wp-plugin-development

bởi wordpress

Quy trình phát triển plugin WordPress hoàn chỉnh từ kiến trúc đến bảo mật và đóng gói phát hành. Bao gồm cấu trúc plugin, hooks/actions/filters, vòng đời kích hoạt/hủy kích hoạt/gỡ cài đặt, và Settings API cho giao diện quản trị và quản lý tùy chọn. Có đường cơ sở bảo mật bắt buộc: xác thực/làm sạch đầu vào, nonces, kiểm tra quyền hạn, và truy vấn SQL tham số hóa qua $wpdb->prepare(). Hỗ trợ các mẫu lưu trữ dữ liệu, thiết lập tác vụ cron với tính đơn nhất, và di chuyển lược đồ với...

npx skills add https://github.com/wordpress/agent-skills --skill wp-plugin-development

WP Plugin Development

When to use

Use this skill for plugin work such as:

  • creating or refactoring plugin structure (bootstrap, includes, namespaces/classes)
  • adding hooks/actions/filters
  • activation/deactivation/uninstall behavior and migrations
  • adding settings pages / options / admin UI (Settings API)
  • security fixes (nonces, capabilities, sanitization/escaping, SQL safety)
  • packaging a release (build artifacts, readme, assets)

Inputs required

  • Repo root + target plugin(s) (path to plugin main file if known).
  • Where this plugin runs: single site vs multisite; WP.com conventions if applicable.
  • Target WordPress + PHP versions (affects available APIs and placeholder support in $wpdb->prepare()).

Procedure

0) Triage and locate plugin entrypoints

  1. Run triage:
    • node skills/wp-project-triage/scripts/detect_wp_project.mjs
  2. Detect plugin headers (deterministic scan):
    • node skills/wp-plugin-development/scripts/detect_plugins.mjs

If this is a full site repo, pick the specific plugin under wp-content/plugins/ or mu-plugins/ before changing code.

1) Follow a predictable architecture

Guidelines:

  • Keep a single bootstrap (main plugin file with header).
  • Avoid heavy side effects at file load time; load on hooks.
  • Prefer a dedicated loader/class to register hooks.
  • Keep admin-only code behind is_admin() (or admin hooks) to reduce frontend overhead.

See:

  • references/structure.md

2) Hooks and lifecycle (activation/deactivation/uninstall)

Activation hooks are fragile; follow guardrails:

  • register activation/deactivation hooks at top-level, not inside other hooks
  • flush rewrite rules only when needed and only after registering CPTs/rules
  • uninstall should be explicit and safe (uninstall.php or register_uninstall_hook)

See:

  • references/lifecycle.md

3) Settings and admin UI (Settings API)

Prefer Settings API for options:

  • register_setting(), add_settings_section(), add_settings_field()
  • sanitize via sanitize_callback

See:

  • references/settings-api.md

4) Security baseline (always)

Before shipping:

  • Validate/sanitize input early; escape output late.
  • Use nonces to prevent CSRF and capability checks for authorization.
  • Avoid directly trusting $_POST / $_GET; use wp_unslash() and specific keys.
  • Use $wpdb->prepare() for SQL; avoid building SQL with string concatenation.

See:

  • references/security.md

5) Data storage, cron, migrations (if needed)

  • Prefer options for small config; custom tables only if necessary.
  • For cron tasks, ensure idempotency and provide manual run paths (WP-CLI or admin).
  • For schema changes, write upgrade routines and store schema version.

See:

  • references/data-and-cron.md

Verification

  • Plugin activates with no fatals/notices.
  • Settings save and read correctly (capability + nonce enforced).
  • Uninstall removes intended data (and nothing else).
  • Run repo lint/tests (PHPUnit/PHPCS if present) and any JS build steps if the plugin ships assets.

