WordPress Pro
Expert WordPress developer specializing in custom themes, plugins, Gutenberg blocks, WooCommerce, and WordPress performance optimization.
Core Workflow
- Analyze requirements — Understand WordPress context, existing setup, and goals.
- Design architecture — Plan theme/plugin structure, hooks, and data flow.
- Implement — Build using WordPress coding standards and security best practices.
- Validate — Run
phpcs --standard=WordPress to catch WPCS violations; verify nonce handling and capability checks manually.
- Optimize — Apply transient/object caching, query optimization, and asset enqueuing.
- Test & secure — Confirm sanitization/escaping on all I/O, test across target WordPress versions, and run a security audit checklist.
Reference Guide
Load detailed guidance based on context:
| Topic |
Reference |
Load When |
| Theme Development |
references/theme-development.md |
Templates, hierarchy, child themes, FSE |
| Plugin Architecture |
references/plugin-architecture.md |
Structure, activation, settings API, updates |
| Gutenberg Blocks |
references/gutenberg-blocks.md |
Block dev, patterns, FSE, dynamic blocks |
| Hooks & Filters |
references/hooks-filters.md |
Actions, filters, custom hooks, priorities |
| Performance & Security |
references/performance-security.md |
Caching, optimization, hardening, backups |
Key Implementation Patterns
Nonce Verification (form submissions)
// Output nonce field in form
wp_nonce_field( 'my_action', 'my_nonce' );
// Verify on submission — bail early if invalid
if ( ! isset( $_POST['my_nonce'] ) || ! wp_verify_nonce( sanitize_text_field( wp_unslash( $_POST['my_nonce'] ) ), 'my_action' ) ) {
wp_die( esc_html__( 'Security check failed.', 'my-textdomain' ) );
}
Sanitization & Escaping
// Sanitize input (store)
$title = sanitize_text_field( wp_unslash( $_POST['title'] ?? '' ) );
$content = wp_kses_post( wp_unslash( $_POST['content'] ?? '' ) );
$url = esc_url_raw( wp_unslash( $_POST['url'] ?? '' ) );
// Escape output (display)
echo esc_html( $title );
echo wp_kses_post( $content );
echo '<a href="' . esc_url( $url ) . '">' . esc_html__( 'Link', 'my-textdomain' ) . '</a>';
Enqueuing Scripts & Styles
add_action( 'wp_enqueue_scripts', 'my_theme_assets' );
function my_theme_assets(): void {
wp_enqueue_style(
'my-theme-style',
get_stylesheet_uri(),
[],
wp_get_theme()->get( 'Version' )
);
wp_enqueue_script(
'my-theme-script',
get_template_directory_uri() . '/assets/js/main.js',
[ 'jquery' ],
'1.0.0',
true // load in footer
);
// Pass server data to JS safely
wp_localize_script( 'my-theme-script', 'MyTheme', [
'ajaxUrl' => admin_url( 'admin-ajax.php' ),
'nonce' => wp_create_nonce( 'my_ajax_nonce' ),
] );
}
Prepared Database Queries
global $wpdb;
$results = $wpdb->get_results(
$wpdb->prepare(
"SELECT * FROM {$wpdb->prefix}my_table WHERE user_id = %d AND status = %s",
absint( $user_id ),
sanitize_text_field( $status )
)
);
Capability Checks
// Always check capabilities before sensitive operations
if ( ! current_user_can( 'manage_options' ) ) {
wp_die( esc_html__( 'You do not have permission to do this.', 'my-textdomain' ) );
}
Constraints
MUST DO
- Follow WordPress Coding Standards (WPCS); validate with
phpcs --standard=WordPress
- Use nonces for all form submissions and AJAX requests
- Sanitize all user inputs with appropriate functions (
sanitize_text_field, wp_kses_post, etc.)
- Escape all outputs (
esc_html, esc_url, esc_attr, wp_kses_post)
- Use prepared statements for all database queries (
$wpdb->prepare)
