How do you review AI-written plugin or theme code?

by•

A lot of WordPress code written with AI works on the first try, but WordPress adds its own traps: missing nonce and capability checks, unescaped output, and queries that are slow on big sites.

When AI hands you a plugin or theme snippet, what is your review routine before it touches a client site? Do you use a linter like PHPCS with the WordPress standards, a staging site, a second AI pass, or just read it line by line?

I am curious what has actually caught real bugs for you, not what sounds best in theory.

14 views

Add a comment

Replies

Best

my first action is to set up a linting utility that follows strict community security rules. That linting utility immediately shows me any data validation gaps and any privilege assignment blind spots. i can fix those gaps in the foundation before I even start a test server.

PHPCS with the WordPress standards is worth having, but it catches the mechanical half: unescaped output, a missing nonce, the patterns it can match. What it can't judge is whether the capability you checked is the right one, because that's a logic question rather than a pattern. The two that have actually caught real problems for me both happen from the outside, not in review. First, log in as a Subscriber and call the plugin's admin-ajax action or REST route directly. A nonce stops a cross-site request, it doesn't stop a genuinely logged-in low-privilege user hitting the endpoint on purpose, and generated handlers very often check is_user_logged_in() where they needed current_user_can(). That reads perfectly fine in a diff. Second, call the same endpoint logged out: a register_rest_route with permission_callback missing, or set to __return_true, is common in AI-written code and the linter has no way to know that wasn't deliberate. Both take about a minute and find things a line-by-line read won't, because the question isn't whether a check exists, it's whether it's the right check.