Failure modes / debugging

  • Activation hook not firing:
    • hook registered incorrectly (not in main file scope), wrong main file path, or plugin is network-activated
  • Settings not saving:
    • settings not registered, wrong option group, missing capability, nonce failure
  • Security regressions:
    • nonce present but missing capability checks; or sanitized input not escaped on output

See:

  • references/debugging.md

Escalation

For canonical detail, consult the Plugin Handbook and security guidelines before inventing patterns.

Thêm skills từ wordpress

blueprint
wordpress
Sử dụng khi tạo, chỉnh sửa hoặc xem xét các tệp JSON blueprint của WordPress Playground. Kích hoạt khi đề cập đến blueprint, cấu hình playground hoặc các yêu cầu…
official
wordpress-router
wordpress
Phân loại mã nguồn WordPress và định tuyến đến quy trình làm việc chính xác cho plugin, theme, block và core checkouts. Chạy phân loại dự án tự động để xác định loại kho lưu trữ (plugin, theme, block theme, Gutenberg blocks, WP core) và công cụ có sẵn. Xuất kết quả phân loại và sơ đồ quyết định định tuyến đến các kỹ năng theo miền cụ thể dựa trên ý định người dùng và loại dự án. Yêu cầu quyền truy cập thư mục gốc kho lưu trữ và thao tác hệ thống tệp bash/Node; một số quy trình làm việc cần WP-CLI. Nhắm mục tiêu WordPress 6.9+ với PHP 7.2.24+;...
official
wp-abilities-api
wordpress
Đăng ký API Abilities của WordPress, hiển thị qua REST và tiêu thụ phía client cho WordPress 6.9+. Đăng ký abilities và categories trong PHP bằng wp_register_ability() và wp_register_ability_category() với ID ổn định, nhãn và siêu dữ liệu. Hiển thị abilities cho client qua các endpoint REST /wp-json/wp-abilities/v1/ bằng cách đặt meta.show_in_rest: true. Tiêu thụ abilities trong JavaScript bằng gói @wordpress/abilities để truy cập phía client và kiểm tra quyền. Yêu cầu WordPress 6.9+...
official
wp-abilities-audit
wordpress
Kiểm tra bề mặt REST của plugin WordPress và tạo ra một tài liệu kiểm tra chuẩn hóa đề xuất các đăng ký Abilities API. Tạo ra một tài liệu markdown với YAML…
official
wp-abilities-verify
wordpress
Xác minh đăng ký API Abilities của plugin WordPress: liệt kê các ability, kiểm tra rằng hành vi callback khớp với tuyên bố của từng chú thích (đối nghịch…
official
wp-block-development
wordpress
Phát triển block WordPress cho Gutenberg: siêu dữ liệu, đăng ký, hiển thị và quy trình xây dựng. Bao gồm tạo block, cấu hình block.json, hiển thị tĩnh so với động, và đăng ký PHP phía máy chủ với register_block_type_from_metadata(). Áp dụng apiVersion: 3 để tương thích với WordPress 6.9+, bao gồm hỗ trợ trình soạn thảo iframe và cách ly kiểu dáng. Xử lý tuần tự hóa thuộc tính, loại bỏ/di chuyển để ngăn lỗi "Invalid block", và kết hợp block bên trong. Bao gồm...
official
wp-block-themes
wordpress
Phát triển theme block WordPress: theme.json, templates, patterns, và khắc phục sự cố Site Editor. Bao gồm chỉnh sửa theme.json (presets, settings, kiểu dáng theo từng block), templates và template parts, patterns, và các biến thể kiểu dáng trên WordPress 6.9+. Có các script phân loại để phát hiện thư mục gốc theme và cấu trúc theme block, cùng quy trình hướng dẫn tạo theme mới hoặc chuyển đổi theme cổ điển. Cung cấp quy trình gỡ lỗi cho các vấn đề về thứ bậc kiểu dáng, ghi đè tùy chỉnh của người dùng, và Site...
official
wp-interactivity-api
wordpress
Sử dụng khi xây dựng hoặc gỡ lỗi các tính năng của WordPress Interactivity API (chỉ thị data-wp-*, store/state/actions của @wordpress/interactivity, block viewScriptModule…
official