Agent skill

Wordpress Plugin Core

by secondsky in secondsky/claude-skills

WordPress plugin development with hooks, security, REST API, custom post types.

MITAuto-check passedSecurity

Install Wordpress Plugin Core

skills CLI
$ npx skills add secondsky/claude-skills --skill wordpress-plugin-core -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install secondsky/claude-skills wordpress-plugin-core --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/secondsky/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/wordpress-plugin-core/skills/wordpress-plugin-core .claude/skills/wordpress-plugin-core && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
wordpress-plugin-core
GitHub stars
227
Token cost
~4.6k tokens
SKILL.md length
1,592 words
Files
45 (incl. scripts, references, assets)
Skills in repo
169
Repo updated
First seen
Licence
MIT

At a glance

WordPress plugin development with hooks, security, REST API, custom post types.

  • Works in 8 steps: Choose Plugin Structure → Create Plugin Header → Security Foundation (5 Essentials) → …
  • Plugin creation
  • SKILL.md covers Quick Start (10 Minutes), The 5-Step Security Foundation, Critical Rules and Known Issues Prevention, plus 7 more sections
  • Runs PHP and Shell scripts from its folder

What it does

Wordpress Plugin Core is an agent skill from secondsky/claude-skills. WordPress plugin development with hooks, security, REST API, custom post types. Use for plugin creation, $wpdb queries, Settings API, or encountering SQL injection, XSS, CSRF, nonce errors.

Its SKILL.md is about 4.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 50 other files, including scripts, reference files and assets (for example `references/advanced-topics.md`, `references/common-hooks.md` and `references/common-patterns.md`).

It sits in Security, covering Web application vulnerabilities. It works with WordPress and PHP. The repository describes itself as: Production-ready skills for Claude Code CLI - Cloudflare, React, Tailwind v4, and AI integrations. The licence is MIT.

When your agent uses it

  • Plugin creation
  • Encountering SQL injection

Example prompts

  • “/wordpress-plugin-core”

Requirements

  • A Bash shell

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Choose Plugin Structure
  2. Create Plugin Header
  3. Security Foundation (5 Essentials)
  4. Use Unique Prefix for Everything
  5. Check Capabilities, Not Admin Status
  6. The Security Trinity
  7. Nonces (CSRF Protection)
  8. Prepared Statements for Database

What it can do on your machine

Read from SKILL.md and the folder at commit 8837836. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (PHP and Shell, from the files we listed), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • developer.wordpress.org
    • patchstack.com
    • blog.nintechnet.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Wordpress Plugin Core loads about 4.6k tokens when it runs, and up to ~33k if it reads all its reference files. Until then it costs about 53 tokens; SKILL.md has 1,592 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~4.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~33k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from secondsky/claude-skills at commit 8837836, republished under its MIT licence (© secondsky). 1,592 words, ~4,582 tokens.

Download SKILL.mdSave it as .claude/skills/wordpress-plugin-core/SKILL.md (or your agent's skills folder). This skill also uses 44 other files; get the full folder from GitHub.
name
wordpress-plugin-core
description
WordPress plugin development with hooks, security, REST API, custom post types. Use for plugin creation, $wpdb queries, Settings API, or encountering SQL injection, XSS, CSRF, nonce errors.
metadata.keywords
wordpress plugin development, wordpress security, wordpress hooks, wordpress filters, wordpress database, wpdb prepare, sanitize_text_field, esc_html…
license
MIT

WordPress Plugin Development (Core)

Status: Production Ready Last Updated: 2026-08-03 Dependencies: None (WordPress 6.0+, PHP 8.0+) Latest Versions: WordPress 7.0+, PHP 8.3+ recommended


Quick Start (10 Minutes)

1. Choose Plugin Structure

Three architecture patterns available (see references/plugin-architectures.md for detailed examples):

  • Simple (functions only) - Small plugins <5 functions
  • OOP - Medium plugins with related functionality
  • PSR-4 (Namespaced + Composer) - Modern standard (2025), most maintainable
2. Create Plugin Header

Every plugin MUST have a header comment in the main file:

php
<?php
/**
 * Plugin Name:       My Awesome Plugin
 * Description:       Brief description.
 * Version:           1.0.0
 * Requires at least: 6.0
 * Requires PHP:      8.0
 * Text Domain:       my-plugin
 */

if ( ! defined( 'ABSPATH' ) ) exit;

CRITICAL: Plugin Name is required, Text Domain must match plugin slug exactly.

