WordPress Server Skill
Production-grade WordPress server configuration — performance, security, caching, and multisite.
RULE: Show all config changes before applying. Backup reminder before any PHP/Nginx change.
🚧 Status: Stub — implementation pending
This reference skill has the structure but the snippet content is still being filled in
(you'll see <!-- TODO --> placeholders below). It activates and tells Claude the topic
exists, but won't yield deep snippets yet.
Want to help? Pick any TODO, write the snippet, open a PR. See CONTRIBUTING.md.
Each contribution moves the skill closer to "Ready" status.
Capabilities
Nginx + WordPress Config
PHP 8.3-FPM Optimization
Redis Object Caching
WP Rocket Configuration
Security Hardening
Staging Environment Setup
Multisite Setup
Key wp-config.php Constants
// Performance
define( 'WP_CACHE', true );
define( 'WP_MEMORY_LIMIT', '256M' );
define( 'WP_MAX_MEMORY_LIMIT', '512M' );
// Security
define( 'DISALLOW_FILE_EDIT', true );
define( 'DISALLOW_FILE_MODS', true ); // disable plugin/theme install
define( 'FORCE_SSL_ADMIN', true );
// Redis Object Cache
define( 'WP_REDIS_HOST', '127.0.0.1' );
define( 'WP_REDIS_PORT', 6379 );
define( 'WP_REDIS_DATABASE', 0 );
define( 'WP_REDIS_PREFIX', '[site-key]:' );
// Debug (disable in production)
define( 'WP_DEBUG', false );
define( 'WP_DEBUG_LOG', false );
define( 'SCRIPT_DEBUG', false );
Redis config for WordPress
# /etc/redis/redis.conf additions
maxmemory 256mb
maxmemory-policy allkeys-lru
save "" # disable RDB persistence for cache-only use
appendonly no
1---2name: wordpress-server3description: WordPress server optimization — Nginx config, PHP 8.3-FPM tuning, Redis object caching, WP Rocket, security hardening, staging, multisite4---5
6# WordPress Server Skill
7
8Production-grade WordPress server configuration — performance, security, caching, and multisite.
9
10**RULE: Show all config changes before applying. Backup reminder before any PHP/Nginx change.**
11
12> **🚧 Status: Stub — implementation pending**
13>
14> This reference skill has the structure but the snippet content is still being filled in
15> (you'll see `<!-- TODO -->` placeholders below). It activates and tells Claude the topic
16> exists, but won't yield deep snippets yet.
17>
18> **Want to help?** Pick any TODO, write the snippet, open a PR. See [CONTRIBUTING.md](../../CONTRIBUTING.md).
19> Each contribution moves the skill closer to "Ready" status.
20
21---
22
23## Capabilities
24
25### Nginx + WordPress Config
26<!-- TODO: WordPress-specific Nginx server block (try_files, PHP-FPM socket) -->
27<!-- TODO: Cache headers for WP Rocket / W3TC static files -->
28<!-- TODO: Block xmlrpc.php, block wp-login.php by IP -->
29<!-- TODO: WooCommerce cart/checkout bypass for page cache -->
30
31### PHP 8.3-FPM Optimization
32<!-- TODO: Pool sizing for WordPress (pm = ondemand for low traffic, dynamic for high) -->
33<!-- TODO: opcache.memory_consumption, opcache.max_accelerated_files for WP -->
34<!-- TODO: realpath_cache_size, upload_max_filesize, max_execution_time -->
35<!-- TODO: PHP slow log setup to catch slow plugins -->
36
37### Redis Object Caching
38<!-- TODO: redis-cache plugin setup, wp-config.php constants -->
39<!-- TODO: Redis maxmemory-policy for WP (allkeys-lru) -->
40<!-- TODO: WooCommerce session handler in Redis -->
41<!-- TODO: Cache flushing strategy (selective vs full) -->
42
43### WP Rocket Configuration
44<!-- TODO: Page cache, browser cache, minify CSS/JS settings -->
45<!-- TODO: CDN integration (DO Spaces / CloudFront) -->
46<!-- TODO: WooCommerce-safe cache exclusions -->
47<!-- TODO: Preloading, heartbeat control, LazyLoad -->
48
49### Security Hardening
50<!-- TODO: Disable file editing in WP admin (DISALLOW_FILE_EDIT) -->
51<!-- TODO: Limit login attempts (plugin vs nginx rate limit) -->
52<!-- TODO: wp-config.php above webroot -->
53<!-- TODO: Database prefix change, user enumeration prevention -->
54<!-- TODO: Wordfence / Security plugins vs WAF -->
55
56### Staging Environment Setup
57<!-- TODO: Subdomain staging (staging.domain.com), WP CLI duplication -->
58<!-- TODO: WP Staging plugin vs manual rsync+dump approach -->
59<!-- TODO: Prevent staging from being indexed (robots.txt, noindex) -->
60<!-- TODO: Sync staging → prod workflow -->
61
62### Multisite Setup
63<!-- TODO: Subdomain vs subdirectory multisite config -->
64<!-- TODO: Nginx config for multisite (wildcard subdomains) -->
65<!-- TODO: Network admin, per-site plugins vs network-activated -->
66<!-- TODO: Domain mapping plugin setup -->
67
68---
69
70## Key wp-config.php Constants
71
72```php
73// Performance
74define( 'WP_CACHE', true );
75define( 'WP_MEMORY_LIMIT', '256M' );
76define( 'WP_MAX_MEMORY_LIMIT', '512M' );
77
78// Security
79define( 'DISALLOW_FILE_EDIT', true );
80define( 'DISALLOW_FILE_MODS', true ); // disable plugin/theme install
81define( 'FORCE_SSL_ADMIN', true );
82
83// Redis Object Cache
84define( 'WP_REDIS_HOST', '127.0.0.1' );
85define( 'WP_REDIS_PORT', 6379 );
86define( 'WP_REDIS_DATABASE', 0 );
87define( 'WP_REDIS_PREFIX', '[site-key]:' );
88
89// Debug (disable in production)
90define( 'WP_DEBUG', false );
91define( 'WP_DEBUG_LOG', false );
92define( 'SCRIPT_DEBUG', false );
93```
94
95### Redis config for WordPress
96```conf
97# /etc/redis/redis.conf additions
98maxmemory 256mb
99maxmemory-policy allkeys-lru
100save "" # disable RDB persistence for cache-only use
101appendonly no
102```
103
104<!-- TODO: Add full interactive workflows for each capability above -->