wp-plugin-development

tarafından wordpress

WordPress eklentisi geliştirme iş akışının tamamı, mimariden güvenlik ve sürüm paketlemesine kadar. Eklenti yapısı, hooks/actions/filters, etkinleştirme/devre dışı bırakma/kaldırma yaşam döngüsü ve yönetici arayüzü ile seçenek yönetimi için Settings API’yi kapsar. Zorunlu güvenlik temelini içerir: girdi doğrulama/sanitizasyon, nonce’lar, yetenek kontrolleri ve $wpdb->prepare() ile parametreli SQL sorguları. Veri depolama desenlerini, idempotentlik ile cron görevi kurulumunu ve şema geçişlerini destekler...

npx skills add https://github.com/wordpress/agent-skills --skill wp-plugin-development

WP Plugin Development

When to use

Use this skill for plugin work such as:

  • creating or refactoring plugin structure (bootstrap, includes, namespaces/classes)
  • adding hooks/actions/filters
  • activation/deactivation/uninstall behavior and migrations
  • adding settings pages / options / admin UI (Settings API)
  • security fixes (nonces, capabilities, sanitization/escaping, SQL safety)
  • packaging a release (build artifacts, readme, assets)

Inputs required

  • Repo root + target plugin(s) (path to plugin main file if known).
  • Where this plugin runs: single site vs multisite; WP.com conventions if applicable.
  • Target WordPress + PHP versions (affects available APIs and placeholder support in $wpdb->prepare()).

Procedure

0) Triage and locate plugin entrypoints

  1. Run triage:
    • node skills/wp-project-triage/scripts/detect_wp_project.mjs
  2. Detect plugin headers (deterministic scan):
    • node skills/wp-plugin-development/scripts/detect_plugins.mjs

If this is a full site repo, pick the specific plugin under wp-content/plugins/ or mu-plugins/ before changing code.

1) Follow a predictable architecture

Guidelines:

  • Keep a single bootstrap (main plugin file with header).
  • Avoid heavy side effects at file load time; load on hooks.
  • Prefer a dedicated loader/class to register hooks.
  • Keep admin-only code behind is_admin() (or admin hooks) to reduce frontend overhead.

See:

  • references/structure.md

2) Hooks and lifecycle (activation/deactivation/uninstall)

Activation hooks are fragile; follow guardrails:

  • register activation/deactivation hooks at top-level, not inside other hooks
  • flush rewrite rules only when needed and only after registering CPTs/rules
  • uninstall should be explicit and safe (uninstall.php or register_uninstall_hook)

See:

  • references/lifecycle.md

3) Settings and admin UI (Settings API)

Prefer Settings API for options:

  • register_setting(), add_settings_section(), add_settings_field()
  • sanitize via sanitize_callback

See:

  • references/settings-api.md

4) Security baseline (always)

Before shipping:

  • Validate/sanitize input early; escape output late.
  • Use nonces to prevent CSRF and capability checks for authorization.
  • Avoid directly trusting $_POST / $_GET; use wp_unslash() and specific keys.
  • Use $wpdb->prepare() for SQL; avoid building SQL with string concatenation.

See:

  • references/security.md

5) Data storage, cron, migrations (if needed)

  • Prefer options for small config; custom tables only if necessary.
  • For cron tasks, ensure idempotency and provide manual run paths (WP-CLI or admin).
  • For schema changes, write upgrade routines and store schema version.

See:

  • references/data-and-cron.md

Verification

  • Plugin activates with no fatals/notices.
  • Settings save and read correctly (capability + nonce enforced).
  • Uninstall removes intended data (and nothing else).
  • Run repo lint/tests (PHPUnit/PHPCS if present) and any JS build steps if the plugin ships assets.