3. Security Foundation (5 Essentials)
php
// 1. Unique Prefix (4-5 chars)
function mypl_init() { /* code */ }
add_action( 'init', 'mypl_init' );

// 2. ABSPATH Check (every file)
if ( ! defined( 'ABSPATH' ) ) exit;

// 3. Nonces for Forms
wp_nonce_field( 'mypl_action', 'mypl_nonce' );

// 4. Sanitize Input, Escape Output
$clean = sanitize_text_field( $_POST['input'] );
echo esc_html( $output );

// 5. Prepared Statements
$wpdb->get_results( $wpdb->prepare( "SELECT * FROM {$wpdb->prefix}table WHERE id = %d", $id ) );

The 5-Step Security Foundation

Step 1: Use Unique Prefix for Everything

Rules: 4-5 chars minimum, apply to functions, classes, constants, options, transients, meta keys. Avoid wp_, __, _.

php
// GOOD
function mypl_init() {}
class MyPL_Settings {}
add_option( 'mypl_option', 'value' );

// BAD - Will conflict
function init() {}
class Settings {}
Step 2: Check Capabilities, Not Admin Status
php
// WRONG
if ( is_admin() ) { /* SECURITY HOLE */ }

// CORRECT
if ( current_user_can( 'manage_options' ) ) { /* Secure */ }

Common Capabilities: manage_options (Admin), edit_posts (Editor), publish_posts (Author)

Step 3: The Security Trinity

Input → Processing → Output (Sanitize → Validate → Escape):

php
// SANITIZATION (Input)
$name = sanitize_text_field( $_POST['name'] );
$email = sanitize_email( $_POST['email'] );
$url = esc_url_raw( $_POST['url'] );
$html = wp_kses_post( $_POST['content'] );

// VALIDATION (Logic)
if ( ! is_email( $email ) ) wp_die( 'Invalid email' );

// ESCAPING (Output)
echo esc_html( $name );
echo '<a href="' . esc_url( $url ) . '">' . esc_html( $text ) . '</a>';

Rule: Sanitize INPUT, escape OUTPUT. Never trust user data.

Step 4: Nonces (CSRF Protection)

One-time tokens proving requests came from your site.

php
// Form
<form method="post">
    <?php wp_nonce_field( 'mypl_action', 'mypl_nonce' ); ?>
    <input type="text" name="data" />
</form>

// Verify
if ( ! wp_verify_nonce( $_POST['mypl_nonce'], 'mypl_action' ) ) wp_die( 'Security check failed' );

// AJAX
check_ajax_referer( 'mypl-ajax-nonce', 'nonce' );
Step 5: Prepared Statements for Database

CRITICAL: Always use $wpdb->prepare() for user input.

php
// WRONG - SQL Injection
$wpdb->get_results( "SELECT * FROM {$wpdb->prefix}table WHERE id = {$_GET['id']}" );

// CORRECT
$wpdb->get_results( $wpdb->prepare( "SELECT * FROM {$wpdb->prefix}table WHERE id = %d", $_GET['id'] ) );

Placeholders: %s (String), %d (Integer), %f (Float)

LIKE Queries: Use $wpdb->esc_like() before adding wildcards:

php
$search = '%' . $wpdb->esc_like( $term ) . '%';
$wpdb->get_results( $wpdb->prepare( "... WHERE title LIKE %s", $search ) );

