WordPress Code Guard
amElnagdy/guard-skills
Reviews WordPress plugin, theme and block code after an agent writes or edits it, catching missing escaping, nonces, capability checks and unprepared queries.
WordPress performance code review and optimization analysis.
$ npx skills add elvismdev/claude-wordpress-skills --skill wp-performance-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install elvismdev/claude-wordpress-skills wp-performance-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/elvismdev/claude-wordpress-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/wp-performance-review .claude/skills/wp-performance-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "wp-performance-review" agent skill from https://github.com/elvismdev/claude-wordpress-skills/tree/master/skills/wp-performance-review into .claude/skills/wp-performance-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wp-performance-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/elvismdev/claude-wordpress-skills/tree/master/skills/wp-performance-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add elvismdev/claude-wordpress-skills --skill wp-performance-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install elvismdev/claude-wordpress-skills wp-performance-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elvismdev/claude-wordpress-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/wp-performance-review .agents/skills/wp-performance-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "wp-performance-review" agent skill from https://github.com/elvismdev/claude-wordpress-skills/tree/master/skills/wp-performance-review into .agents/skills/wp-performance-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wp-performance-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elvismdev/claude-wordpress-skills --skill wp-performance-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install elvismdev/claude-wordpress-skills wp-performance-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elvismdev/claude-wordpress-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/wp-performance-review .cursor/skills/wp-performance-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "wp-performance-review" agent skill from https://github.com/elvismdev/claude-wordpress-skills/tree/master/skills/wp-performance-review into .cursor/skills/wp-performance-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wp-performance-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/elvismdev/claude-wordpress-skills.git --path skills/wp-performance-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add elvismdev/claude-wordpress-skills --skill wp-performance-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install elvismdev/claude-wordpress-skills wp-performance-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elvismdev/claude-wordpress-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/wp-performance-review .gemini/skills/wp-performance-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "wp-performance-review" agent skill from https://github.com/elvismdev/claude-wordpress-skills/tree/master/skills/wp-performance-review into .gemini/skills/wp-performance-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wp-performance-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install elvismdev/claude-wordpress-skills wp-performance-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add elvismdev/claude-wordpress-skills --skill wp-performance-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/elvismdev/claude-wordpress-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/wp-performance-review .github/skills/wp-performance-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "wp-performance-review" agent skill from https://github.com/elvismdev/claude-wordpress-skills/tree/master/skills/wp-performance-review into .github/skills/wp-performance-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wp-performance-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elvismdev/claude-wordpress-skills --skill wp-performance-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install elvismdev/claude-wordpress-skills wp-performance-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elvismdev/claude-wordpress-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/wp-performance-review .opencode/skills/wp-performance-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "wp-performance-review" agent skill from https://github.com/elvismdev/claude-wordpress-skills/tree/master/skills/wp-performance-review into .opencode/skills/wp-performance-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wp-performance-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
wp-performance-reviewWordPress performance code review and optimization analysis.
Wp Performance Review is an agent skill from elvismdev/claude-wordpress-skills. WordPress performance code review and optimization analysis. Use when reviewing WordPress PHP code for performance issues, auditing themes/plugins for scalability, optimizing WPQuery, analyzing caching strategies, checking code before launch, or detecting anti-patterns, or when user mentions "performance review", "optimization audit", "slow WordPress", "slow queries", "high-traffic", "scale WordPress", "code review", "timeout", "500 error", "out of memory", or "site won't load". Detects anti-patterns in database…
Its SKILL.md is about 4.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/anti-patterns.md`, `references/caching-guide.md` and `references/measurement-guide.md`).
It sits in Business, Finance & HR, covering Performance reviews, Caching and Code review. It works with WordPress and PHP. The repository describes itself as: Professional WordPress engineering skills for Claude Code - performance optimization, security auditing, Gutenberg block development, and theme/plugin best practices. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 0ac0bbd. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are php, bash, javascript and markdown).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Wp Performance Review loads about 4.5k tokens when it runs, and up to ~21k if it reads all its reference files. Until then it costs about 150 tokens; SKILL.md has 817 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from elvismdev/claude-wordpress-skills at commit 0ac0bbd, republished under its MIT licence (© elvismdev). 817 words, ~4,499 tokens.
