Skip to the guide
All guides

Your first review

Start with one part of your project and get a review you can check and act on.

app WordPress DevKit 2.0.0checked reading 3 minutes

On this page

1. Choose a bounded target

After installation, open your target WordPress repository. Choose one plugin, theme, route or user journey, not the whole site. Say whether you want a review (read-only) or an implementation, and give the supported WordPress, PHP and WooCommerce versions when you know them.

2. Establish the project context

If the stack is unfamiliar, start with onboarding. It maps entrypoints, versions and owners, then points you to the right specialist.

Text
/wp-devkit:onboarding-review wp-content/plugins/example-plugin

That is a Claude plugin command. In Codex, ChatGPT, Antigravity or with manually installed skills, name the skill and keep the request scoped:

Text
$wp-devkit-site-audit-and-onboarding
Review wp-content/plugins/example-plugin without editing files.
Read the target project's instructions and this skill's engineering contract.
Map the entrypoints, discover versions, and prioritize specialist follow-up.

3. Run the specialist review

Use security for authorization and data paths, REST for routes, WooCommerce for orders and checkout, themes for templates. All 20 domains are listed in the guide library.

Text
/wp-devkit:security-review wp-content/plugins/example-plugin

4. Read the result

This is the shape of a real result, shortened from a run against a 25-line test plugin that contains a missing capability check, an unprepared SQL query and an unescaped output:

Text
Verdict: 3 CRITICAL findings. Read-only review; nothing was executed.

[CRITICAL][confirmed] Missing capability check on banner update (CWE-862)
Location : plugin.php:4-8 (sink at :6)
Actor    : authenticated subscriber
Path     : $_POST['banner'] -> update_option()   (check_ajax_referer is the only guard)
Impact   : a low role overwrites an administrator-only setting
Fix      : add current_user_can( 'manage_options' ) after the nonce check
Regression: admin 200; subscriber with a valid nonce 403 and option unchanged; anonymous rejected

[Candidate] where the 'fixture-settings' nonce is issued is not in this plugin.
            Missing evidence named; no severity assigned.

Not executed: PHPCS, PHPStan, runtime requests.
"No findings" would mean none in the inspected scope, not that the system is secure.

Run against a clean plugin, the same command reported no findings: it did not flag a fixed query without prepare() or a deliberately public REST route.

5. Ask for useful evidence

  • Confirmed findings and unverified candidates in separate groups.
  • For each finding: file and line, actor, trigger, reachable path, impact and confidence.
  • A minimal remediation and a regression that also preserves valid behavior.
  • Actual check commands, exit codes, coverage limits and unexecuted checks.

6. Review before fixing

Open the cited source and check the path yourself. A search match is a lead, not a finding. When a fix is warranted, follow review to fix to authorize a bounded implementation.

If something looks wrong

  • The command is not found: Claude commands need the plugin loaded; see installation and the FAQ .
  • The agent edited files during a review: that violates the contract. Stop, revert, and report it with the skill quality form (opens in a new tab) .
  • A finding seems wrong or a real problem was missed: report a minimal example the same way.

Note

Short commands request quick scans. The -review variants request broader reviews. The design command requests implementation; design-review stays read-only. See the command catalog for exact routing.