Critical Rules

Always Do

✅ Use unique prefix (4-5 chars) for all global code (functions, classes, options, transients) ✅ Add ABSPATH check to every PHP file: if ( ! defined( 'ABSPATH' ) ) exit; ✅ Check capabilities (current_user_can()) not just is_admin() ✅ Verify nonces for all forms and AJAX requests ✅ Use $wpdb->prepare() for all database queries with user input ✅ Sanitize input with sanitize_*() functions before saving ✅ Escape output with esc_*() functions before displaying ✅ Flush rewrite rules on activation when registering custom post types ✅ Use uninstall.php for permanent cleanup (not deactivation hook) ✅ Follow WordPress Coding Standards (tabs for indentation, Yoda conditions)

Never Do

❌ Never use extract() - Creates security vulnerabilities ❌ Never trust $_POST/$_GET without sanitization ❌ Never concatenate user input into SQL - Always use prepare() ❌ Never use is_admin() alone for permission checks ❌ Never output unsanitized data - Always escape ❌ Never use generic function/class names - Always prefix ❌ Never use short PHP tags <? or <?= - Use <?php only ❌ Never delete user data on deactivation - Only on uninstall ❌ Never register uninstall hook repeatedly - Only once on activation ❌ Never use register_uninstall_hook() in main flow - Use uninstall.php instead


Known Issues Prevention

This skill prevents 20 documented issues:

Issue #1: SQL Injection

Error: Database compromised via unescaped user input Source: https://patchstack.com/articles/sql-injection/ (15% of all vulnerabilities) Why It Happens: Direct concatenation of user input into SQL queries Prevention: Always use $wpdb->prepare() with placeholders

php
// VULNERABLE
$wpdb->query( "DELETE FROM {$wpdb->prefix}table WHERE id = {$_GET['id']}" );

// SECURE
$wpdb->query( $wpdb->prepare( "DELETE FROM {$wpdb->prefix}table WHERE id = %d", $_GET['id'] ) );
Issue #2: XSS (Cross-Site Scripting)

Error: Malicious JavaScript executed in user browsers Source: https://patchstack.com (35% of all vulnerabilities) Why It Happens: Outputting unsanitized user data to HTML Prevention: Always escape output with context-appropriate function

php
// VULNERABLE
echo $_POST['name'];
echo '<div class="' . $_POST['class'] . '">';

// SECURE
echo esc_html( $_POST['name'] );
echo '<div class="' . esc_attr( $_POST['class'] ) . '">';
Issue #3: CSRF (Cross-Site Request Forgery)

Error: Unauthorized actions performed on behalf of users Source: https://blog.nintechnet.com/25-wordpress-plugins-vulnerable-to-csrf-attacks/ Why It Happens: No verification that requests originated from your site Prevention: Use nonces with wp_nonce_field() and wp_verify_nonce()

php
// VULNERABLE
if ( $_POST['action'] == 'delete' ) {
    delete_user( $_POST['user_id'] );
}

// SECURE
if ( ! wp_verify_nonce( $_POST['nonce'], 'mypl_delete_user' ) ) {
    wp_die( 'Security check failed' );
}
delete_user( absint( $_POST['user_id'] ) );
Issue #4: Missing Capability Checks

Error: Regular users can access admin functions Source: WordPress Security Review Guidelines Why It Happens: Using is_admin() instead of current_user_can() Prevention: Always check capabilities, not just admin context

php
// VULNERABLE
if ( is_admin() ) {
    // Any logged-in user can trigger this
}

// SECURE
if ( current_user_can( 'manage_options' ) ) {
    // Only administrators can trigger this
}
Issue #5: Direct File Access

Error: PHP files executed outside WordPress context Source: WordPress Plugin Handbook Why It Happens: No ABSPATH check at top of file Prevention: Add ABSPATH check to every PHP file

php
// Add to top of EVERY PHP file
if ( ! defined( 'ABSPATH' ) ) {
    exit;
}
Additional Issues (#6-20)

For comprehensive error coverage beyond the Top 5, load references/error-catalog.md which includes:

  • Functionality: Prefix collision, rewrite rules not flushed, deprecated functions, text domain mismatch, plugin dependencies, autosave triggers
  • Performance: Scripts loaded everywhere, transients not cleaned, admin-ajax.php performance
  • Security: Missing sanitization on save, incorrect LIKE queries, using extract(), missing REST API permission callbacks, uninstall hook issues
  • Data Integrity: Data deleted on deactivation

Each issue includes: error description, source, why it happens, prevention code, impact severity, and frequency.