.claude/skills/wp-performance-review/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Systematic performance code review for WordPress themes, plugins, and custom code. Core principle: Scan critical issues first (OOM, unbounded queries, cache bypass), then warnings, then optimizations. Report with line numbers and severity levels.
Use when:
Don't use for:
functions.php, plugin.php, *.php)Scan for:
query_posts() → CRITICAL: Never use - breaks main queryposts_per_page.*-1 or numberposts.*-1 → CRITICAL: Unbounded querysession_start() → CRITICAL: Bypasses page cacheadd_action.*init.* or add_action.*wp_loaded → Check if expensive code runs every requestupdate_option or add_option in non-admin context → WARNING: DB writes on page loadwp_remote_get or wp_remote_post without caching → WARNING: Blocking HTTPScan for:
posts_per_page argument → WARNING: Defaults to blog setting'meta_query' with 'value' comparisons → WARNING: Unindexed column scanpost__not_in with large arrays → WARNING: Slow exclusionLIKE '%term%' (leading wildcard) → WARNING: Full table scanno_found_rows => true when not paginating → INFO: Unnecessary countwp_ajax_*, REST endpoints)Scan for:
admin-ajax.php usage → INFO: Consider REST API insteadsetInterval or polling patterns → CRITICAL: Self-DDoS risk*.php in theme)Scan for:
get_template_part in loops → WARNING: Consider caching outputwp_remote_get in templates → WARNING: Blocks renderingScan for:
$.post( for read operations → WARNING: Use GET for cacheabilitysetInterval.*fetch\|ajax → CRITICAL: Polling patternimport _ from 'lodash' → WARNING: Full library import bloats bundle<script> making AJAX calls on load → Check necessityblock.json, *.js in blocks/)Scan for:
registerBlockStyle() calls → WARNING: Each creates preview iframewp_kses_post($content) in render callbacks → WARNING: Breaks InnerBlocksrender_callback → INFO: Consider dynamic for maintainabilityfunctions.php, *.php)Scan for:
wp_enqueue_script without version → INFO: Cache busting issueswp_enqueue_script without defer/async strategy → INFO: Blocks renderingTHEME_VERSION constant → INFO: Version managementwp_enqueue_script without conditional check → WARNING: Assets load globally when only needed on specific pagesScan for:
set_transient with dynamic keys (e.g., user_{$id}) → WARNING: Table bloat without object cacheset_transient for frequently-changing data → WARNING: Defeats caching purposeScan for:
DISABLE_WP_CRON constant → INFO: Cron runs on page requestswp_schedule_event without checking if already scheduled → WARNING: Duplicate schedules# Critical issues - scan these first
grep -rn "posts_per_page.*-1\|numberposts.*-1" .
grep -rn "query_posts\s*(" .
grep -rn "session_start\s*(" .
grep -rn "setInterval.*fetch\|setInterval.*ajax\|setInterval.*\\\$\." .
# Database writes on frontend
grep -rn "update_option\|add_option" . | grep -v "admin\|activate\|install"
# Uncached expensive functions
grep -rn "url_to_postid\|attachment_url_to_postid\|count_user_posts" .
# External HTTP without caching
grep -rn "wp_remote_get\|wp_remote_post\|file_get_contents.*http" .
# Cache bypass risks
grep -rn "setcookie\|session_start" .
# PHP code anti-patterns
grep -rn "in_array\s*(" . | grep -v "true\s*)" # Missing strict comparison
grep -rn "<<<" . # Heredoc/nowdoc syntax
grep -rn "cache_results.*false" .
