Php Wordpress Audit
0xShe/PHP-Code-Audit-Skill
WordPress 框架特效安全审计工具。针对 WordPress 常见 nonce/capability/checkadminreferer、AJAX action、escape/sanitize、重定向、安全上传与远程请求等机制进行白盒静态审计,并映射到通用漏洞类型体系(AUTH/CSRF/XSS/SQL/CFG/SSRF 等)。
WordPress plugin development with hooks, security, REST API, custom post types.
$ npx skills add secondsky/claude-skills --skill wordpress-plugin-core -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install secondsky/claude-skills wordpress-plugin-core --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/secondsky/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/wordpress-plugin-core/skills/wordpress-plugin-core .claude/skills/wordpress-plugin-core && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "wordpress-plugin-core" agent skill from https://github.com/secondsky/claude-skills/tree/main/plugins/wordpress-plugin-core/skills/wordpress-plugin-core into .claude/skills/wordpress-plugin-core/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wordpress-plugin-core", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/secondsky/claude-skills/tree/main/plugins/wordpress-plugin-core/skills/wordpress-plugin-coreType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add secondsky/claude-skills --skill wordpress-plugin-core -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install secondsky/claude-skills wordpress-plugin-core --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/secondsky/claude-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/wordpress-plugin-core/skills/wordpress-plugin-core .agents/skills/wordpress-plugin-core && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "wordpress-plugin-core" agent skill from https://github.com/secondsky/claude-skills/tree/main/plugins/wordpress-plugin-core/skills/wordpress-plugin-core into .agents/skills/wordpress-plugin-core/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wordpress-plugin-core", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add secondsky/claude-skills --skill wordpress-plugin-core -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install secondsky/claude-skills wordpress-plugin-core --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/secondsky/claude-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/wordpress-plugin-core/skills/wordpress-plugin-core .cursor/skills/wordpress-plugin-core && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "wordpress-plugin-core" agent skill from https://github.com/secondsky/claude-skills/tree/main/plugins/wordpress-plugin-core/skills/wordpress-plugin-core into .cursor/skills/wordpress-plugin-core/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wordpress-plugin-core", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/secondsky/claude-skills.git --path plugins/wordpress-plugin-core/skills/wordpress-plugin-core--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add secondsky/claude-skills --skill wordpress-plugin-core -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install secondsky/claude-skills wordpress-plugin-core --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/secondsky/claude-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/wordpress-plugin-core/skills/wordpress-plugin-core .gemini/skills/wordpress-plugin-core && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "wordpress-plugin-core" agent skill from https://github.com/secondsky/claude-skills/tree/main/plugins/wordpress-plugin-core/skills/wordpress-plugin-core into .gemini/skills/wordpress-plugin-core/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wordpress-plugin-core", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install secondsky/claude-skills wordpress-plugin-coreInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add secondsky/claude-skills --skill wordpress-plugin-core -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/secondsky/claude-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/wordpress-plugin-core/skills/wordpress-plugin-core .github/skills/wordpress-plugin-core && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "wordpress-plugin-core" agent skill from https://github.com/secondsky/claude-skills/tree/main/plugins/wordpress-plugin-core/skills/wordpress-plugin-core into .github/skills/wordpress-plugin-core/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wordpress-plugin-core", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add secondsky/claude-skills --skill wordpress-plugin-core -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install secondsky/claude-skills wordpress-plugin-core --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/secondsky/claude-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/wordpress-plugin-core/skills/wordpress-plugin-core .opencode/skills/wordpress-plugin-core && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "wordpress-plugin-core" agent skill from https://github.com/secondsky/claude-skills/tree/main/plugins/wordpress-plugin-core/skills/wordpress-plugin-core into .opencode/skills/wordpress-plugin-core/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wordpress-plugin-core", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
wordpress-plugin-coreWordPress plugin development with hooks, security, REST API, custom post types.