Plugin Architecture Patterns

Choose the right architecture for your plugin size and complexity:

Decision Guide

Simple (Functions Only)

  • When: Small plugins (<5 functions), single feature
  • Pros: Easy to start, minimal boilerplate
  • Cons: Doesn't scale, hard to organize beyond ~5 functions
  • Example: Simple shortcode plugin, basic widget

OOP (Singleton Pattern)

  • When: Medium plugins (5-20 functions), related functionality
  • Pros: Better organization, encapsulation, testable
  • Cons: More boilerplate than simple, not using modern PHP features
  • Example: Custom post type plugin, admin settings page

PSR-4 (Namespaced + Composer)

  • When: Large/modern plugins, team development, 2025+ standard
  • Pros: Modern PHP, namespaces, autoloading, best practices
  • Cons: Requires Composer, more initial setup
  • Example: E-commerce extension, multi-feature plugin
Complete Examples

For full implementation examples with directory structure, activation hooks, and code patterns, load references/plugin-architectures.md.


Common Implementation Patterns

This skill provides production-ready patterns for 8 common WordPress plugin features:

  1. Custom Post Types - Register CPTs with Gutenberg support, flush rewrite rules
  2. Custom Taxonomies - Hierarchical (categories) or flat (tags) taxonomies
  3. Meta Boxes - Save custom fields with proper security (nonces, capabilities, autosave checks)
  4. Settings API - WordPress-native settings pages with sanitization
  5. REST API Endpoints - Modern API endpoints with permission callbacks and validation
  6. AJAX Handlers - Legacy admin-ajax.php pattern (use REST API for new projects)
  7. Custom Database Tables - Create tables with dbDelta, versioning
  8. Transients for Caching - Cache expensive operations, clear on updates

For complete implementation code, load references/common-patterns.md when implementing any of these features. Each pattern includes:

  • Full working code examples
  • Security requirements checklist
  • Common mistakes to avoid
  • Best practices and performance tips


Distribution & Auto-Updates

Plugins hosted outside WordPress.org can provide automatic updates using Plugin Update Checker by YahnisElsts (recommended).

Quick Solutions:

  • Public Repos: Plugin Update Checker (GitHub/GitLab/BitBucket)
  • Private Plugins: Plugin Update Checker + authentication token
  • Commercial Plugins: Freemius or Custom Update Server
  • No Coding: Git Updater plugin

For complete implementation, load references/github-auto-updates.md which includes:

  • Plugin Update Checker setup (5 minutes)
  • GitHub Releases workflow
  • Private repository authentication
  • Security best practices (checksums, tokens, rate limiting)
  • Alternative solutions comparison
  • ZIP structure requirements

Show full SKILL.md (642 more words)Show less

Dependencies

Required:

  • WordPress 6.0+ (recommend 7.0+)
  • PHP 8.0+ (recommend 8.3+)

Optional:

  • Composer 2.0+ - For PSR-4 autoloading
  • WP-CLI 2.0+ - For command-line plugin management
  • Query Monitor - For debugging and performance analysis

Official Documentation


Troubleshooting

Fatal Errors: Enable WP_DEBUG, check wp-content/debug.log, verify prefixed names

404 on CPTs: Flush rewrite rules (add flush_rewrite_rules(); temporarily in wp-admin)

Nonce Failures: Check matching names, correct action, 24-hour expiration

AJAX Returns 0/-1: Verify action name matches wp_ajax_{action}, nonce sent/verified, handler hooked

HTML Stripped: Use wp_kses_post() instead of sanitize_text_field()

DB Queries Fail: Always use $wpdb->prepare(), include $wpdb->prefix, verify syntax