# JavaScript bundle issues
grep -rn "import.*from.*lodash['\"]" . # Full lodash import
grep -rn "registerBlockStyle" . # Many block styles = performance issue
# Asset loading issues
grep -rn "wp_enqueue_script\|wp_enqueue_style" . | grep -v "is_page\|is_singular\|is_admin"
# Transient misuse
grep -rn "set_transient.*\\\$" . # Dynamic transient keys
grep -rn "set_transient" . | grep -v "get_transient" # Set without checking first
# WP-Cron issues
grep -rn "wp_schedule_event" . | grep -v "wp_next_scheduled" # Missing schedule checkDifferent hosting environments require different approaches:
Managed WordPress Hosts (WP Engine, Pantheon, Pressable, WordPress VIP, etc.):
wpcom_vip_* on VIP)Self-Hosted / Standard Hosting:
Shared Hosting:
// ❌ CRITICAL: Unbounded query.
'posts_per_page' => -1
// ✅ GOOD: Set reasonable limit, paginate if needed.
'posts_per_page' => 100,
'no_found_rows' => true, // Skip count if not paginating.
// ❌ CRITICAL: Never use query_posts().
query_posts( 'cat=1' ); // Breaks pagination, conditionals.
// ✅ GOOD: Use WP_Query or pre_get_posts filter.
$query = new WP_Query( array( 'cat' => 1 ) );
// Or modify main query:
add_action( 'pre_get_posts', function( $query ) {
if ( $query->is_main_query() && ! is_admin() ) {
$query->set( 'cat', 1 );
}
} );
// ❌ CRITICAL: Missing WHERE clause (falsy ID becomes 0).
$query = new WP_Query( array( 'p' => intval( $maybe_false_id ) ) );
// ✅ GOOD: Validate ID before querying.
if ( ! empty( $maybe_false_id ) ) {
$query = new WP_Query( array( 'p' => intval( $maybe_false_id ) ) );
}
// ❌ WARNING: LIKE with leading wildcard (full table scan).
$wpdb->get_results( "SELECT * FROM wp_posts WHERE post_title LIKE '%term%'" );
// ✅ GOOD: Use trailing wildcard only, or use WP_Query 's' parameter.
$wpdb->get_results( $wpdb->prepare(
"SELECT * FROM wp_posts WHERE post_title LIKE %s",
$wpdb->esc_like( $term ) . '%'
) );
// ❌ WARNING: NOT IN queries (filter in PHP instead).
'post__not_in' => $excluded_ids
// ✅ GOOD: Fetch all, filter in PHP (faster for large exclusion lists).
$posts = get_posts( array( 'posts_per_page' => 100 ) );
$posts = array_filter( $posts, function( $post ) use ( $excluded_ids ) {
return ! in_array( $post->ID, $excluded_ids, true );
} );// ❌ WARNING: Code runs on every request via init.
add_action( 'init', 'expensive_function' );
// ✅ GOOD: Check context before running expensive code.
add_action( 'init', function() {
if ( is_admin() || wp_doing_cron() ) {
return;
}
// Frontend-only code here.
} );
// ❌ CRITICAL: Database writes on every page load.
add_action( 'wp_head', 'prefix_bad_tracking' );
function prefix_bad_tracking() {
update_option( 'last_visit', time() );
}
// ✅ GOOD: Use object cache buffer, flush via cron.
add_action( 'shutdown', function() {
wp_cache_incr( 'page_views_buffer', 1, 'counters' );
} );
// ❌ WARNING: Using admin-ajax.php instead of REST API.
// Prefer: register_rest_route() - leaner bootstrap.// ❌ WARNING: O(n) lookup - use isset() with associative array.
in_array( $value, $array ); // Also missing strict = true.
// ✅ GOOD: O(1) lookup with isset().
$allowed = array( 'foo' => true, 'bar' => true );
if ( isset( $allowed[ $value ] ) ) {
// Process.
}
// ❌ WARNING: Heredoc prevents late escaping.