Wordpress Plugin Core is an agent skill from secondsky/claude-skills. WordPress plugin development with hooks, security, REST API, custom post types. Use for plugin creation, $wpdb queries, Settings API, or encountering SQL injection, XSS, CSRF, nonce errors.
Its SKILL.md is about 4.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 50 other files, including scripts, reference files and assets (for example `references/advanced-topics.md`, `references/common-hooks.md` and `references/common-patterns.md`).
It sits in Security, covering Web application vulnerabilities. It works with WordPress and PHP. The repository describes itself as: Production-ready skills for Claude Code CLI - Cloudflare, React, Tailwind v4, and AI integrations. The licence is MIT.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 8837836. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 2 files in scripts/ (PHP and Shell, from the files we listed), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
developer.wordpress.orgpatchstack.comblog.nintechnet.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Wordpress Plugin Core loads about 4.6k tokens when it runs, and up to ~33k if it reads all its reference files. Until then it costs about 53 tokens; SKILL.md has 1,592 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from secondsky/claude-skills at commit 8837836, republished under its MIT licence (© secondsky). 1,592 words, ~4,582 tokens.
.claude/skills/wordpress-plugin-core/SKILL.md (or your agent's skills folder). This skill also uses 44 other files; get the full folder from GitHub.Status: Production Ready Last Updated: 2026-08-03 Dependencies: None (WordPress 6.0+, PHP 8.0+) Latest Versions: WordPress 7.0+, PHP 8.3+ recommended
Three architecture patterns available (see references/plugin-architectures.md for detailed examples):
Every plugin MUST have a header comment in the main file:
<?php
/**
* Plugin Name: My Awesome Plugin
* Description: Brief description.
* Version: 1.0.0
* Requires at least: 6.0
* Requires PHP: 8.0
* Text Domain: my-plugin
*/
if ( ! defined( 'ABSPATH' ) ) exit;CRITICAL: Plugin Name is required, Text Domain must match plugin slug exactly.
// 1. Unique Prefix (4-5 chars)
function mypl_init() { /* code */ }
add_action( 'init', 'mypl_init' );
// 2. ABSPATH Check (every file)
if ( ! defined( 'ABSPATH' ) ) exit;
// 3. Nonces for Forms
wp_nonce_field( 'mypl_action', 'mypl_nonce' );
// 4. Sanitize Input, Escape Output
$clean = sanitize_text_field( $_POST['input'] );
echo esc_html( $output );
// 5. Prepared Statements
$wpdb->get_results( $wpdb->prepare( "SELECT * FROM {$wpdb->prefix}table WHERE id = %d", $id ) );Rules: 4-5 chars minimum, apply to functions, classes, constants, options, transients, meta keys. Avoid wp_, __, _.
// GOOD
function mypl_init() {}
class MyPL_Settings {}
add_option( 'mypl_option', 'value' );
// BAD - Will conflict
function init() {}
class Settings {}// WRONG
if ( is_admin() ) { /* SECURITY HOLE */ }
// CORRECT
if ( current_user_can( 'manage_options' ) ) { /* Secure */ }Common Capabilities: manage_options (Admin), edit_posts (Editor), publish_posts (Author)
Input → Processing → Output (Sanitize → Validate → Escape):
// SANITIZATION (Input)
$name = sanitize_text_field( $_POST['name'] );
$email = sanitize_email( $_POST['email'] );
$url = esc_url_raw( $_POST['url'] );
$html = wp_kses_post( $_POST['content'] );
// VALIDATION (Logic)
if ( ! is_email( $email ) ) wp_die( 'Invalid email' );
// ESCAPING (Output)
echo esc_html( $name );
echo '<a href="' . esc_url( $url ) . '">' . esc_html( $text ) . '</a>';Rule: Sanitize INPUT, escape OUTPUT. Never trust user data.
One-time tokens proving requests came from your site.
// Form
<form method="post">
<?php wp_nonce_field( 'mypl_action', 'mypl_nonce' ); ?>
<input type="text" name="data" />
</form>
// Verify
if ( ! wp_verify_nonce( $_POST['mypl_nonce'], 'mypl_action' ) ) wp_die( 'Security check failed' );
// AJAX
check_ajax_referer( 'mypl-ajax-nonce', 'nonce' );CRITICAL: Always use $wpdb->prepare() for user input.