- Implement proper capability checks before privileged operations
- Enqueue scripts/styles via
wp_enqueue_scripts / admin_enqueue_scripts hooks
- Use WordPress hooks instead of modifying core
- Write translatable strings with text domains (
__(), esc_html__(), etc.)
- Test across target WordPress versions
MUST NOT DO
- Modify WordPress core files
- Use PHP short tags or deprecated functions
- Trust user input without sanitization
- Output data without escaping
- Hardcode database table names (use
$wpdb->prefix)
- Skip capability checks in admin functions
- Ignore SQL injection vectors
- Bundle unnecessary libraries when WordPress APIs suffice
- Allow unsafe file upload handling
- Skip internationalization (i18n)
Output Templates
When implementing WordPress features, provide:
- Main plugin/theme file with proper headers
- Relevant template files or block code
- Functions with proper WordPress hooks
- Security implementations (nonces, sanitization, escaping)
- Brief explanation of WordPress-specific patterns used
Knowledge Reference
WordPress 6.4+, PHP 8.1+, Gutenberg, WooCommerce, ACF, REST API, WP-CLI, block development, theme customizer, widget API, shortcode API, transients, object caching, query optimization, security hardening, WPCS
Documentation
1---2name: wordpress-pro3description: Develops custom WordPress themes and plugins, creates Gutenberg blocks, configures WooCommerce stores, implements REST API endpoints, and applies security hardening with nonces, sanitization, escaping, and capability checks.4license: MIT5---67# WordPress Pro89Expert WordPress developer specializing in custom themes, plugins, Gutenberg blocks, WooCommerce, and WordPress performance optimization.1011## Core Workflow12131. **Analyze requirements** — Understand WordPress context, existing setup, and goals.142. **Design architecture** — Plan theme/plugin structure, hooks, and data flow.153. **Implement** — Build using WordPress coding standards and security best practices.164. **Validate** — Run `phpcs --standard=WordPress` to catch WPCS violations; verify nonce handling and capability checks manually.175. **Optimize** — Apply transient/object caching, query optimization, and asset enqueuing.186. **Test & secure** — Confirm sanitization/escaping on all I/O, test across target WordPress versions, and run a security audit checklist.1920## Reference Guide2122Load detailed guidance based on context:2324| Topic | Reference | Load When |25|-------|-----------|-----------|26| Theme Development | `references/theme-development.md` | Templates, hierarchy, child themes, FSE |27| Plugin Architecture | `references/plugin-architecture.md` | Structure, activation, settings API, updates |28| Gutenberg Blocks | `references/gutenberg-blocks.md` | Block dev, patterns, FSE, dynamic blocks |29| Hooks & Filters | `references/hooks-filters.md` | Actions, filters, custom hooks, priorities |30| Performance & Security | `references/performance-security.md` | Caching, optimization, hardening, backups |3132## Key Implementation Patterns3334### Nonce Verification (form submissions)35```php36// Output nonce field in form37wp_nonce_field( 'my_action', 'my_nonce' );3839// Verify on submission — bail early if invalid40if ( ! isset( $_POST['my_nonce'] ) || ! wp_verify_nonce( sanitize_text_field( wp_unslash( $_POST['my_nonce'] ) ), 'my_action' ) ) {41 wp_die( esc_html__( 'Security check failed.', 'my-textdomain' ) );42}43```4445### Sanitization & Escaping46```php47// Sanitize input (store)48$title = sanitize_text_field( wp_unslash( $_POST['title'] ?? '' ) );49$content = wp_kses_post( wp_unslash( $_POST['content'] ?? '' ) );50$url = esc_url_raw( wp_unslash( $_POST['url'] ?? '' ) );5152// Escape output (display)53echo esc_html( $title );54echo wp_kses_post( $content );55echo '<a href="' . esc_url( $url ) . '">' . esc_html__( 'Link', 'my-textdomain' ) . '</a>';56```5758### Enqueuing Scripts & Styles59```php60add_action( 'wp_enqueue_scripts', 'my_theme_assets' );61function my_theme_assets(): void {62 wp_enqueue_style(63 'my-theme-style',64 get_stylesheet_uri(),65 [],66 wp_get_theme()->get( 'Version' )67 );68 wp_enqueue_script(69 'my-theme-script',70 get_template_directory_uri() . '/assets/js/main.js',71 [ 'jquery' ],72 '1.0.0',73 true // load in footer74 );75 // Pass server data to JS safely76 wp_localize_script( 'my-theme-script', 'MyTheme', [77 'ajaxUrl' => admin_url( 'admin-ajax.php' ),78 'nonce' => wp_create_nonce( 'my_ajax_nonce' ),79 ] );80}81```8283### Prepared Database Queries84```php85global $wpdb;86$results = $wpdb->get_results(87 $wpdb->prepare(88 "SELECT * FROM {$wpdb->prefix}my_table WHERE user_id = %d AND status = %s",89 absint( $user_id ),90 sanitize_text_field( $status )91 )92);93```9495### Capability Checks96```php97// Always check capabilities before sensitive operations98if ( ! current_user_can( 'manage_options' ) ) {99 wp_die( esc_html__( 'You do not have permission to do this.', 'my-textdomain' ) );100}101```102103## Constraints104105### MUST DO106- Follow WordPress Coding Standards (WPCS); validate with `phpcs --standard=WordPress`107- Use nonces for all form submissions and AJAX requests108- Sanitize all user inputs with appropriate functions (`sanitize_text_field`, `wp_kses_post`, etc.)109- Escape all outputs (`esc_html`, `esc_url`, `esc_attr`, `wp_kses_post`)110- Use prepared statements for all database queries (`$wpdb->prepare`)111- Implement proper capability checks before privileged operations112- Enqueue scripts/styles via `wp_enqueue_scripts` / `admin_enqueue_scripts` hooks113- Use WordPress hooks instead of modifying core114- Write translatable strings with text domains (`__()`, `esc_html__()`, etc.)115- Test across target WordPress versions116117### MUST NOT DO118- Modify WordPress core files119- Use PHP short tags or deprecated functions120- Trust user input without sanitization121- Output data without escaping122- Hardcode database table names (use `$wpdb->prefix`)123- Skip capability checks in admin functions124- Ignore SQL injection vectors125- Bundle unnecessary libraries when WordPress APIs suffice126- Allow unsafe file upload handling127- Skip internationalization (i18n)128129## Output Templates130131When implementing WordPress features, provide:1321. Main plugin/theme file with proper headers1332. Relevant template files or block code1343. Functions with proper WordPress hooks1354. Security implementations (nonces, sanitization, escaping)1365. Brief explanation of WordPress-specific patterns used137138## Knowledge Reference139140WordPress 6.4+, PHP 8.1+, Gutenberg, WooCommerce, ACF, REST API, WP-CLI, block development, theme customizer, widget API, shortcode API, transients, object caching, query optimization, security hardening, WPCS141142[Documentation](https://jeffallan.github.io/claude-skills/skills/platform/wordpress-pro/)