All skills
wordpress avatar

/wp-plugin-directory-guidelines

@20324d2 official
by wordpresswordpress/agent-skills2.2k stars
327

Use when reviewing WordPress plugins for GPL compliance, checking license headers or compatibility, evaluating upsell/freemium/trialware patterns, validating plugin naming or trademark rules, checking plugin slugs, understanding why a plugin was rejected from WordPress.org, or answering any question about the 18 WordPress.org Plugin Directory guidelines — even if the user doesn't mention 'guidelines' explicitly.

Use this Skill: https://skilld.dev/gh/wordpress/agent-skills/wp-plugin-directory-guidelines

This session only. Nothing lands on disk.

referencesgpl-compliance.md

≈2.6k tokens on demand. Your agent reads this file only when SKILL.md points to it.

GPL Compliance (Guideline 1 in Detail)

Verification (Licensing)

  • Every licensing-related issue must cite Guideline 1 and include the specific file/license value found.
  • License compatibility claims must match the GPL-Compatible Licenses table or the GNU GPL-Compatible License List.
  • Use local references/ files when present; otherwise use authoritative external URLs.

Failure modes (Licensing)

  • If a license is not listed in the compatibility tables, do not guess; check the GNU license list or escalate.
  • If a plugin uses a dual-license model, verify both licenses independently.

Quick Reference: WordPress GPL Requirements

WordPress is licensed under GPLv2 or later. All plugins distributed via WordPress.org must be:

  1. 100% GPL-compatible (code, images, CSS, and all assets)
  2. Include a license declaration in the main plugin file header
  3. Include the full license text or a URI reference to it
  4. Not restrict freedoms granted by the GPL

GPL Versions Summary

Version Year Key Addition
GPLv1 1989 Base copyleft: share-alike for modifications
GPLv2 1991 Patent clause (Section 7), clearer distribution terms
GPLv3 2007 Anti-tivoization, explicit patent grants, compatibility provisions

WordPress uses GPLv2 or later, meaning plugins can use GPLv2, GPLv3, or "GPLv2 or later".

For full license texts, see:

License Compliance Checklist

When reviewing a plugin, verify:

  • Main plugin file has a valid License: header (e.g., GPL-2.0-or-later, GPL-2.0+, GPLv2 or later)
  • Main plugin file has a License URI: header pointing to the GPL text
  • If bundled libraries exist, each has a GPL-compatible license
  • No "split licensing" (e.g., code GPL but premium features proprietary)
  • No additional restrictions beyond what GPL allows
  • No clauses restricting commercial use, modification, or redistribution
  • No obfuscated code (violates the spirit of source code availability)

Valid License Headers for WordPress Plugins

License: GPL-2.0-or-later
License URI: https://www.gnu.org/licenses/gpl-2.0.html
License: GPL-3.0-or-later
License URI: https://www.gnu.org/licenses/gpl-3.0.html
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Accepted Licenses by the WordPress.org Plugin Directory

Source: Plugin Check - License_Utils trait

The Plugin Directory accepts licenses matching these identifiers (after normalization). The validation uses is_license_gpl_compatible() with the pattern:

GPL|GNU|LGPL|MIT|FreeBSD|New BSD|BSD-3-Clause|BSD 3 Clause|OpenLDAP|Expat|Apache2|MPL20|ISC|CC0|Unlicense|WTFPL|Artistic|Boost|NCSA|ZLib|X11

GPL Family (recommended)

Accepted Values SPDX Identifier License URI
GPL-2.0-or-later, GPLv2 or later, GPL-2.0+ GPL-2.0-or-later https://www.gnu.org/licenses/gpl-2.0.html
GPL-2.0-only, GPLv2 GPL-2.0-only https://www.gnu.org/licenses/gpl-2.0.html
GPL-3.0-or-later, GPLv3 or later, GPL-3.0+ GPL-3.0-or-later https://www.gnu.org/licenses/gpl-3.0.html
GPL-3.0-only, GPLv3 GPL-3.0-only https://www.gnu.org/licenses/gpl-3.0.html
GNU General Public License (any version text) — —
LGPL-2.1, LGPLv2.1 LGPL-2.1-or-later https://www.gnu.org/licenses/lgpl-2.1.html
LGPL-3.0, LGPLv3 LGPL-3.0-or-later https://www.gnu.org/licenses/lgpl-3.0.html

