Agent skill

WordPress Pro

by Jeffallan in Jeffallan/claude-skills

Develops WordPress themes, plugins, Gutenberg blocks and WooCommerce features with nonce, escaping and capability checks, phpcs linting and caching tuned for speed.

MITAuto-check passedDevelopment

Install WordPress Pro

skills CLI
$ npx skills add Jeffallan/claude-skills --skill wordpress-pro -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Jeffallan/claude-skills wordpress-pro --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Jeffallan/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/wordpress-pro .claude/skills/wordpress-pro && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
wordpress-pro
GitHub stars
12k
Token cost
~1.6k tokens
SKILL.md length
374 words
Files
6 (incl. references)
Skills in repo
58
Repo updated
First seen
Licence
MIT

At a glance

Develops WordPress themes, plugins, Gutenberg blocks and WooCommerce features with nonce, escaping and capability checks, phpcs linting and caching tuned for speed.

  • Works in 6 steps: Analyze requirements — Understand… → Design architecture — Plan theme/plugin… → Implement — Build using WordPress coding… → …
  • Building a custom WordPress theme or child theme
  • SKILL.md covers Core Workflow, Reference Guide, Key Implementation Patterns and Constraints, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

The agent analyzes the WordPress setup and goals, plans theme or plugin structure, hooks and data flow, and builds to WordPress coding standards. Validation runs phpcs --standard=WordPress and checks nonce handling and capability checks by hand. Optimization applies transient or object caching, query tuning and proper asset enqueuing, and the final pass confirms sanitization and escaping on all input and output, tests across target WordPress versions and runs a security checklist.

Code patterns show nonce fields and verification, sanitizing with sanitize_text_field and wp_kses_post, enqueuing scripts and styles, prepared queries through $wpdb->prepare, and capability checks with current_user_can. Reference files cover themes with child themes and FSE, plugin architecture and the settings API, Gutenberg blocks and patterns, hooks and filters, and performance and security including backups.

When your agent uses it

  • Building a custom WordPress theme or child theme
  • Writing a plugin with activation hooks and a settings page
  • Registering Gutenberg blocks and block patterns
  • Extending WooCommerce or adding REST API endpoints
  • Hardening a site with nonces, escaping and capability checks

Example prompts

  • “Create a plugin with an options page that saves settings behind a nonce and capability check.”
  • “Register a dynamic Gutenberg block that lists the latest case studies.”
  • “Audit the theme's templates for unescaped output and fix it.”
  • “Speed up the archive page by caching the expensive query in a transient.”

Requirements

  • PHP with `phpcs` and the WordPress coding standards

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Analyze requirements — Understand WordPress context, existing setup, and goals.
  2. Design architecture — Plan theme/plugin structure, hooks, and data flow.
  3. Implement — Build using WordPress coding standards and security best practices.
  4. Validate — Run phpcs --standard=WordPress to catch WPCS violations; verify nonce handling and capability checks manually.
  5. Optimize — Apply transient/object caching, query optimization, and asset enqueuing.
  6. Test & secure — Confirm sanitization/escaping on all I/O, test across target WordPress versions, and run a security audit checklist.

What it can do on your machine

Read from SKILL.md and the folder at commit 1be15d8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are php).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • synergetic.solutions
    • jeffallan.github.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

WordPress Pro loads about 1.6k tokens when it runs, and up to ~35k if it reads all its reference files. Until then it costs about 140 tokens; SKILL.md has 374 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~140
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~35k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Jeffallan/claude-skills at commit 1be15d8, republished under its MIT licence (© Jeffallan). 374 words, ~1,610 tokens.

Download SKILL.mdSave it as .claude/skills/wordpress-pro/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
wordpress-pro
description
Develops custom WordPress themes and plugins, creates and registers Gutenberg blocks and block patterns, configures WooCommerce stores, implements WordPress REST API endpoints, applies security hardening (nonces, sanitization, escaping, capability checks), and optimizes performance through caching and query tuning. Use when building WordPress themes, writing plugins, customizing Gutenberg blocks, extending WooCommerce, working with ACF, using the WordPress REST API, applying hooks and filters, or improving WordPress performance and security.
license
MIT
metadata.author
https://github.com/Jeffallan
metadata.company
https://synergetic.solutions
metadata.version
1.1.0
metadata.domain
platform
metadata.triggers
WordPress, WooCommerce, Gutenberg, WordPress theme, WordPress plugin, custom blocks, ACF, WordPress REST API, hooks, filters, WordPress performance, WordPress…
metadata.role
expert
metadata.scope
implementation
metadata.output-format
code
metadata.related-skills
php-pro, laravel-specialist, fullstack-guardian, security-reviewer

WordPress Pro

Expert WordPress developer specializing in custom themes, plugins, Gutenberg blocks, WooCommerce, and WordPress performance optimization.

