What's new since August 2024

🦴 WP Bones is back on Product Hunt: 33 releases since the first launch

On August 5, 2024 WP Bones launched here at 1.5.5: a framework that brings Laravel's habits to WordPress plugins. Two years and 33 releases later (1.6.0 β†’ 3.0.0), here's what's new πŸ‘‡

πŸ”’ Secure by default (3.0)

πŸšͺ Pages and menus that declare no capability need manage_options; REST routes without a permission_callback refuse every request

πŸ›‘οΈ Every request that changes something on a WP Bones admin page carries the plugin's nonce: $plugin->csrfField() in the form, checked before any controller runs; logged Ajax actions need one too

πŸ—„οΈ Migrations run once per site, recorded in an option, on activation or after a version change, however the update arrived; a lock keeps two requests from running them twice; seeders are migrations now

πŸ“ Compiled Blade views and logs go to uploads/wpbones/, behind an index.php and a deny-all .htaccess

🧭 php bones migrate:to-v3 converts the migrations and seeders, then lists the pages, routes, forms and Ajax providers that still need a look. Upgrading from 2.x:

composer require "wpbones/wpbones:^3.0"
php bones migrate:to-v3

βš™οΈ A modern build (2.0)

πŸ“¦ One webpack config on /scripts finds every app, script and stylesheet in resources/assets: TypeScript and LESS out of the box, no more Gulp

✨ php bones make:app scaffolds a React/TypeScript admin app; php bones migrate:to-v2 moves a 1.x plugin over

🧰 The bones CLI, 27 commands

πŸ›Ÿ Generators never overwrite a file unless you pass --force; Folder/Class works in every one of them

🚚 deploy checks where it's going before it builds, stops on a failed build, leaves out what git ignores and Composer's dev packages, and can create a ZIP

πŸƒ Runs from any folder; rename touches only what changes; update no longer removes the framework first

πŸ§ͺ php bones tinker shows errors and values; custom commands can load WordPress and reach your plugin

⏰ make:schedule for WordPress cron jobs

πŸ—„οΈ Database

πŸ” The query builder escapes every value and validates identifiers

πŸͺΆ Eloquent on SQLite, so it works in WordPress Playground and Studio, and on MySQL with WordPress's own charset: emoji survive the round trip

🏷️ Tables with or without the WordPress prefix

🧩 Boilerplates and demos

πŸ“š From 2 boilerplates to 14: API, Base, Blade, Cron, Custom Post Types, Database, Hooks, Internationalization, Mantine, Options, Packages, React, Routes, TypeScript

▢️ Each one opens in WordPress Playground from before you clone it

πŸ§ͺ Tested

βœ… From no test suite to 350 tests and 897 assertions, on PHP 8.1 to 8.4, on every pull request; a deprecation fails the build

🧑 And more

🌍 Translations for React apps and blocks, with make-pot and make-json scripts

🚩 A Flags package for feature flags from YAML files

🎨 Asset managers that enqueue admin and front-end scripts the WordPress way

πŸ” WP Bones for Raycast: the docs and the boilerplates one keystroke away

πŸ“– A new home at , with upgrade guides for 2.0 and 3.0

Thanks to everyone who sent code: dansleboby, balazsnasz and bredecl on GitHub πŸ™

Free and open source Β· PHP 8.1+ β†’

What should WP Bones learn next? Tell me below πŸ‘‡

46 views

Add a comment

Replies

Best

27 CLI commands is a lot of surface area. The part I would probably care about most is generators not overwriting files by default. Can that behavior be customized for teams with their own scaffolding workflow?

Β of the 27 that's the one I'd pick too. not as a setting today: generators never overwrite and --force goes on each call, never as a default. for a team's own scaffolding the way in is a custom command in your plugin (php bones make:console starts one): bones lists it next to its own commands, and since it's your code the templates live in your repo and you decide what it overwrites

what's missing is overriding the built-in templates from the project, like Laravel's stub:publish. fair ask, it's on the list now πŸ› οΈ

Β  quick follow-up: it shipped today in 3.1.0. make:* now reads a stubs/ folder in your plugin first, and php bones stub:publish copies the framework's there to start from