Other GPL-Compatible Licenses Accepted

Identifier License Name Notes
MIT MIT License Permissive, compatible with GPLv2 and GPLv3
Expat Expat License Functionally equivalent to MIT
X11 X11 License Permissive; similar to Expat but with extra X Consortium clause
FreeBSD BSD 2-Clause (FreeBSD) Permissive, compatible with GPLv2 and GPLv3
New BSD, BSD-3-Clause, BSD 3 Clause BSD 3-Clause Permissive, compatible with GPLv2 and GPLv3
Apache2, Apache-2.0 Apache License 2.0 Compatible with GPLv3 only (NOT GPLv2)
MPL20, MPL-2.0 Mozilla Public License 2.0 Compatible via Section 3.3
ISC ISC License Permissive, compatible with GPLv2 and GPLv3
OpenLDAP OpenLDAP Public License v2.7 Permissive; older v2.3 is NOT compatible
CC0 Creative Commons Zero Public domain dedication
Unlicense The Unlicense Public domain dedication
WTFPL Do What The F*** You Want To Public License Permissive, accepted in full text form too
Artistic Artistic License 2.0 Compatible via relicensing option in §4(c)(ii); Artistic 1.0 is NOT compatible
Boost Boost Software License 1.0 Lax permissive, compatible with GPLv2 and GPLv3
NCSA NCSA/University of Illinois Open Source License Based on Expat + modified BSD; compatible with GPLv2 and GPLv3
ZLib zlib License Permissive, compatible with GPLv2 and GPLv3

Licenses NOT Accepted

Any license not matching the identifiers above will be rejected. Common rejections include:

  • Proprietary / All Rights Reserved
  • Creative Commons BY-NC (NonCommercial restriction)
  • Creative Commons BY-ND (NoDerivatives restriction)
  • Creative Commons BY-SA (v3.0 and earlier; v4.0 is one-way compatible with GPLv3 but not in the Plugin Check regex)
  • JSON License ("shall be used for Good, not Evil")
  • SSPL (Server Side Public License)
  • BSL (Business Source License)
  • Commons Clause
  • Elastic License
  • Original BSD (4-clause) — advertising clause incompatible with GPL
  • MPL-1.0 — only MPL 2.0 is GPL-compatible
  • EPL (Eclipse Public License) — weak copyleft, incompatible with GPL
  • EUPL (European Union Public License) — copyleft incompatible with GPL without multi-step relicensing
  • Artistic License 1.0 — vague wording makes it incompatible; use 2.0 instead
  • OpenLDAP v2.3 (old) — incompatible; v2.7 is accepted

Common GPL Violations in Plugin Review

1. Split Licensing

Plugin claims GPL but restricts premium features:

  • "Free version is GPL, premium is proprietary" - VIOLATION
  • All code distributed must be GPL-compatible

2. Obfuscated Code

  • Minified JavaScript is acceptable IF source is provided
  • PHP obfuscation (ionCube, Zend Guard, etc.) - VIOLATION (prevents exercise of GPL freedoms)
  • Encoded/encrypted PHP - VIOLATION

3. Missing License Information

  • No license header in main file
  • No license file in the package
  • Bundled libraries without license documentation

4. Restrictive Clauses

  • "You may not sell this plugin" - VIOLATION (GPL allows commercial redistribution)
  • "You may not remove author credits" - Acceptable under GPLv3 Section 7(b), but not as blanket restriction
  • "For personal use only" - VIOLATION
  • "You must link back to our site" - VIOLATION (additional restriction)

5. Incompatible Library Inclusion

  • Including code under GPL-incompatible licenses
  • Using assets (images, fonts, CSS) under restrictive licenses

Key GPL Concepts for Reviewers

Distribution vs. Private Use

  • GPL obligations activate upon distribution (conveying to others)
  • Private modifications do NOT trigger GPL requirements
  • Publishing on WordPress.org IS distribution

Derivative Works

  • A WordPress plugin that uses WordPress APIs is generally considered a derivative work
  • Plugins that merely aggregate with WordPress may have different considerations
  • When in doubt, the safe approach is GPL-compatible licensing

