What's new since August 2024
𦴠WP Bones is back on Product Hunt: 33 releases since the first launch
On August 5, 2024 WP Bones launched here at 1.5.5: a framework that brings Laravel's habits to WordPress plugins. Two years and 33 releases later (1.6.0 β 3.0.0), here's what's new π
π Secure by default (3.0)
πͺ Pages and menus that declare no capability need manage_options; REST routes without a permission_callback refuse every request
π‘οΈ Every request that changes something on a WP Bones admin page carries the plugin's nonce: $plugin->csrfField() in the form, checked before any controller runs; logged Ajax actions need one too
ποΈ Migrations run once per site, recorded in an option, on activation or after a version change, however the update arrived; a lock keeps two requests from running them twice; seeders are migrations now
π Compiled Blade views and logs go to uploads/wpbones/, behind an index.php and a deny-all .htaccess
π§ php bones migrate:to-v3 converts the migrations and seeders, then lists the pages, routes, forms and Ajax providers that still need a look. Upgrading from 2.x:
composer require "wpbones/wpbones:^3.0"
php bones migrate:to-v3βοΈ A modern build (2.0)
π¦ One webpack config on @wordpress/scripts finds every app, script and stylesheet in resources/assets: TypeScript and LESS out of the box, no more Gulp
β¨ php bones make:app scaffolds a React/TypeScript admin app; php bones migrate:to-v2 moves a 1.x plugin over
π§° The bones CLI, 27 commands
π Generators never overwrite a file unless you pass --force; Folder/Class works in every one of them
π deploy checks where it's going before it builds, stops on a failed build, leaves out what git ignores and Composer's dev packages, and can create a ZIP
π Runs from any folder; rename touches only what changes; update no longer removes the framework first
π§ͺ php bones tinker shows errors and values; custom commands can load WordPress and reach your plugin
β° make:schedule for WordPress cron jobs
ποΈ Database
π The query builder escapes every value and validates identifiers
πͺΆ Eloquent on SQLite, so it works in WordPress Playground and Studio, and on MySQL with WordPress's own charset: emoji survive the round trip
π·οΈ Tables with or without the WordPress prefix
π§© Boilerplates and demos
π From 2 boilerplates to 14: API, Base, Blade, Cron, Custom Post Types, Database, Hooks, Internationalization, Mantine, Options, Packages, React, Routes, TypeScript
βΆοΈ Each one opens in WordPress Playground from wpbones.com before you clone it
π§ͺ Tested
β From no test suite to 350 tests and 897 assertions, on PHP 8.1 to 8.4, on every pull request; a deprecation fails the build
π§‘ And more
π Translations for React apps and blocks, with make-pot and make-json scripts
π© A Flags package for feature flags from YAML files
π¨ Asset managers that enqueue admin and front-end scripts the WordPress way
π WP Bones for Raycast: the docs and the boilerplates one keystroke away
π A new home at wpbones.com, with upgrade guides for 2.0 and 3.0
Thanks to everyone who sent code: dansleboby, balazsnasz and bredecl on GitHub π
Free and open source Β· PHP 8.1+ β https://wpbones.com
What should WP Bones learn next? Tell me below π


Replies
27 CLI commands is a lot of surface area. The part I would probably care about most is generators not overwriting files by default. Can that behavior be customized for teams with their own scaffolding workflow?
@noahandersonΒ of the 27 that's the one I'd pick too. not as a setting today: generators never overwrite and --force goes on each call, never as a default. for a team's own scaffolding the way in is a custom command in your plugin (php bones make:console starts one): bones lists it next to its own commands, and since it's your code the templates live in your repo and you decide what it overwrites
what's missing is overriding the built-in templates from the project, like Laravel's stub:publish. fair ask, it's on the list now π οΈ https://github.com/wpbones/WPBones/issues/133
@noahandersonΒ quick follow-up: it shipped today in 3.1.0. make:* now reads a stubs/ folder in your plugin first, and php bones stub:publish copies the framework's there to start from https://wpbones.com/docs/bones-console/bones-console#customizing-the-stubs