$html = <<<HTML
<div>$unescaped_content</div>
HTML;
// ✅ GOOD: Escape at output.
printf( '<div>%s</div>', esc_html( $content ) );// ❌ WARNING: Uncached expensive function calls.
url_to_postid( $url );
attachment_url_to_postid( $attachment_url );
count_user_posts( $user_id );
wp_oembed_get( $url );
// ✅ GOOD: Wrap with object cache (works on any host).
function prefix_cached_url_to_postid( $url ) {
$cache_key = 'url_to_postid_' . md5( $url );
$post_id = wp_cache_get( $cache_key, 'url_lookups' );
if ( false === $post_id ) {
$post_id = url_to_postid( $url );
wp_cache_set( $cache_key, $post_id, 'url_lookups', HOUR_IN_SECONDS );
}
return $post_id;
}
// ✅ GOOD: On WordPress VIP, use platform helpers instead.
// wpcom_vip_url_to_postid(), wpcom_vip_attachment_url_to_postid(), etc.
// ❌ WARNING: Large autoloaded options.
add_option( 'prefix_large_data', $data ); // Add: , '', 'no' for autoload.
// ❌ INFO: Missing wp_cache_get_multiple for batch lookups.
foreach ( $ids as $id ) {
wp_cache_get( "key_{$id}" );
}// ❌ WARNING: AJAX POST request (bypasses cache).
$.post( ajaxurl, data ); // Prefer: $.get() for read operations.
// ❌ CRITICAL: Polling pattern (self-DDoS).
setInterval( () => fetch( '/wp-json/...' ), 5000 );// ❌ WARNING: Synchronous external HTTP in page load.
wp_remote_get( $url ); // Cache result or move to cron.
// ✅ GOOD: Set timeout and handle errors.
$response = wp_remote_get( $url, array( 'timeout' => 2 ) );
if ( is_wp_error( $response ) ) {
return get_fallback_data();
}// ❌ WARNING: WP Cron runs on page requests.
// Add to wp-config.php:
define( 'DISABLE_WP_CRON', true );
// Run via server cron: * * * * * wp cron event run --due-now
// ❌ CRITICAL: Long-running cron blocks entire queue.
add_action( 'my_daily_sync', function() {
foreach ( get_users() as $user ) { // 50k users = hours.
sync_user_data( $user );
}
} );
// ✅ GOOD: Batch processing with rescheduling.
add_action( 'my_batch_sync', function() {
$offset = (int) get_option( 'sync_offset', 0 );
$users = get_users( array( 'number' => 100, 'offset' => $offset ) );
if ( empty( $users ) ) {
delete_option( 'sync_offset' );
return;
}
foreach ( $users as $user ) {
sync_user_data( $user );
}
update_option( 'sync_offset', $offset + 100 );
wp_schedule_single_event( time() + 60, 'my_batch_sync' );
} );
// ❌ WARNING: Scheduling without checking if already scheduled.
wp_schedule_event( time(), 'hourly', 'my_task' ); // Creates duplicates!
// ✅ GOOD: Check before scheduling.
if ( ! wp_next_scheduled( 'my_task' ) ) {
wp_schedule_event( time(), 'hourly', 'my_task' );
}// ❌ CRITICAL: Plugin starts PHP session on frontend (bypasses ALL page cache).
session_start(); // Check plugins for this - entire site becomes uncacheable!
// ❌ WARNING: Unique query params create cache misses.
// https://example.com/?utm_source=fb&utm_campaign=123&fbclid=abc
// Each unique URL = separate cache entry = cache miss.
// Solution: Strip marketing params at CDN/edge level.
// ❌ WARNING: Setting cookies on public pages.
setcookie( 'visitor_id', $id ); // Prevents caching for that user.// ❌ WARNING: Dynamic transient keys create table bloat (without object cache).
set_transient( "user_{$user_id}_cart", $data, HOUR_IN_SECONDS );
// 10,000 users = 10,000 rows in wp_options!
// ✅ GOOD: Use object cache for user-specific data.
wp_cache_set( "cart_{$user_id}", $data, 'user_carts', HOUR_IN_SECONDS );
// ❌ WARNING: Transients for frequently-changing data defeats purpose.
set_transient( 'visitor_count', $count, 60 ); // Changes every minute.
