wordpress-plugin-core

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is primarily focused on educational content and scaffolding templates for WordPress development. It strictly follows and promotes the official WordPress Plugin Handbook security guidelines.
  • [COMMAND_EXECUTION]: The scaffold-plugin.sh script is provided to automate the creation of new plugins. It performs local file system operations (copying templates, renaming files, creating directories) and executes sed for placeholder replacement. These actions are directly aligned with the skill's stated purpose of scaffolding development environments.
  • [EXTERNAL_DOWNLOADS]: The documentation and templates provide instructions for integrating well-known and widely-used third-party libraries such as YahnisElsts/plugin-update-checker via Composer or Git submodules. These references are documented as standard practices for plugins hosted outside the official WordPress.org repository.
  • [PROMPT_INJECTION]: No malicious patterns or instructions to bypass AI safety filters were detected. The instructional content is professional and focused on code quality and security standards.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 03:16 AM
Security Audit — agent-trust-hub — wordpress-plugin-core