Source Code Requirement

  • GPL requires access to "complete corresponding source code"
  • For WordPress plugins: all PHP, JS source files, build scripts
  • Minified files must have corresponding source available

The "Or Later" Clause

  • "GPLv2 or later" allows users to choose GPLv2 OR any later version
  • "GPLv2 only" means strictly GPLv2 (less flexible but valid)
  • WordPress itself uses "GPLv2 or later"

Violation Reporting Workflow

When a GPL violation is identified:

  1. Document the violation precisely:

    • Product name and version
    • Distributor information
    • Specific license terms violated
    • Evidence (screenshots, code snippets)
  2. Contact the copyright holder first

  3. Report to FSF if the code is FSF-copyrighted: license-violation@gnu.org

  4. For WordPress.org plugins: flag through the plugin review process

Frequently Asked Questions

For comprehensive GPL FAQ answers, see the GNU GPL FAQ.

Common questions during plugin review:

Can a plugin charge money and still be GPL? Yes. GPL allows charging for distribution. The requirement is that recipients get GPL freedoms (use, modify, redistribute).

Does a plugin need to include the full GPL text? GPLv2 Section 1 and GPLv3 Section 4 require giving recipients a copy of the license. A URI reference in the header plus including a LICENSE file is standard practice.

Can a plugin restrict who uses it? No. GPL explicitly prohibits additional restrictions on recipients. "For personal use only" or "non-commercial" clauses are incompatible.

Is minified JS without source a violation? If the plugin only distributes minified JS without any way to obtain the source, this conflicts with GPL's source code requirements. The source should be available (in the package or via a repository).

Can a plugin use CC-BY-SA images? CC-BY-SA 4.0 is one-way compatible with GPLv3 (CC-BY-SA material can be included in GPLv3 works). CC-BY-SA 3.0 is NOT compatible.

What about fonts bundled in plugins? Fonts must be under GPL-compatible licenses. Common acceptable font licenses: OFL (SIL Open Font License), Apache 2.0 (with GPLv3), MIT, GPL with font exception.

Source: SKILL.md on GitHub

No alerts16d3 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill is a security auditing tool for WordPress plugins, providing checklists for GPL compliance, naming rules, and directory guidelines. It is designed to help identify potential violations such as obfuscated code or unauthorized data collection. No malicious behavior was detected within the skill's instructions or references.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

Signed by skilld at 20324d2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 3 months ago
compatibility
Targets WordPress 7.0+ (PHP 7.4.0+).
  • wordpress
  • gpl
  • licensing
  • plugin-compliance
  • trademark
  • wordpress-org
  • php
  • plugin-directory

README badge

README badge for wordpress/agent-skills/wp-plugin-directory-guidelines

Authoritative reference for the 18 WordPress.org Plugin Directory guidelines covering GPL licensing, plugin naming, trademark rules, trialware restrictions, and submission requirements. Use this skill to audit plugins for compliance before WordPress.org submission, verify GPL header validity and license compatibility, or answer questions about what is allowed in the plugin directory.

Generated from the current SKILL.md.

Does this skill cover all 18 WordPress.org Plugin Directory guidelines?
Yes. The skill is an authoritative reference for all 18 guidelines, with detailed checklists and specific procedures for GPL compliance, naming rules, trialware restrictions, and submission requirements.
What license headers does WordPress.org accept?
WordPress.org accepts GPL-2.0-or-later, GPL-3.0-or-later, or GPLv2/GPLv3 or later formats, with a corresponding License URI header pointing to the GPL text.
Does this help identify why a plugin was rejected from WordPress.org?
Yes. The skill guides you through the 18-guideline checklist to identify common violations (GPL incompatibility, trialware patterns, trademark issues, obfuscation) that typically cause rejections.
Can I use MIT or BSD licensed libraries in my WordPress plugin?
Yes, MIT, BSD, ISC, zlib, and Boost are commonly accepted as GPL-compatible. For conditional licenses like Apache-2.0 or MPL-2.0, the skill provides detailed compatibility guidance.
What counts as trialware and violates the guidelines?
The skill includes a trialware checklist covering premium upsells, freemium flows, license checks, and teaser UI. It flags patterns that restrict core functionality based on payment or licensing.

Generated from the current SKILL.md. These answers refresh after source changes.