// WRONG - SQL Injection
$wpdb->get_results( "SELECT * FROM {$wpdb->prefix}table WHERE id = {$_GET['id']}" );
// CORRECT
$wpdb->get_results( $wpdb->prepare( "SELECT * FROM {$wpdb->prefix}table WHERE id = %d", $_GET['id'] ) );Placeholders: %s (String), %d (Integer), %f (Float)
LIKE Queries: Use $wpdb->esc_like() before adding wildcards:
$search = '%' . $wpdb->esc_like( $term ) . '%';
$wpdb->get_results( $wpdb->prepare( "... WHERE title LIKE %s", $search ) );✅ Use unique prefix (4-5 chars) for all global code (functions, classes, options, transients)
✅ Add ABSPATH check to every PHP file: if ( ! defined( 'ABSPATH' ) ) exit;
✅ Check capabilities (current_user_can()) not just is_admin()
✅ Verify nonces for all forms and AJAX requests
✅ Use $wpdb->prepare() for all database queries with user input
✅ Sanitize input with sanitize_*() functions before saving
✅ Escape output with esc_*() functions before displaying
✅ Flush rewrite rules on activation when registering custom post types
✅ Use uninstall.php for permanent cleanup (not deactivation hook)
✅ Follow WordPress Coding Standards (tabs for indentation, Yoda conditions)
❌ Never use extract() - Creates security vulnerabilities
❌ Never trust $_POST/$_GET without sanitization
❌ Never concatenate user input into SQL - Always use prepare()
❌ Never use is_admin() alone for permission checks
❌ Never output unsanitized data - Always escape
❌ Never use generic function/class names - Always prefix
❌ Never use short PHP tags <? or <?= - Use <?php only
❌ Never delete user data on deactivation - Only on uninstall
❌ Never register uninstall hook repeatedly - Only once on activation
❌ Never use register_uninstall_hook() in main flow - Use uninstall.php instead
This skill prevents 20 documented issues:
Error: Database compromised via unescaped user input
Source: https://patchstack.com/articles/sql-injection/ (15% of all vulnerabilities)
Why It Happens: Direct concatenation of user input into SQL queries
Prevention: Always use $wpdb->prepare() with placeholders
// VULNERABLE
$wpdb->query( "DELETE FROM {$wpdb->prefix}table WHERE id = {$_GET['id']}" );
// SECURE
$wpdb->query( $wpdb->prepare( "DELETE FROM {$wpdb->prefix}table WHERE id = %d", $_GET['id'] ) );Error: Malicious JavaScript executed in user browsers Source: https://patchstack.com (35% of all vulnerabilities) Why It Happens: Outputting unsanitized user data to HTML Prevention: Always escape output with context-appropriate function
// VULNERABLE
echo $_POST['name'];
echo '<div class="' . $_POST['class'] . '">';
// SECURE
echo esc_html( $_POST['name'] );
echo '<div class="' . esc_attr( $_POST['class'] ) . '">';Error: Unauthorized actions performed on behalf of users
Source: https://blog.nintechnet.com/25-wordpress-plugins-vulnerable-to-csrf-attacks/
Why It Happens: No verification that requests originated from your site
Prevention: Use nonces with wp_nonce_field() and wp_verify_nonce()
// VULNERABLE
if ( $_POST['action'] == 'delete' ) {
delete_user( $_POST['user_id'] );
}
// SECURE
if ( ! wp_verify_nonce( $_POST['nonce'], 'mypl_delete_user' ) ) {
wp_die( 'Security check failed' );
}
delete_user( absint( $_POST['user_id'] ) );Error: Regular users can access admin functions
Source: WordPress Security Review Guidelines
Why It Happens: Using is_admin() instead of current_user_can()
Prevention: Always check capabilities, not just admin context
// VULNERABLE
if ( is_admin() ) {
// Any logged-in user can trigger this
}
// SECURE
if ( current_user_can( 'manage_options' ) ) {
// Only administrators can trigger this
}Error: PHP files executed outside WordPress context Source: WordPress Plugin Handbook Why It Happens: No ABSPATH check at top of file Prevention: Add ABSPATH check to every PHP file
// Add to top of EVERY PHP file
if ( ! defined( 'ABSPATH' ) ) {
exit;
}For comprehensive error coverage beyond the Top 5, load references/error-catalog.md which includes:
Each issue includes: error description, source, why it happens, prevention code, impact severity, and frequency.
