wp-plugin-development

Kompletter WordPress-Plugin-Entwicklungsworkflow von der Architektur über Sicherheit bis hin zur Release-Verpackung. Behandelt Plugin-Struktur, Hooks/Actions/Filters, Aktivierungs-/Deaktivierungs-/Deinstallations-Lebenszyklus und Settings API für Admin-UI und Optionenverwaltung. Enthält obligatorische Sicherheitsbasis: Eingabevalidierung/-bereinigung, Nonces, Berechtigungsprüfungen und parametrisierte SQL-Abfragen über $wpdb->prepare(). Unterstützt Datenspeichermuster, Cron-Task-Einrichtung mit Idempotenz und Schema-Migrationen mit...

npx skills add https://github.com/wordpress/agent-skills --skill wp-plugin-development

WP Plugin Development

When to use

Use this skill for plugin work such as:

  • creating or refactoring plugin structure (bootstrap, includes, namespaces/classes)
  • adding hooks/actions/filters
  • activation/deactivation/uninstall behavior and migrations
  • adding settings pages / options / admin UI (Settings API)
  • security fixes (nonces, capabilities, sanitization/escaping, SQL safety)
  • packaging a release (build artifacts, readme, assets)

Inputs required

  • Repo root + target plugin(s) (path to plugin main file if known).
  • Where this plugin runs: single site vs multisite; WP.com conventions if applicable.
  • Target WordPress + PHP versions (affects available APIs and placeholder support in $wpdb->prepare()).

Procedure

0) Triage and locate plugin entrypoints

  1. Run triage:
    • node skills/wp-project-triage/scripts/detect_wp_project.mjs
  2. Detect plugin headers (deterministic scan):
    • node skills/wp-plugin-development/scripts/detect_plugins.mjs

If this is a full site repo, pick the specific plugin under wp-content/plugins/ or mu-plugins/ before changing code.

1) Follow a predictable architecture

Guidelines:

  • Keep a single bootstrap (main plugin file with header).
  • Avoid heavy side effects at file load time; load on hooks.
  • Prefer a dedicated loader/class to register hooks.
  • Keep admin-only code behind is_admin() (or admin hooks) to reduce frontend overhead.

See:

  • references/structure.md

2) Hooks and lifecycle (activation/deactivation/uninstall)

Activation hooks are fragile; follow guardrails:

  • register activation/deactivation hooks at top-level, not inside other hooks
  • flush rewrite rules only when needed and only after registering CPTs/rules
  • uninstall should be explicit and safe (uninstall.php or register_uninstall_hook)

See:

  • references/lifecycle.md

3) Settings and admin UI (Settings API)

Prefer Settings API for options:

  • register_setting(), add_settings_section(), add_settings_field()
  • sanitize via sanitize_callback

See:

  • references/settings-api.md

4) Security baseline (always)

Before shipping:

  • Validate/sanitize input early; escape output late.
  • Use nonces to prevent CSRF and capability checks for authorization.
  • Avoid directly trusting $_POST / $_GET; use wp_unslash() and specific keys.
  • Use $wpdb->prepare() for SQL; avoid building SQL with string concatenation.

See:

  • references/security.md

5) Data storage, cron, migrations (if needed)

  • Prefer options for small config; custom tables only if necessary.
  • For cron tasks, ensure idempotency and provide manual run paths (WP-CLI or admin).
  • For schema changes, write upgrade routines and store schema version.

See:

  • references/data-and-cron.md

Verification

  • Plugin activates with no fatals/notices.
  • Settings save and read correctly (capability + nonce enforced).
  • Uninstall removes intended data (and nothing else).
  • Run repo lint/tests (PHPUnit/PHPCS if present) and any JS build steps if the plugin ships assets.

Failure modes / debugging

  • Activation hook not firing:
    • hook registered incorrectly (not in main file scope), wrong main file path, or plugin is network-activated
  • Settings not saving:
    • settings not registered, wrong option group, missing capability, nonce failure
  • Security regressions:
    • nonce present but missing capability checks; or sanitized input not escaped on output

See:

  • references/debugging.md

Escalation

For canonical detail, consult the Plugin Handbook and security guidelines before inventing patterns.