When to Load References

This skill uses progressive disclosure - main file contains essentials, reference files have detailed implementation. Load references based on your current task:

references/common-patterns.md (465 lines)

Load when: Implementing specific WordPress features Contains:

  • Custom Post Types (registration, Gutenberg support, rewrite rules)
  • Custom Taxonomies (hierarchical vs flat, REST API)
  • Meta Boxes (security requirements, save hooks, autosave checks)
  • Settings API (register_setting, sections, fields hierarchy)
  • REST API Endpoints (permission callbacks, validation, responses)
  • AJAX Handlers (nonce verification, wp_ajax hooks, JavaScript integration)
  • Custom Database Tables (dbDelta, character encoding, versioning)
  • Transients for Caching (cache patterns, invalidation, expiration)
references/plugin-architectures.md (220 lines)

Load when: Choosing plugin structure or migrating between patterns Contains:

  • Simple Pattern (functions only, <5 functions)
  • OOP Pattern (singleton, encapsulation, medium plugins)
  • PSR-4 Pattern (namespaces, Composer autoloading, modern standard)
  • Decision tree for pattern selection
  • Complete directory structures with all files
  • Activation/deactivation hook examples
  • Migration paths between patterns
references/error-catalog.md (Issues #6-20, 573 lines)

Load when: Debugging issues beyond Top 5 security vulnerabilities Contains:

  • Functionality issues (prefix collision, rewrite rules, deprecated functions, text domains, dependencies, autosave)
  • Performance issues (scripts everywhere, transients cleanup, admin-ajax.php alternatives)
  • Security issues (sanitization, extract(), REST permissions, uninstall hooks)
  • Data integrity issues (deactivation vs uninstall) Each issue includes: Error description, source/reference, why it happens, prevention code, impact severity, frequency
references/advanced-topics.md (150 lines)

Load when: Implementing i18n, WP-CLI, cron jobs, or dependency checking Contains:

  • Internationalization (i18n) - load_plugin_textdomain(), translation workflow, .pot/.po/.mo files
  • WP-CLI Commands - custom command creation, progress bars, output functions
  • Scheduled Events (Cron) - wp_schedule_event(), custom schedules, activation hooks
  • Plugin Dependencies Check - version requirements, soft dependencies, user-friendly error messages
references/security-checklist.md (527 lines)

Load when: Performing security audit or reviewing code for vulnerabilities Contains:

  • Complete security audit checklist
  • OWASP Top 10 for WordPress
  • Code examples for each vulnerability type
  • Testing procedures and tools
  • Security plugin recommendations
references/github-auto-updates.md (1,224 lines)

Load when: Setting up auto-updates for plugins hosted outside WordPress.org Contains:

  • Plugin Update Checker (recommended) - 5-minute setup
  • GitHub Releases workflow and automation
  • Private repository authentication (tokens, wp-config.php)
  • Alternative solutions (Git Updater, Custom Server, Freemius)
  • Security best practices (checksums, signing, rate limiting)
  • ZIP structure requirements and common mistakes
  • Deployment automation examples
references/common-hooks.md (234 lines)

Load when: Working with WordPress hooks and need hook reference Contains:

  • Action hooks reference (init, admin_menu, save_post, etc.)
  • Filter hooks reference (the_content, post_type_args, etc.)
  • Hook priority and execution order
  • Common hook combinations and patterns

Complete Setup Checklist

Use this checklist to verify your plugin:

  • Plugin header complete with all fields
  • ABSPATH check at top of every PHP file
  • All functions/classes use unique prefix
  • All forms have nonce verification
  • All user input is sanitized
  • All output is escaped
  • All database queries use $wpdb->prepare()
  • Capability checks (not just is_admin())
  • Custom post types flush rewrite rules on activation
  • Deactivation hook only clears temporary data
  • uninstall.php handles permanent cleanup
  • Text domain matches plugin slug
  • Scripts/styles only load where needed
  • WP_DEBUG enabled during development
  • Tested with Query Monitor for performance
  • No deprecated function warnings
  • Works with latest WordPress version

Questions? Issues?