Choose the right architecture for your plugin size and complexity:
Simple (Functions Only)
OOP (Singleton Pattern)
PSR-4 (Namespaced + Composer)
For full implementation examples with directory structure, activation hooks, and code patterns, load references/plugin-architectures.md.
This skill provides production-ready patterns for 8 common WordPress plugin features:
For complete implementation code, load references/common-patterns.md when implementing any of these features. Each pattern includes:
Plugins hosted outside WordPress.org can provide automatic updates using Plugin Update Checker by YahnisElsts (recommended).
Quick Solutions:
For complete implementation, load references/github-auto-updates.md which includes:
Required:
Optional:
Fatal Errors: Enable WP_DEBUG, check wp-content/debug.log, verify prefixed names
404 on CPTs: Flush rewrite rules (add flush_rewrite_rules(); temporarily in wp-admin)
Nonce Failures: Check matching names, correct action, 24-hour expiration
AJAX Returns 0/-1: Verify action name matches wp_ajax_{action}, nonce sent/verified, handler hooked
HTML Stripped: Use wp_kses_post() instead of sanitize_text_field()
DB Queries Fail: Always use $wpdb->prepare(), include $wpdb->prefix, verify syntax
This skill uses progressive disclosure - main file contains essentials, reference files have detailed implementation. Load references based on your current task:
references/common-patterns.md (465 lines)Load when: Implementing specific WordPress features Contains:
references/plugin-architectures.md (220 lines)Load when: Choosing plugin structure or migrating between patterns Contains:
references/error-catalog.md (Issues #6-20, 573 lines)Load when: Debugging issues beyond Top 5 security vulnerabilities Contains:
references/advanced-topics.md (150 lines)Load when: Implementing i18n, WP-CLI, cron jobs, or dependency checking Contains:
references/security-checklist.md (527 lines)Load when: Performing security audit or reviewing code for vulnerabilities Contains:
references/github-auto-updates.md (1,224 lines)Load when: Setting up auto-updates for plugins hosted outside WordPress.org Contains:
references/common-hooks.md (234 lines)Load when: Working with WordPress hooks and need hook reference Contains:
Use this checklist to verify your plugin:
Questions? Issues?
references/error-catalog.md for additional issues #6-20© secondsky, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 44 other files (scripts, references, assets) in plugins/wordpress-plugin-core/skills/wordpress-plugin-core of secondsky/claude-skills.
Open the folder on GitHubat commit 8837836
Wordpress Plugin Core next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Wordpress Plugin Core this skillsecondsky/claude-skills | 227 | — | ~4.6k | Automated safety check: Pass | MIT | |
| Php Wordpress Audit0xShe/PHP-Code-Audit-Skill | 402 | 1 repos | ~666 | Automated safety check: Pass | None | |
| Wp Security Reviewjorgerosal/wordpress-skills | 101 | — | ~6.4k | Automated safety check: Pass | MIT | |
| Auditing Php Applicationstrilwu/secskills | 156 | — | ~2.8k | Automated safety check: Pass | MIT | |
| Php Framework Auditwgpsec/AboutSecurity | 1.8k | — | ~767 | Automated safety check: Notes | None | |
| Code Audit3stoneBrother/code-audit | 893 | 1 repos | ~2.7k | Automated safety check: Pass | None |
0xShe/PHP-Code-Audit-Skill
WordPress 框架特效安全审计工具。针对 WordPress 常见 nonce/capability/checkadminreferer、AJAX action、escape/sanitize、重定向、安全上传与远程请求等机制进行白盒静态审计,并映射到通用漏洞类型体系(AUTH/CSRF/XSS/SQL/CFG/SSRF 等)。
jorgerosal/wordpress-skills
WordPress security code review and vulnerability detection. An agent skill from jorgerosal/wordpress-skills.
