WP Manifestindependent plugin directory
manifest / developer / wp-local-dev-tools

<em>Local DEV Tools</em>

A collection of dev tools and settings accessible from WP Admin used while building a local WordPress site

by Matt Hodder · github.com/matthodder/wp-local-dev-tools · website

★ 0stars
0forks

Install

No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:

wp plugin install https://github.com/matthodder/wp-local-dev-tools/archive/refs/heads/main.zip

Local DEV Tools (mh-devtools)

A collection of dev tools and settings accessible from WP Admin used while building a local WordPress site...

Only use on a local environment. Delete this plugin before the site goes live. When the environment type (wp_get_environment_type()) is anything other than local or development, the plugin shows an error notice to admins in wp-admin.

Requirements

  • PHP 7.4+, WordPress 6.3+
  • Composer
  • Node 20+ (development only, to build assets/ into dist/)

Setup

composer install
npm install
npm run build:production

What's in it

Everything lives under the DEV TOOLS menu in wp-admin. Various tools, settings, and diagnostic tools to help in development without messing with command line.

Logging custom errors

mh_log_error( $text, $level = 'e' ) writes to wp-content/mh_logs.log. Levels are e/error, i/info and d/debug.

Uninstall

Deleting the plugin from the Plugins screen deletes the mh_dt_options option and wp-content/mh_logs.log.

Security note

Adminer gives full read/write access to the site's database. This plugin makes that very convenient, which is also why it must never reach a live site.

  • Automatic login. adminer/index.php logs Adminer in with DB_USER / DB_PASSWORD from wp-config.php. Anyone who gets past the WordPress check gets the whole database.
  • WordPress check. adminer/index.php only runs for a logged-in user with manage_options, on a local or development environment, while the plugin is active.
  • The Adminer file itself is not protected. Composer installs the compiled Adminer file. That file can be requested directly by URL, which skips the WP check. It shows Adminer's normal login form, so a visitor still needs database credentials, but it is exposed.
  • Before going live, DELETE the plugin. Don't just deactivate it.

Structure

mh-devtools.php     Plugin startup.
uninstall.php       Deletes the option and log file when the plugin is deleted
adminer/index.php   Protected Adminer entry point (DEV TOOLS → Database)
lib/                Shared building blocks
  class-file-loader.php  Requires every PHP file in a folder (alphabetical, recursive)
  class-card.php         Card markup
  class-tool.php         Base class for Tools page cards
  class-setting.php      Base class for Settings page toggles
  class-registry.php     Registry of tools and settings (Registry::tools(), Registry::settings())
inc/                The plugin
  functions.php          
  tools/                 Various tools (auto-loaded)
  settings/              Various settings (auto-loaded)
assets/             Source files (edit these)
dist/               Compiled output (don't edit these)

Scripts

Command Description
npm run watch Rebuild on change, with source maps
npm run build Lint everything, then minified production build
npm run build:production Minified production build only
npm run lint Stylelint + ESLint + PHPCS
npm run fix Auto-fix what each linter can
composer lint PHPCS (WordPress Coding Standards) only
composer lint:fix PHPCBF only

Autoprefixer reads browser targets from browserslist in package.json; esbuild targets es2020.

Coding standards

  • PHP: WordPress Coding Standards (phpcs.xml.dist), PHP 7.4+ compatibility, text domain mh-devtools, prefixes mh_devtools / mh_dt.
  • SCSS: stylelint-config-sass-guidelines with alphabetical properties and logical properties (config in package.json). Classes are prefixed mh- and use BEM (.mh-card, .mh-card--full, .mh-card__title).
  • JS: @wordpress/eslint-plugin.