Core Workflow

  1. Analyze requirements — Understand WordPress context, existing setup, and goals.
  2. Design architecture — Plan theme/plugin structure, hooks, and data flow.
  3. Implement — Build using WordPress coding standards and security best practices.
  4. Validate — Run phpcs --standard=WordPress to catch WPCS violations; verify nonce handling and capability checks manually.
  5. Optimize — Apply transient/object caching, query optimization, and asset enqueuing.
  6. Test & secure — Confirm sanitization/escaping on all I/O, test across target WordPress versions, and run a security audit checklist.

Reference Guide

Load detailed guidance based on context:

TopicReferenceLoad When
Theme Developmentreferences/theme-development.mdTemplates, hierarchy, child themes, FSE
Plugin Architecturereferences/plugin-architecture.mdStructure, activation, settings API, updates
Gutenberg Blocksreferences/gutenberg-blocks.mdBlock dev, patterns, FSE, dynamic blocks
Hooks & Filtersreferences/hooks-filters.mdActions, filters, custom hooks, priorities
Performance & Securityreferences/performance-security.mdCaching, optimization, hardening, backups

Key Implementation Patterns

Nonce Verification (form submissions)
php
// Output nonce field in form
wp_nonce_field( 'my_action', 'my_nonce' );

// Verify on submission — bail early if invalid
if ( ! isset( $_POST['my_nonce'] ) || ! wp_verify_nonce( sanitize_text_field( wp_unslash( $_POST['my_nonce'] ) ), 'my_action' ) ) {
    wp_die( esc_html__( 'Security check failed.', 'my-textdomain' ) );
}
Sanitization & Escaping
php
// Sanitize input (store)
$title   = sanitize_text_field( wp_unslash( $_POST['title'] ?? '' ) );
$content = wp_kses_post( wp_unslash( $_POST['content'] ?? '' ) );
$url     = esc_url_raw( wp_unslash( $_POST['url'] ?? '' ) );

// Escape output (display)
echo esc_html( $title );
echo wp_kses_post( $content );
echo '<a href="' . esc_url( $url ) . '">' . esc_html__( 'Link', 'my-textdomain' ) . '</a>';
Enqueuing Scripts & Styles
php
add_action( 'wp_enqueue_scripts', 'my_theme_assets' );
function my_theme_assets(): void {
    wp_enqueue_style(
        'my-theme-style',
        get_stylesheet_uri(),
        [],
        wp_get_theme()->get( 'Version' )
    );
    wp_enqueue_script(
        'my-theme-script',
        get_template_directory_uri() . '/assets/js/main.js',
        [ 'jquery' ],
        '1.0.0',
        true // load in footer
    );
    // Pass server data to JS safely
    wp_localize_script( 'my-theme-script', 'MyTheme', [
        'ajaxUrl' => admin_url( 'admin-ajax.php' ),
        'nonce'   => wp_create_nonce( 'my_ajax_nonce' ),
    ] );
}
Prepared Database Queries
php
global $wpdb;
$results = $wpdb->get_results(
    $wpdb->prepare(
        "SELECT * FROM {$wpdb->prefix}my_table WHERE user_id = %d AND status = %s",
        absint( $user_id ),
        sanitize_text_field( $status )
    )
);
Capability Checks
php
// Always check capabilities before sensitive operations
if ( ! current_user_can( 'manage_options' ) ) {
    wp_die( esc_html__( 'You do not have permission to do this.', 'my-textdomain' ) );
}

