“Vibe coding” means describing what you want in plain language and letting an AI tool write the code. It’s a fun way to build small features, but code you don’t understand can break your site or open security holes. Here’s how to vibe code like a responsible scientist.
Start small and sandboxed
- Pick a tiny feature, like a shortcode that shows a message or a simple settings field.
- Put it in a small custom plugin, not your theme’s functions file, so it survives theme changes.
- Test in WordPress Playground or staging first. WordPress Playground runs WordPress right in your browser, so you can experiment with nothing at stake. Your host’s staging site is the next step before production.
The four security checks
Ask the AI to explain its code, then check it for these WordPress essentials:
- Sanitize input: clean data coming in, using functions like
sanitize_text_field(). - Escape output: make data safe when displayed, using
esc_html(),esc_attr()oresc_url(). - Nonces: verify form submissions and actions came from your site, using
wp_nonce_field()andcheck_admin_referer()orwp_verify_nonce(). - Capabilities: confirm the user is allowed to do the action, using
current_user_can().
Here’s a tiny example of the pattern for saving a setting from an admin form:
if ( isset( $_POST['pp_message'] )
&& current_user_can( 'manage_options' )
&& check_admin_referer( 'pp_save_message' ) ) {
$message = sanitize_text_field( wp_unslash( $_POST['pp_message'] ) );
update_option( 'pp_message', $message );
}
// Later, when displaying it:
echo '<p>' . esc_html( get_option( 'pp_message', '' ) ) . '</p>';
The form itself would include wp_nonce_field( 'pp_save_message' ). Notice all four checks: capability, nonce, sanitize on the way in, escape on the way out.
Professor’s warning: Never paste AI-generated code straight into a live site, and never edit plugin or theme files through the dashboard on production. One typo can take your site down. Test in Playground or staging, keep a backup, and ask a developer to review anything that handles payments, logins or personal data.
Prompts that produce safer code
Include requirements in your prompt: “Write a small WordPress plugin that follows WordPress coding standards. Sanitize all input, escape all output, use nonces for form submissions, check capabilities, and explain each part.” Then ask, “What security issues could this code have?” Learn more on our vibe coding page.
Your assignment
- Open WordPress Playground and ask an AI tool to build a tiny shortcode plugin.
- Check the code for sanitizing, escaping, nonces and capabilities, and fix anything missing.
- Test it until it works, then write down what each part does in your own words.