Build secure WordPress plugins with core patterns for hooks, database interactions, Settings API, custom post types, REST API, and AJAX. Covers three architecture patterns (Simple, OOP, PSR-4) and the Security Trinity. Use when creating plugins, implementing nonces/sanitization/escaping, working with $wpdb prepared statements, or troubleshooting SQL injection, XSS, CSRF vulnerabilities, or plugin activation errors. ajaxurl => admin_url( admin-ajax.php ), nonce => wp_create_nonce( mypl-ajax-nonce
/plugin marketplace add jezweb/claude-skills/plugin install jezweb-wordpress-plugin-core-skills-wordpress-plugin-core@jezweb/claude-skillsWarn about potential security issues when editing files - targets command injection, XSS vulnerabilities, and dangerous coding patterns
Security reminder hook that warns about potential security issues when editing files, including command injection, XSS, and unsafe code patterns
Payload Development plugin - covers collections, fields, hooks, access control, plugins, and database adapters.
API security hardening, authentication implementation, authorization patterns, rate limiting, and input validation