  1. Check references/error-catalog.md for additional issues #6-20
  2. Verify all steps in the security foundation
  3. Check official docs: https://developer.wordpress.org/plugins/
  4. Enable WP_DEBUG and check debug.log
  5. Use Query Monitor plugin to debug hooks and queries

© secondsky, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 44 other files (scripts, references, assets) in plugins/wordpress-plugin-core/skills/wordpress-plugin-core of secondsky/claude-skills.

  • SKILL.md
  • assets/example-template.txt
  • examples/github-updater.php
  • references/advanced-topics.md
  • references/common-hooks.md
  • references/common-patterns.md
  • references/error-catalog.md
  • references/example-reference.md
  • references/github-auto-updates.md
  • references/plugin-architectures.md
  • references/security-checklist.md
  • scripts/example-script.sh
  • scripts/scaffold-plugin.sh
  • templates/examples/ajax-handler.php
  • templates/examples/custom-post-type.php
  • … and 30 more

Open the folder on GitHubat commit 8837836

Compare with similar skills

Wordpress Plugin Core next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Wordpress Plugin Core compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Wordpress Plugin Core this skillsecondsky/claude-skills227—~4.6kAutomated safety check: PassMIT
Php Wordpress Audit0xShe/PHP-Code-Audit-Skill4021 repos~666Automated safety check: PassNone
Wp Security Reviewjorgerosal/wordpress-skills101—~6.4kAutomated safety check: PassMIT
Auditing Php Applicationstrilwu/secskills156—~2.8kAutomated safety check: PassMIT
Php Framework Auditwgpsec/AboutSecurity1.8k—~767Automated safety check: NotesNone
Code Audit3stoneBrother/code-audit8931 repos~2.7kAutomated safety check: PassNone

Similar skills

  • Php Wordpress Audit

    0xShe/PHP-Code-Audit-Skill

    WordPress 框架特效安全审计工具。针对 WordPress 常见 nonce/capability/checkadminreferer、AJAX action、escape/sanitize、重定向、安全上传与远程请求等机制进行白盒静态审计,并映射到通用漏洞类型体系(AUTH/CSRF/XSS/SQL/CFG/SSRF 等)。

    402 GitHub starsUsed in 1 repo~666 tokens
    SecurityAuto-check passed
  • Wp Security Review

    jorgerosal/wordpress-skills

    WordPress security code review and vulnerability detection. An agent skill from jorgerosal/wordpress-skills.

    101 GitHub stars~6.4k tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Audit PHP web application source for critical vulnerabilities using PHP's specific sink and footgun catalog — object injection via unserialize and phar:// POP chains, type-juggling and magic-hash…

    156 GitHub stars~2.8k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Php Framework Audit

    wgpsec/AboutSecurity

    PHP 框架特定安全审计。当在 PHP 白盒审计中已识别目标使用特定框架、 需要检查框架特有安全机制和常见配置缺陷时触发。

    1.8k GitHub stars~767 tokensUpdated 5 days ago
    Backend & APIsAuto-check: notes
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    893 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Php Codeigniter Audit

    0xShe/PHP-Code-Audit-Skill

    CodeIgniter 框架特效安全审计工具。针对 CodeIgniter 的 CSRF、XSS 输出过滤、数据库查询构造、路由与验证器配置、会话 Cookie 安全等机制进行白盒静态审计,并映射到通用漏洞类型体系(CSRF/AUTH/XSS/SQL/CFG/SESS 等)。

    402 GitHub starsUsed in 1 repo~477 tokens
    SecurityAuto-check passed

More from secondsky/claude-skills

All 169 skills in this repo
  • Tanstack AI

    secondsky/claude-skills

    TanStack AI (alpha) provider-agnostic type-safe chat with streaming for OpenAI, Anthropic, Gemini, Ollama.

