# WordPress Code Review

> Use this tool when you need to enforce WordPress coding standards and security best practices in your development workflow. It solves problems related to code quality, security vulnerabilities, and compliance with WordPress guidelines by validating PHP and JavaScript code against customizable rules and performing scans for common issues like SQL injection and XSS. It takes in code inputs and outputs validation results, making it ideal for development teams maintaining WordPress plugins or themes who require automated code review and security validation.

Canonical page: https://skillsregistry.net/skills/miniorangedev-wp-code-review  
JSON: https://api.skillsregistry.net/v1/skills/miniorangedev-wp-code-review

## Description

This MCP server provides WordPress-focused code review capabilities by fetching coding guidelines, validation rules, and security patterns from configurable web-hosted markdown files. Built by miniOrange's internal development team using TypeScript with the Model Context Protocol SDK, it offers tools for validating PHP and JavaScript code against WordPress best practices, performing security vulnerability scans for common issues like SQL injection and XSS, and accessing customizable coding standards through a flexible URL-based guideline system. The implementation uses a factory pattern designed for extensibility to future sources like Confluence or GitHub, parses markdown-formatted rules with configurable severity levels, and includes comprehensive security checks for dangerous functions, input validation, and WordPress-specific vulnerabilities, making it valuable for development teams maintaining WordPress plugins or themes who need automated code quality enforcement and security validation integrated into their AI-assisted development workflow.

## Trust

- **Trust score (0–1):** 0.94
- **Verification tier:** verified
- **Last scanned:** 2026-09-28

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** database
- **Updated:** 2026-09-28

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/miniorangedev-wp-code-review)
- **Repository:** <https://github.com/miniorangedev/wp-code-review-mcp-server>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "miniorangedev-wp-code-review"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/miniorangedev-wp-code-review` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/miniorangedev-wp-code-review/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