// ✅ GOOD: Use object cache for volatile data.
wp_cache_set( 'visitor_count', $count, 'stats' );
// ❌ WARNING: Large data in transients on shared hosting.
set_transient( 'api_response', $megabytes_of_json, DAY_IN_SECONDS );
// Without object cache = serialized blob in wp_options.
// ✅ GOOD: Check hosting before using transients for large data.
if ( wp_using_ext_object_cache() ) {
set_transient( 'api_response', $data, DAY_IN_SECONDS );
} else {
// Store in files or skip caching on shared hosting.
}// ❌ WARNING: Assets load globally when only needed on specific pages.
add_action( 'wp_enqueue_scripts', function() {
wp_enqueue_script( 'contact-form-js', ... );
wp_enqueue_style( 'contact-form-css', ... );
} );
// ✅ GOOD: Conditional enqueue based on page/template.
add_action( 'wp_enqueue_scripts', function() {
if ( is_page( 'contact' ) || is_page_template( 'contact-template.php' ) ) {
wp_enqueue_script( 'contact-form-js', ... );
wp_enqueue_style( 'contact-form-css', ... );
}
} );
// ✅ GOOD: Only load WooCommerce assets on shop pages.
add_action( 'wp_enqueue_scripts', function() {
if ( ! is_woocommerce() && ! is_cart() && ! is_checkout() ) {
wp_dequeue_style( 'woocommerce-general' );
wp_dequeue_script( 'wc-cart-fragments' );
}
} );// ❌ WARNING: No timeout set (default is 5 seconds).
wp_remote_get( $url ); // Set timeout: array( 'timeout' => 2 ).
// ❌ WARNING: Missing error handling for API failures.
$response = wp_remote_get( $url );
echo $response['body']; // Check is_wp_error() first!// ❌ WARNING: Generating sitemaps for deep archives (crawlers hammer these).
// Solution: Exclude old post types, cache generated sitemaps.
// ❌ CRITICAL: Redirect loops consuming CPU.
// Debug with: x-redirect-by header, wp_debug_backtrace_summary().// ❌ WARNING: Searching meta_value without index.
'meta_query' => array(
array(
'key' => 'color',
'value' => 'red',
),
)
// Better: Use taxonomy or encode value in meta_key name.
// ❌ WARNING: Binary meta values requiring value scan.
'meta_key' => 'featured',
'meta_value' => 'true',
// Better: Presence of 'is_featured' key = true, absence = false.For deeper context on any pattern: Load references/anti-patterns.md
| Severity | Description |
|---|---|
| Critical | Will cause failures at scale (OOM, 500 errors, DB locks) |
| Warning | Degrades performance under load |
| Info | Optimization opportunity |
Structure findings as:
## Performance Review: [filename/component]
### Critical Issues
- **Line X**: [Issue] - [Explanation] - [Fix]
### Warnings
- **Line X**: [Issue] - [Explanation] - [Fix]
### Recommendations
- [Optimization opportunities]
### Summary
- Total issues: X Critical, Y Warnings, Z Info
- Estimated impact: [High/Medium/Low]When performing performance reviews, avoid these errors:
| Mistake | Why It's Wrong | Fix |
|---|---|---|
Flagging posts_per_page => -1 in admin-only code | Admin queries don't face public scale | Check context - admin, CLI, cron are lower risk |
Missing the session_start() buried in a plugin | Cache bypass affects entire site | Always grep for session_start across all code |
Ignoring no_found_rows for non-paginated queries | Small optimization but adds up | Flag as INFO, not WARNING |
| Recommending object cache on shared hosting | Many shared hosts lack persistent cache | Check hosting environment first |
| Only reviewing PHP, missing JS polling | JS setInterval + fetch = self-DDoS | Review .js files for polling patterns |
Load these references based on the task:
| Task | Reference to Load |
|---|---|
| Reviewing PHP code for issues | references/anti-patterns.md |
| Optimizing WP_Query calls | references/wp-query-guide.md |
| Implementing caching | references/caching-guide.md |
| High-traffic event prep | references/measurement-guide.md |
Note: For standard code reviews, anti-patterns.md contains all patterns needed. Other references provide deeper context when specifically optimizing queries, implementing caching strategies, or preparing for traffic events.
