Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
wordpress avatar

Wp Plugin Development

  • 4.7k installs
  • 1.9k repo stars
  • Updated July 27, 2026
  • wordpress/agent-skills

wp-plugin-development is an agent skill: Use when developing WordPress plugins: architecture and hooks, activation/deactivation/uninstall, admin UI and Settings API, data storage, c

About

The wp-plugin-development skill Use when developing WordPress plugins: architecture and hooks, activation/deactivation/uninstall, admin UI and Settings API, data storage, cron/tasks, security (nonces/capabilities/sanitization/escaping), and release packaging.. WP Plugin Development When to use Use this skill for plugin work such as: - creating or refactoring plugin structure (bootstrap, includes, namespaces/classes) - adding hooks/actions/filters - activation/deactivation/uninstall behavior and migrations - adding settings pages / options / admin UI (Settings API) - security fixes (nonces, capabilities, sanitization/escaping, SQL safety) - packaging a release (build artifacts, readme, assets) Inputs required - Repo root + target plugin(s) (path to plugin main file if known). - Where this plugin runs: single site vs multisite; WP.com conventions if applicable. - Target WordPress + Agents should read SKILL.md quick start steps, verify required binaries and environment variables, and follow reference files for exact parameters before calling tools.

  • Covers wp-plugin-development quick start, workflow steps, and reference pointers from SKILL.md.
  • Tagged for stage build and subphase backend in the closed Skillselion taxonomy.
  • Documents prerequisites, permissions shell, filesystem, git, and compatible agents.
  • Includes AEO tagMeta with task queries, keywords, and evidence quotes for discovery.
  • Cross-links related skills and generated REFERENCE.md tables where the repo provides them.

Wp Plugin Development by the numbers

  • 4,655 all-time installs (skills.sh)
  • +242 installs in the week ending Jul 28, 2026 (Skillselion tracking)
  • Ranked #4 of 65 PHP & Laravel skills by installs in the Skillselion catalog
  • Security screen: HIGH risk (skills.sh audit)
  • Data as of Jul 28, 2026 (Skillselion catalog sync)
At a glance

wp-plugin-development capabilities & compatibility

Capabilities
wp plugin development documented workflow · quick start examples · reference parameter lookup · taxonomy aligned metadata · aeo discovery fields
Use cases
api development · security audit
From the docs

What wp-plugin-development says it does

Use when developing WordPress plugins: architecture and hooks, activation/deactivation/uninstall, ad
SKILL.md
npx skills add https://github.com/wordpress/agent-skills --skill wp-plugin-development

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs4.7k
repo stars1.9k
Security audit2 / 3 scanners passed
Last updatedJuly 27, 2026
Repositorywordpress/agent-skills

How do I run wp-plugin-development correctly without guessing steps, tools, or parameters?

Use when developing WordPress plugins: architecture and hooks, activation/deactivation/uninstall, admin UI and Settings API, data storage, cron/tasks, security (nonces/capabilities/sanitization/e

Who is it for?

Teams using wp-plugin-development when SKILL.md triggers match the user request.

Skip if: Skip when the task is outside wp-plugin-development documented triggers or sibling skill scope.

When should I use this skill?

User mentions wp-plugin-development, related trigger phrases, or asks to follow this SKILL.md workflow.

What you get

Completed wp-plugin-development workflow with outputs and checks defined in SKILL.md.

  • wp-plugin-development output per SKILL.md

By the numbers

  • Stage build/backend
  • Category PHP & Laravel
  • Complexity intermediate

Files

SKILL.mdMarkdownGitHub ↗

WP Plugin Development

When to use

Use this skill for plugin work such as:

  • creating or refactoring plugin structure (bootstrap, includes, namespaces/classes)
  • adding hooks/actions/filters
  • activation/deactivation/uninstall behavior and migrations
  • adding settings pages / options / admin UI (Settings API)
  • security fixes (nonces, capabilities, sanitization/escaping, SQL safety)
  • packaging a release (build artifacts, readme, assets)

Inputs required

  • Repo root + target plugin(s) (path to plugin main file if known).
  • Where this plugin runs: single site vs multisite; WP.com conventions if applicable.
  • Target WordPress + PHP versions (affects available APIs and placeholder support in $wpdb->prepare()).

Procedure

0) Triage and locate plugin entrypoints

1. Run triage:

  • node skills/wp-project-triage/scripts/detect_wp_project.mjs

2. Detect plugin headers (deterministic scan):

  • node skills/wp-plugin-development/scripts/detect_plugins.mjs

If this is a full site repo, pick the specific plugin under wp-content/plugins/ or mu-plugins/ before changing code.

1) Follow a predictable architecture

Guidelines:

  • Keep a single bootstrap (main plugin file with header).
  • Avoid heavy side effects at file load time; load on hooks.
  • Prefer a dedicated loader/class to register hooks.
  • Keep admin-only code behind is_admin() (or admin hooks) to reduce frontend overhead.

See:

  • references/structure.md

2) Hooks and lifecycle (activation/deactivation/uninstall)

Activation hooks are fragile; follow guardrails:

  • register activation/deactivation hooks at top-level, not inside other hooks
  • flush rewrite rules only when needed and only after registering CPTs/rules
  • uninstall should be explicit and safe (uninstall.php or register_uninstall_hook)

See:

  • references/lifecycle.md

3) Settings and admin UI (Settings API)

Prefer Settings API for options:

  • register_setting(), add_settings_section(), add_settings_field()
  • sanitize via sanitize_callback

See:

  • references/settings-api.md

4) Security baseline (always)

Before shipping:

  • Validate/sanitize input early; escape output late.
  • Use nonces to prevent CSRF and capability checks for authorization.
  • Avoid directly trusting $_POST / $_GET; use wp_unslash() and specific keys.
  • Use $wpdb->prepare() for SQL; avoid building SQL with string concatenation.

See:

  • references/security.md

5) Data storage, cron, migrations (if needed)

  • Prefer options for small config; custom tables only if necessary.
  • For cron tasks, ensure idempotency and provide manual run paths (WP-CLI or admin).
  • For schema changes, write upgrade routines and store schema version.

See:

  • references/data-and-cron.md

Verification

  • Plugin activates with no fatals/notices.
  • Settings save and read correctly (capability + nonce enforced).
  • Uninstall removes intended data (and nothing else).
  • Run repo lint/tests (PHPUnit/PHPCS if present) and any JS build steps if the plugin ships assets.

Failure modes / debugging

  • Activation hook not firing:
  • hook registered incorrectly (not in main file scope), wrong main file path, or plugin is network-activated
  • Settings not saving:
  • settings not registered, wrong option group, missing capability, nonce failure
  • Security regressions:
  • nonce present but missing capability checks; or sanitized input not escaped on output

See:

  • references/debugging.md

Escalation

For canonical detail, consult the Plugin Handbook and security guidelines before inventing patterns.

Related skills

How it compares

wp-plugin-development implements its own SKILL.md workflow rather than a generic substitute skill.

FAQ

Who is wp-plugin-development for?

Agents and developers following the wp-plugin-development SKILL.md guidance.

When should I use wp-plugin-development?

When user intent matches description triggers and quick start scenarios.

Is wp-plugin-development safe to install?

Review the Security Audits panel before production shell or network use.

PHP & Laravelbackendtesting

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.