trilwu/secskills
Audit PHP web application source for critical vulnerabilities using PHP's specific sink and footgun catalog — object injection via unserialize and phar:// POP chains, type-juggling and magic-hash…
wgpsec/AboutSecurity
PHP 框架特定安全审计。当在 PHP 白盒审计中已识别目标使用特定框架、 需要检查框架特有安全机制和常见配置缺陷时触发。
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
0xShe/PHP-Code-Audit-Skill
CodeIgniter 框架特效安全审计工具。针对 CodeIgniter 的 CSRF、XSS 输出过滤、数据库查询构造、路由与验证器配置、会话 Cookie 安全等机制进行白盒静态审计,并映射到通用漏洞类型体系(CSRF/AUTH/XSS/SQL/CFG/SESS 等)。
secondsky/claude-skills
TanStack AI (alpha) provider-agnostic type-safe chat with streaming for OpenAI, Anthropic, Gemini, Ollama.
secondsky/claude-skills
AutoAnimate (@formkit/auto-animate) zero-config animations for React.
secondsky/claude-skills
MUI Base UI unstyled React components with Floating UI. An agent skill from secondsky/claude-skills.
secondsky/claude-skills
This skill should be used when the user asks to "upload images to Cloudflare", "implement direct creator upload", "configure image transformations", "optimize WebP/AVIF", "create image variants"…
secondsky/claude-skills
Deploy Next.js to Cloudflare Workers via the OpenNext adapter (@opennextjs/cloudflare).
secondsky/claude-skills
Cloudflare Sandboxes SDK for secure code execution in Linux containers at edge.
Categories
WordPress plugin development with hooks, security, REST API, custom post types. Wordpress Plugin Core is an agent skill from secondsky/claude-skills. WordPress plugin development with hooks, security, REST API, custom post types.
Wordpress Plugin Core fits situations like: plugin creation; encountering SQL injection.
Run `npx skills add secondsky/claude-skills --skill wordpress-plugin-core -a claude-code`. Or copy the skill folder (plugins/wordpress-plugin-core/skills/wordpress-plugin-core in secondsky/claude-skills) into .claude/skills/wordpress-plugin-core in your project. Claude Code loads it when a task matches its description.
Run `npx skills add secondsky/claude-skills --skill wordpress-plugin-core -a codex`. Or copy the skill folder (plugins/wordpress-plugin-core/skills/wordpress-plugin-core in secondsky/claude-skills) into .agents/skills/wordpress-plugin-core in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add secondsky/claude-skills --skill wordpress-plugin-core -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/wordpress-plugin-core, .gemini/skills/wordpress-plugin-core, .github/skills/wordpress-plugin-core and .opencode/skills/wordpress-plugin-core in your project.
Going by SKILL.md and its folder, Wordpress Plugin Core needs PHP and a shell for the scripts in its folder. Our summary lists: A Bash shell.
SKILL.md names 3 domains. As links in the text: developer.wordpress.org, patchstack.com and blog.nintechnet.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Wordpress Plugin Core is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.6k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 29k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Wordpress Plugin Core: Php Wordpress Audit (0xShe/PHP-Code-Audit-Skill, 402 stars), Wp Security Review (jorgerosal/wordpress-skills, 101 stars), Auditing Php Applications (trilwu/secskills, 156 stars) and Php Framework Audit (wgpsec/AboutSecurity, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
secondsky (a GitHub user) maintains it in secondsky/claude-skills, which has 227 GitHub stars. The repository holds 169 skills in this directory. The repository was last updated on September 28, 2026.
Source: secondsky/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.