, restrict allowed markup with wp_kses_post() or wp_kses() before output.

AJAX handlers

  • For wp_ajax_*, verify nonce and check capabilities.
  • For wp_ajax_nopriv_*, assume unauthenticated attacker-controlled traffic.
  • Return JSON with wp_send_json_success() or wp_send_json_error().
  • Do not expose private data from AJAX responses.

Common review guidance:

Source: SKILL.md on GitHub

1 warning9d5 checks · Risk SAFE
  • Gen Agent Trust Hub9d

    This skill provides a structured workflow and discovery tools for WordPress plugin development, emphasizing security best practices. No malicious behaviors or security risks were identified.

  • Socket9d

    No alerts

  • Snyk9d

    Risk: LOW · No issues

  • Runlayer7mo

    6/8 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 20324d2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 3 months ago
Other metadata
compatibility
Targets WordPress 7.0+ (PHP 7.4.0+). Filesystem-based agent with bash + node. Some workflows require WP-CLI.
  • Security
  • wordpress
  • php
  • plugin-development
  • settings-api
  • hooks
  • wp-cli
  • activation
  • admin-ui

README badge

README badge for wordpress/agent-skills/wp-plugin-development

Guides plugin development for WordPress 6.9+ with architecture patterns, hook registration, activation/deactivation workflows, Settings API for admin UI, and security practices (nonces, capabilities, sanitization, SQL safety). Use this when building or refactoring WordPress plugins, setting up options storage, or packaging releases with WP-CLI and bash workflows.

Generated from the current SKILL.md.

What WordPress and PHP versions does this skill target?
WordPress 6.9+ with PHP 7.2.24+. You should confirm your target versions before following the guidance, as some APIs and prepared statement placeholders vary by version.
Does this skill cover multisite WordPress?
The skill acknowledges multisite and single-site configurations as inputs you must specify, but does not provide detailed multisite-specific guidance. Consult the Plugin Handbook for multisite-specific hooks and options.
What security practices does this skill enforce?
Input validation/sanitization, nonces for CSRF prevention, capability checks for authorization, late escaping on output, and prepared statements for SQL queries. The skill provides a baseline but refers to the security reference for canonical detail.
Can I use this skill for custom post types and rewrite rules?
Yes. The skill covers activation hooks and flushing rewrite rules, but warns that these are fragile; rewrite rules should only flush after registering CPTs and only when necessary.
Does this skill require WP-CLI?
Some workflows require WP-CLI (particularly for cron tasks and manual admin operations), but it is not universally required. Check the referenced guidance for your specific task.

Generated from the current SKILL.md. These answers refresh after source changes.