wp-plugin-directory-guidelines

Use when reviewing WordPress plugins for GPL compliance, checking license headers or compatibility, evaluating upsell/freemium/trialware patterns, validating…

npx skills add https://github.com/wordpress/agent-skills --skill wp-plugin-directory-guidelines

Overview

Authoritative reference for the 18 WordPress.org Plugin Directory guidelines. Covers GPL licensing, plugin naming/trademark rules, trialware restrictions, and all other submission requirements.

When to use

Use this skill when you need to:

  • Review a WordPress plugin for compliance with the WordPress.org Plugin Directory guidelines
  • Check GPL license compatibility for a plugin or its bundled libraries
  • Verify license headers in plugin files
  • Identify common guideline violations before submission
  • Answer questions about what is or is not allowed on WordPress.org
  • Evaluate premium/upsell flows, license checks, or freemium positioning
  • Review "teaser" or "preview" UI for trialware violations

Inputs required

  • Plugin source code (or specific files to review)
  • Optional: plugin readme and plugin header metadata for naming and license checks

Procedure

  1. Check the plugin's license header against the Valid License Headers section below.
  2. Walk through the 18 Guidelines checklist, paying special attention to Guidelines 1, 4, 5, 7, 8, and 17.
  3. Confirm trialware/freemium compliance using the checklist in guideline-review-checklist.md (Guideline 5 section).
  4. For bundled third-party code, verify license compatibility against GPL-Compatible Licenses (Quick) below.
  5. Flag matches from Common GPL Violations (Quick) below.
  6. For edge cases, consult the detailed references and the GNU GPL FAQ.

18-Guideline Review Checklist

Use the detailed, per-guideline checklist in guideline-review-checklist.md. Load this reference file only when a full guideline audit is requested.

GPL Compliance (Guideline 1 in Detail)

Use gpl-compliance.md for full license tables, compatibility nuances, and examples. Keep this inline section as a quick decision aid.

Verification (Licensing)

  • Every licensing-related issue must cite Guideline 1 and include the file path and exact license string.
  • Confirm compatibility claims against GPL-Compatible Licenses (Quick) and escalate ambiguous licenses.

Failure modes (Licensing)

  • If a license is not clearly GPL-compatible, do not guess. Check the GNU license list.
  • For dual-license packages, verify both licenses and redistribution terms.

Quick Reference: WordPress GPL Requirements

  • WordPress is GPLv2 or later.
  • Plugins distributed on WordPress.org must be 100% GPL-compatible (code and assets).
  • Include a valid License: header and License URI: in the main plugin file.
  • Do not add restrictions that conflict with GPL freedoms.

Valid License Headers

GPL Versions Summary

VersionYearKey Addition
GPLv11989Base copyleft: share-alike for modifications
GPLv21991"Liberty or death" clause (Section 7), clearer distribution terms
GPLv32007Anti-tivoization, explicit patent grants, compatibility provisions

WordPress uses GPLv2 or later, meaning plugins can use GPLv2, GPLv3, or "GPLv2 or later".

For full license texts, see:

License Compliance Checklist

When reviewing a plugin, verify:

  • Main plugin file has a valid License: header (e.g., GPL-2.0-or-later, GPL-2.0+, GPLv2 or later)
  • Main plugin file has a License URI: header pointing to the GPL text
  • If bundled libraries exist, each has a GPL-compatible license
  • No "split licensing" (e.g., code GPL but premium features proprietary)
  • No additional restrictions beyond what GPL allows
  • No clauses restricting commercial use, modification, or redistribution
  • No obfuscated code (violates the spirit of source code availability)

Valid License Headers for WordPress Plugins

License: GPL-2.0-or-later
License URI: https://www.gnu.org/licenses/gpl-2.0.html
License: GPL-3.0-or-later
License URI: https://www.gnu.org/licenses/gpl-3.0.html
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

GPL-Compatible Licenses (Quick)

  • Safe defaults: GPL-2.0-or-later, GPL-3.0-or-later.
  • Commonly accepted permissive families: MIT/Expat, BSD, ISC, zlib, Boost.
  • Conditional compatibility requires care: Apache-2.0 and MPL-2.0 (verify usage context).
  • For full accepted and rejected identifiers, use gpl-compliance.md.

Common GPL Violations (Quick)

  • Split licensing that restricts distributed code.
  • Obfuscated or non-corresponding source distribution.
  • Restrictive clauses (non-commercial, no-resale, forced backlink).
  • Bundling GPL-incompatible libraries or assets.

Plugin Naming Rules (Guideline 17)

Use naming-rules.md for full trademark lists, slug blocks, and naming examples. Keep this inline checklist for quick screening.

Naming Checklist (Quick)

  • Name is not a placeholder and has at least 5 alphanumeric characters.
  • Header name and readme name match.
  • Name is specific and function-related; avoid keyword stuffing.
  • Trademark/project names appear only after connectors like for, with, using, and.
  • No banned/discouraged terms or trademark portmanteaus.
  • Slug is lowercase, hyphenated, <= 50 chars, and avoids blocked terms.

More skills from wordpress

blueprint
wordpress
Use when creating, editing, or reviewing WordPress Playground blueprint JSON files. Triggers on mentions of blueprints, playground configuration, or requests…
official
wordpress-router
wordpress
Classify WordPress codebases and route to the correct workflow for plugins, themes, blocks, and core checkouts. Runs automated project triage to identify repo type (plugin, theme, block theme, Gutenberg blocks, WP core) and available tooling Outputs classification results and decision tree routing to domain-specific skills based on user intent and project kind Requires repo root access and bash/Node filesystem operations; some workflows need WP-CLI Targets WordPress 6.9+ with PHP 7.2.24+;...
official
wp-abilities-api
wordpress
WordPress Abilities API registration, REST exposure, and client-side consumption for WordPress 6.9+. Register abilities and categories in PHP using wp_register_ability() and wp_register_ability_category() with stable IDs, labels, and metadata Expose abilities to clients via the /wp-json/wp-abilities/v1/ REST endpoints by setting meta.show_in_rest: true Consume abilities in JavaScript using the @wordpress/abilities package for client-side access and permission checks Requires WordPress 6.9+...
official
wp-abilities-audit
wordpress
Audit a WordPress plugin's REST surface and produce a standardized audit document proposing Abilities API registrations. Produces a markdown doc with a YAML…
official
wp-abilities-verify
wordpress
Verify a WordPress plugin's Abilities API registrations: enumerate abilities, check that callback behavior matches each annotation's claim (the adversarial…
official
wp-block-development
wordpress
WordPress block development for Gutenberg: metadata, registration, rendering, and build workflows. Covers block creation, block.json configuration, static vs. dynamic rendering, and server-side PHP registration with register_block_type_from_metadata() Enforces apiVersion: 3 for WordPress 6.9+ compatibility, including iframe editor support and style isolation Handles attribute serialization, deprecations/migrations to prevent "Invalid block" errors, and inner blocks composition Includes...
official
wp-block-themes
wordpress
WordPress block theme development: theme.json, templates, patterns, and Site Editor troubleshooting. Covers theme.json editing (presets, settings, per-block styles), templates and template parts, patterns, and style variations across WordPress 6.9+ Includes triage scripts to detect theme roots and block theme structure, plus guided procedures for creating new themes or converting classic themes Provides debugging workflows for style hierarchy issues, user customization overrides, and Site...
official
wp-interactivity-api
wordpress
Use when building or debugging WordPress Interactivity API features (data-wp-* directives, @wordpress/interactivity store/state/actions, block viewScriptModule…
official