Failure modes / debugging

  • Activation hook not firing:
    • hook registered incorrectly (not in main file scope), wrong main file path, or plugin is network-activated
  • Settings not saving:
    • settings not registered, wrong option group, missing capability, nonce failure
  • Security regressions:
    • nonce present but missing capability checks; or sanitized input not escaped on output

See:

  • references/debugging.md

Escalation

For canonical detail, consult the Plugin Handbook and security guidelines before inventing patterns.

wordpress tarafından daha fazla skill

blueprint
wordpress
WordPress Playground blueprint JSON dosyalarını oluştururken, düzenlerken veya incelerken kullanılır. Blueprint'lerden, playground yapılandırmasından veya taleplerden bahsedildiğinde tetiklenir…
official
wordpress-router
wordpress
WordPress kod tabanlarını sınıflandırır ve eklentiler, temalar, bloklar ile çekirdek kontrolleri için doğru iş akışına yönlendirir. Depo türünü (eklenti, tema, blok teması, Gutenberg blokları, WP çekirdeği) ve mevcut araçları belirlemek için otomatik proje triyajı çalıştırır. Kullanıcı niyeti ve proje türüne göre sınıflandırma sonuçları ile karar ağacı yönlendirmesini alana özel becerilere çıktı olarak verir. Depo kök erişimi ve bash/Node dosya sistemi işlemleri gerektirir; bazı iş akışları WP-CLI'ye ihtiyaç duyar. WordPress 6.9+ ve PHP
official
wp-abilities-api
wordpress
WordPress Abilities API kaydı, REST sunumu ve WordPress 6.9+ için istemci tarafı tüketimi. wp_register_ability() ve wp_register_ability_category() kullanarak PHP'de kararlı kimlikler, etiketler ve meta verilerle yetenekler ve kategoriler kaydedin. meta.show_in_rest: true ayarını yaparak yetenekleri /wp-json/wp-abilities/v1/ REST uç noktaları aracılığıyla istemcilere sunun. @wordpress/abilities paketini kullanarak JavaScript'te istemci tarafı erişim ve izin kontrolleri için yetenekleri tüketin. WordPress 6.9+ gerektirir...
official
wp-abilities-audit
wordpress
WordPress eklentisinin REST yüzeyini denetleyin ve Abilities API kayıtları öneren standart bir denetim belgesi oluşturun. YAML içeren bir markdown belgesi üretir…
official
wp-abilities-verify
wordpress
WordPress eklentisinin Abilities API kayıtlarını doğrulayın: yetenekleri numaralandırın, geri çağırma davranışının her açıklamanın iddiasıyla eşleşip eşleşmediğini kontrol edin (saldırgan…
official
wp-block-development
wordpress
WordPress blok geliştirme (Gutenberg için): meta veri, kayıt, oluşturma ve derleme iş akışları. Blok oluşturma, block.json yapılandırması, statik ve dinamik oluşturma ile register_block_type_from_metadata() kullanarak sunucu tarafı PHP kaydını kapsar. WordPress 6.9+ uyumluluğu için apiVersion: 3'ü zorunlu kılar; iframe düzenleyici desteği ve stil izolasyonunu içerir. "Geçersiz blok" hatalarını önlemek için nitelik serileştirme, eski sürümler/geçişler ve iç blok kompozisyonunu yönetir. Şunları içerir...
official
wp-block-themes
wordpress
WordPress blok tema geliştirme: theme.json, şablonlar, desenler ve Site Düzenleyici sorun giderme. theme.json düzenleme (ön ayarlar, ayarlar, blok başına stiller), şablonlar ve şablon parçaları, desenler ve WordPress 6.9+ üzerinde stil varyasyonlarını kapsar. Tema köklerini ve blok tema yapısını tespit etmek için triyaj betikleri ile yeni temalar oluşturma veya klasik temaları dönüştürme için rehberli prosedürler içerir. Stil hiyerarşisi sorunları, kullanıcı özelleştirme geçersiz kılmaları ve Site... için hata ayıklama iş akışları sağlar.
official
wp-interactivity-api
wordpress
WordPress Interactivity API özellikleri (data-wp-* yönergeleri, @wordpress/interactivity store/state/actions, block viewScriptModule…) oluştururken veya hata ayıklarken kullanın.
official