    227 GitHub starsUsed in 1 repo~3.6k tokens
    Auto-check: notes
  • Auto Animate

    secondsky/claude-skills

    AutoAnimate (@formkit/auto-animate) zero-config animations for React.

    227 GitHub stars~2.9k tokensUpdated 10 days ago
    Auto-check passed
  • Base UI React

    secondsky/claude-skills

    MUI Base UI unstyled React components with Floating UI. An agent skill from secondsky/claude-skills.

    227 GitHub stars~1.9k tokensUpdated 10 days ago
    Auto-check passed
  • Cloudflare Images

    secondsky/claude-skills

    This skill should be used when the user asks to "upload images to Cloudflare", "implement direct creator upload", "configure image transformations", "optimize WebP/AVIF", "create image variants"…

    227 GitHub stars~3.6k tokensUpdated 10 days ago
    Auto-check: notes
  • Cloudflare Nextjs

    secondsky/claude-skills

    Deploy Next.js to Cloudflare Workers via the OpenNext adapter (@opennextjs/cloudflare).

    227 GitHub stars~5.3k tokensUpdated 10 days ago
    Auto-check: notes
  • Cloudflare Sandbox

    secondsky/claude-skills

    Cloudflare Sandboxes SDK for secure code execution in Linux containers at edge.

    227 GitHub stars~4.5k tokensUpdated 10 days ago
    Auto-check passed

Works with

Categories

Questions about Wordpress Plugin Core

What does Wordpress Plugin Core do?

WordPress plugin development with hooks, security, REST API, custom post types. Wordpress Plugin Core is an agent skill from secondsky/claude-skills. WordPress plugin development with hooks, security, REST API, custom post types.

When should I use Wordpress Plugin Core?

Wordpress Plugin Core fits situations like: plugin creation; encountering SQL injection.

How do I install Wordpress Plugin Core in Claude Code?

Run `npx skills add secondsky/claude-skills --skill wordpress-plugin-core -a claude-code`. Or copy the skill folder (plugins/wordpress-plugin-core/skills/wordpress-plugin-core in secondsky/claude-skills) into .claude/skills/wordpress-plugin-core in your project. Claude Code loads it when a task matches its description.

How do I install Wordpress Plugin Core in Codex?

Run `npx skills add secondsky/claude-skills --skill wordpress-plugin-core -a codex`. Or copy the skill folder (plugins/wordpress-plugin-core/skills/wordpress-plugin-core in secondsky/claude-skills) into .agents/skills/wordpress-plugin-core in your project. Codex loads it when a task matches its description.

Can I use Wordpress Plugin Core in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add secondsky/claude-skills --skill wordpress-plugin-core -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/wordpress-plugin-core, .gemini/skills/wordpress-plugin-core, .github/skills/wordpress-plugin-core and .opencode/skills/wordpress-plugin-core in your project.

What does Wordpress Plugin Core need to run?

Going by SKILL.md and its folder, Wordpress Plugin Core needs PHP and a shell for the scripts in its folder. Our summary lists: A Bash shell.

Does Wordpress Plugin Core access the network?

SKILL.md names 3 domains. As links in the text: developer.wordpress.org, patchstack.com and blog.nintechnet.com. This is read from the text; nothing was executed.

Is Wordpress Plugin Core safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Wordpress Plugin Core use?

Wordpress Plugin Core is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Wordpress Plugin Core use?

About 4.6k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 29k tokens, read only when the agent opens those files.

What are the alternatives to Wordpress Plugin Core?

Skills that share tags, products or a category with Wordpress Plugin Core: Php Wordpress Audit (0xShe/PHP-Code-Audit-Skill, 402 stars), Wp Security Review (jorgerosal/wordpress-skills, 101 stars), Auditing Php Applications (trilwu/secskills, 156 stars) and Php Framework Audit (wgpsec/AboutSecurity, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Wordpress Plugin Core?

secondsky (a GitHub user) maintains it in secondsky/claude-skills, which has 227 GitHub stars. The repository holds 169 skills in this directory. The repository was last updated on September 28, 2026.

Source: secondsky/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.