Mehr Skills von wordpress

blueprint
wordpress
Verwenden beim Erstellen, Bearbeiten oder Überprüfen von WordPress Playground Blueprint JSON-Dateien. Wird bei Erwähnungen von Blueprints, Playground-Konfiguration oder Anfragen ausgelöst…
official
wordpress-router
wordpress
Klassifiziere WordPress-Codebasen und leite an den korrekten Workflow für Plugins, Themes, Blöcke und Core-Checkouts weiter. Führt automatisiertes Projekt-Triage durch, um den Repo-Typ (Plugin, Theme, Block-Theme, Gutenberg-Blöcke, WP-Core) und verfügbare Werkzeuge zu identifizieren. Gibt Klassifikationsergebnisse und Entscheidungsbaum-Routing an domänenspezifische Skills basierend auf Benutzerabsicht und Projektart aus. Erfordert Repo-Root-Zugriff sowie Bash/Node-Dateisystemoperationen; einige Workflows benötigen WP-CLI. Zielgruppe: WordPress 6.9+ mit PHP 7.2.24+;...
official
wp-abilities-api
wordpress
WordPress-Abilities-API-Registrierung, REST-Bereitstellung und clientseitige Nutzung für WordPress 6.9+. Registrieren Sie Abilities und Kategorien in PHP mit wp_register_ability() und wp_register_ability_category() mit stabilen IDs, Labels und Metadaten. Stellen Sie Abilities Clients über die /wp-json/wp-abilities/v1/ REST-Endpunkte zur Verfügung, indem Sie meta.show_in_rest: true setzen. Nutzen Sie Abilities in JavaScript mit dem @wordpress/abilities-Paket für clientseitigen Zugriff und Berechtigungsprüfungen. Erfordert WordPress 6.9+...
official
wp-abilities-audit
wordpress
Audit a WordPress plugin's REST surface and produce a standardized audit document proposing Abilities API registrations. Produces a markdown doc with a YAML…
official
wp-abilities-verify
wordpress
Überprüfe die Abilities-API-Registrierungen eines WordPress-Plugins: Fähigkeiten auflisten, prüfen, ob das Callback-Verhalten mit der Behauptung jeder Annotation übereinstimmt (die adversariale…
official
wp-block-development
wordpress
WordPress-Block-Entwicklung für Gutenberg: Metadaten, Registrierung, Rendering und Build-Workflows. Behandelt Block-Erstellung, block.json-Konfiguration, statisches vs. dynamisches Rendering und serverseitige PHP-Registrierung mit register_block_type_from_metadata(). Erzwingt apiVersion: 3 für WordPress 6.9+-Kompatibilität, einschließlich iframe-Editor-Unterstützung und Stilisolierung. Behandelt Attributserialisierung, Deprecations/Migrationen zur Vermeidung von "Invalid block"-Fehlern und die Zusammensetzung innerer Blöcke. Enthält...
official
wp-block-themes
wordpress
WordPress-Block-Theme-Entwicklung: theme.json, Vorlagen, Patterns und Fehlerbehebung im Site-Editor. Behandelt theme.json-Bearbeitung (Voreinstellungen, Einstellungen, blockbezogene Stile), Vorlagen und Vorlagenteile, Patterns sowie Stilvarianten ab WordPress 6.9+. Enthält Triage-Skripte zur Erkennung von Theme-Wurzeln und Block-Theme-Strukturen sowie geführte Verfahren zur Erstellung neuer Themes oder zur Umwandlung klassischer Themes. Bietet Debugging-Workflows für Probleme mit der Stilhierarchie, Überschreibungen durch Benutzeranpassungen und den Site...
official
wp-interactivity-api
wordpress
Verwenden beim Erstellen oder Debuggen von WordPress Interactivity API-Funktionen (data-wp-*-Direktiven, @wordpress/interactivity store/state/actions, block viewScriptModule…
official