© elvismdev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (references) in skills/wp-performance-review of elvismdev/claude-wordpress-skills.
Open the folder on GitHubat commit 0ac0bbd
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in elvismdev/claude-wordpress-skills, which our catalogue first saw on October 7, 2026.
Wp Performance Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Wp Performance Review this skillelvismdev/claude-wordpress-skills | 234 | 1 repos | ~4.5k | Automated safety check: Pass | MIT | |
| WordPress Code GuardamElnagdy/guard-skills | 1.3k | — | ~2.4k | Automated safety check: Pass | MIT | |
| WordPress ProJeffallan/claude-skills | 12k | — | ~1.6k | Automated safety check: Pass | MIT | |
| WooCommerce Code Reviewwoocommerce/woocommerce | 11k | 3 repos | ~1.1k | Automated safety check: Pass | Custom licence | |
| Performance CheckZeroDeng01/sublinkPro | 1.7k | — | ~1.8k | Automated safety check: Pass | MIT | |
| Wp Performancegambitph/Stackable | 350 | 3 repos | ~1.5k | Automated safety check: Pass | GPL-3.0 |
amElnagdy/guard-skills
Reviews WordPress plugin, theme and block code after an agent writes or edits it, catching missing escaping, nonces, capability checks and unprepared queries.
Jeffallan/claude-skills
Develops WordPress themes, plugins, Gutenberg blocks and WooCommerce features with nonce, escaping and capability checks, phpcs linting and caching tuned for speed.
woocommerce/woocommerce
Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.
ZeroDeng01/sublinkPro
Checklist for reviewing code changes that touch queries, APIs, rendering, caching or algorithms for performance, scalability and resource-usage problems.
gambitph/Stackable
A skill your agent uses when investigating or improving WordPress performance (backend-only agent): profiling and measurement (WP-CLI profile/doctor, Server-Timing, Query Monitor via REST headers)…
jorgerosal/wordpress-skills
WordPress block editor code review and Gutenberg block development patterns for WordPress 6.x+.
Categories
WordPress performance code review and optimization analysis. Wp Performance Review is an agent skill from elvismdev/claude-wordpress-skills. WordPress performance code review and optimization analysis.
Wp Performance Review fits situations like: reviewing WordPress PHP code for performance issues; auditing themes/plugins for scalability; optimizing WPQuery; analyzing caching strategies.
Run `npx skills add elvismdev/claude-wordpress-skills --skill wp-performance-review -a claude-code`. Or copy the skill folder (skills/wp-performance-review in elvismdev/claude-wordpress-skills) into .claude/skills/wp-performance-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add elvismdev/claude-wordpress-skills --skill wp-performance-review -a codex`. Or copy the skill folder (skills/wp-performance-review in elvismdev/claude-wordpress-skills) into .agents/skills/wp-performance-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elvismdev/claude-wordpress-skills --skill wp-performance-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/wp-performance-review, .gemini/skills/wp-performance-review, .github/skills/wp-performance-review and .opencode/skills/wp-performance-review in your project.
SKILL.md names no scripts, command-line tools or credentials: Wp Performance Review is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Wp Performance Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.5k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 16k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Wp Performance Review: WordPress Code Guard (amElnagdy/guard-skills, 1.3k stars), WordPress Pro (Jeffallan/claude-skills, 12k stars), WooCommerce Code Review (woocommerce/woocommerce, 11k stars) and Performance Check (ZeroDeng01/sublinkPro, 1.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
elvismdev (a GitHub user) maintains it in elvismdev/claude-wordpress-skills, which has 234 GitHub stars. The repository was last updated on November 29, 2025.
Source: elvismdev/claude-wordpress-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.