New: “AI + WordPress” lessons just dropped — build smarter sites in half the time.

Vibe Coding a Small Feature Safely

Use AI to help write a tiny WordPress feature, then test it in Playground or staging and check sanitizing, escaping, nonces and capabilities.

“Vibe coding” means describing what you want in plain language and letting an AI tool write the code. It’s a fun way to build small features, but code you don’t understand can break your site or open security holes. Here’s how to vibe code like a responsible scientist.

Start small and sandboxed

  • Pick a tiny feature, like a shortcode that shows a message or a simple settings field.
  • Put it in a small custom plugin, not your theme’s functions file, so it survives theme changes.
  • Test in WordPress Playground or staging first. WordPress Playground runs WordPress right in your browser, so you can experiment with nothing at stake. Your host’s staging site is the next step before production.

The four security checks

Ask the AI to explain its code, then check it for these WordPress essentials:

  • Sanitize input: clean data coming in, using functions like sanitize_text_field().
  • Escape output: make data safe when displayed, using esc_html(), esc_attr() or esc_url().
  • Nonces: verify form submissions and actions came from your site, using wp_nonce_field() and check_admin_referer() or wp_verify_nonce().
  • Capabilities: confirm the user is allowed to do the action, using current_user_can().

Here’s a tiny example of the pattern for saving a setting from an admin form:

if ( isset( $_POST['pp_message'] )
    && current_user_can( 'manage_options' )
    && check_admin_referer( 'pp_save_message' ) ) {
    $message = sanitize_text_field( wp_unslash( $_POST['pp_message'] ) );
    update_option( 'pp_message', $message );
}

// Later, when displaying it:
echo '<p>' . esc_html( get_option( 'pp_message', '' ) ) . '</p>';

The form itself would include wp_nonce_field( 'pp_save_message' ). Notice all four checks: capability, nonce, sanitize on the way in, escape on the way out.

Professor’s warning: Never paste AI-generated code straight into a live site, and never edit plugin or theme files through the dashboard on production. One typo can take your site down. Test in Playground or staging, keep a backup, and ask a developer to review anything that handles payments, logins or personal data.

Prompts that produce safer code

Include requirements in your prompt: “Write a small WordPress plugin that follows WordPress coding standards. Sanitize all input, escape all output, use nonces for form submissions, check capabilities, and explain each part.” Then ask, “What security issues could this code have?” Learn more on our vibe coding page.

Your assignment

  1. Open WordPress Playground and ask an AI tool to build a tiny shortcode plugin.
  2. Check the code for sanitizing, escaping, nonces and capabilities, and fix anything missing.
  3. Test it until it works, then write down what each part does in your own words.