Constraints

MUST DO
  • Follow WordPress Coding Standards (WPCS); validate with phpcs --standard=WordPress
  • Use nonces for all form submissions and AJAX requests
  • Sanitize all user inputs with appropriate functions (sanitize_text_field, wp_kses_post, etc.)
  • Escape all outputs (esc_html, esc_url, esc_attr, wp_kses_post)
  • Use prepared statements for all database queries ($wpdb->prepare)
  • Implement proper capability checks before privileged operations
  • Enqueue scripts/styles via wp_enqueue_scripts / admin_enqueue_scripts hooks
  • Use WordPress hooks instead of modifying core
  • Write translatable strings with text domains (__(), esc_html__(), etc.)
  • Test across target WordPress versions
Show full SKILL.md (131 more words)Show less
MUST NOT DO
  • Modify WordPress core files
  • Use PHP short tags or deprecated functions
  • Trust user input without sanitization
  • Output data without escaping
  • Hardcode database table names (use $wpdb->prefix)
  • Skip capability checks in admin functions
  • Ignore SQL injection vectors
  • Bundle unnecessary libraries when WordPress APIs suffice
  • Allow unsafe file upload handling
  • Skip internationalization (i18n)

Output Templates

When implementing WordPress features, provide:

  1. Main plugin/theme file with proper headers
  2. Relevant template files or block code
  3. Functions with proper WordPress hooks
  4. Security implementations (nonces, sanitization, escaping)
  5. Brief explanation of WordPress-specific patterns used

Knowledge Reference

WordPress 6.4+, PHP 8.1+, Gutenberg, WooCommerce, ACF, REST API, WP-CLI, block development, theme customizer, widget API, shortcode API, transients, object caching, query optimization, security hardening, WPCS

Maintained by @jeffallan, Principal Consultant at Synergetic Solutions

Documentation

© Jeffallan, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (references) in skills/wordpress-pro of Jeffallan/claude-skills.

  • SKILL.md
  • references/gutenberg-blocks.md
  • references/hooks-filters.md
  • references/performance-security.md
  • references/plugin-architecture.md
  • references/theme-development.md

Open the folder on GitHubat commit 1be15d8

Compare with similar skills

WordPress Pro next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

WordPress Pro compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
WordPress Pro this skillJeffallan/claude-skills12k—~1.6kAutomated safety check: PassMIT
WordPress Code GuardamElnagdy/guard-skills1.3k—~2.4kAutomated safety check: PassMIT
Wp Performancegambitph/Stackable3503 repos~1.5kAutomated safety check: PassGPL-3.0
WooCommerce Store API Routeswoocommerce/woocommerce11k—~932Automated safety check: PassCustom licence
Wp Performance Reviewelvismdev/claude-wordpress-skills2341 repos~4.5kAutomated safety check: PassMIT
WooCommerce Backend Conventionswoocommerce/woocommerce11k1 repos~614Automated safety check: PassCustom licence

Similar skills

  • WordPress Code Guard

    amElnagdy/guard-skills

    Reviews WordPress plugin, theme and block code after an agent writes or edits it, catching missing escaping, nonces, capability checks and unprepared queries.

    1.3k GitHub stars~2.4k tokensUpdated 3 mo ago
    DevelopmentAuto-check passed
  • Wp Performance

    gambitph/Stackable

    A skill your agent uses when investigating or improving WordPress performance (backend-only agent): profiling and measurement (WP-CLI profile/doctor, Server-Timing, Query Monitor via REST headers)…

    350 GitHub starsUsed in 3 repos~1.5k tokens
    Backend & APIsAuto-check passed
  • WooCommerce Store API Routes

    woocommerce/woocommerce

    Guidelines for adding or changing routes in the WooCommerce Store API under /wc/store/v1, covering authentication, REST design, schemas and variations.

    11k GitHub stars~932 tokensUpdated today
    Backend & APIsAuto-check passed
  • Wp Performance Review

    elvismdev/claude-wordpress-skills

    WordPress performance code review and optimization analysis.

    234 GitHub starsUsed in 1 repo~4.5k tokens
    Business, Finance & HRAuto-check passed
  • WooCommerce Backend Conventions

    woocommerce/woocommerce

    Guides agents writing or changing WooCommerce backend PHP so new classes, hooks and unit tests follow the project's conventions.

    11k GitHub starsUsed in 1 repo~614 tokens
    DevelopmentAuto-check passed
  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed

More from Jeffallan/claude-skills

All 58 skills in this repo
  • API Designer

    Jeffallan/claude-skills

    Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.

    12k GitHub starsUsed in 2 repos~2k tokens
    Auto-check passed
  • CLI Developer

    Jeffallan/claude-skills

    Walks through designing, building and polishing a command-line tool: user workflow and command hierarchy, implementation in commander, click, typer or cobra, completions and cross-platform testing.

    12k GitHub starsUsed in 1 repo~1.2k tokens
    Auto-check passed
  • Fine-Tuning Expert

    Jeffallan/claude-skills

    Guides LLM fine-tuning with LoRA and QLoRA through Hugging Face PEFT, from dataset validation and training checks to adapter merging, quantization and deployment.

    12k GitHub starsUsed in 1 repo~1.7k tokens
    Auto-check passed
  • GraphQL Architect

    Jeffallan/claude-skills

    Designs GraphQL schemas and Apollo Federation graphs, with DataLoader resolvers, subscriptions, query complexity limits and caching.

    12k GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • Kubernetes Specialist

    Jeffallan/claude-skills

    Creates and checks Kubernetes manifests, Helm charts, RBAC and network policies, and helps debug pod problems, with kubectl checks and rollback steps.

    12k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Laravel Specialist

    Jeffallan/claude-skills

    Builds Laravel 10+ applications with Eloquent models, Sanctum authentication, Horizon queues, API resources and Livewire components, tested with Pest or PHPUnit.

    12k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed

Questions about WordPress Pro

What does WordPress Pro do?

Develops WordPress themes, plugins, Gutenberg blocks and WooCommerce features with nonce, escaping and capability checks, phpcs linting and caching tuned for speed. The agent analyzes the WordPress setup and goals, plans theme or plugin structure, hooks and data flow, and builds to WordPress coding standards. Validation runs phpcs --standard=WordPress and checks nonce handling and capability checks by hand.

When should I use WordPress Pro?

WordPress Pro fits situations like: building a custom WordPress theme or child theme; writing a plugin with activation hooks and a settings page; registering Gutenberg blocks and block patterns; extending WooCommerce or adding REST API endpoints.

How do I install WordPress Pro in Claude Code?

Run `npx skills add Jeffallan/claude-skills --skill wordpress-pro -a claude-code`. Or copy the skill folder (skills/wordpress-pro in Jeffallan/claude-skills) into .claude/skills/wordpress-pro in your project. Claude Code loads it when a task matches its description.

How do I install WordPress Pro in Codex?

Run `npx skills add Jeffallan/claude-skills --skill wordpress-pro -a codex`. Or copy the skill folder (skills/wordpress-pro in Jeffallan/claude-skills) into .agents/skills/wordpress-pro in your project. Codex loads it when a task matches its description.

Can I use WordPress Pro in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Jeffallan/claude-skills --skill wordpress-pro -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/wordpress-pro, .gemini/skills/wordpress-pro, .github/skills/wordpress-pro and .opencode/skills/wordpress-pro in your project.

What does WordPress Pro need to run?

SKILL.md names no scripts, command-line tools or credentials: WordPress Pro is instructions for the agent only. Our summary lists: PHP with `phpcs` and the WordPress coding standards.

Does WordPress Pro access the network?

SKILL.md names 3 domains. As links in the text: github.com, synergetic.solutions and jeffallan.github.io. This is read from the text; nothing was executed.

Is WordPress Pro safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does WordPress Pro use?

WordPress Pro is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does WordPress Pro use?

About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 33k tokens, read only when the agent opens those files.

What are the alternatives to WordPress Pro?

Skills that share tags, products or a category with WordPress Pro: WordPress Code Guard (amElnagdy/guard-skills, 1.3k stars), Wp Performance (gambitph/Stackable, 350 stars), WooCommerce Store API Routes (woocommerce/woocommerce, 11k stars) and Wp Performance Review (elvismdev/claude-wordpress-skills, 234 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains WordPress Pro?

Jeffallan (a GitHub user) maintains it in Jeffallan/claude-skills, which has 11,754 GitHub stars. The repository holds 58 skills in this directory. The repository was last updated on October 3, 2026.

Source: Jeffallan/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.