<em>Local DEV Tools</em>
A collection of dev tools and settings accessible from WP Admin used while building a local WordPress site
by Matt Hodder · github.com/matthodder/wp-local-dev-tools · website
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/matthodder/wp-local-dev-tools/archive/refs/heads/main.zipLocal DEV Tools (mh-devtools)
A collection of dev tools and settings accessible from WP Admin used while building a local WordPress site...
Only use on a local environment. Delete this plugin before the site goes live. When the environment type (
wp_get_environment_type()) is anything other thanlocalordevelopment, the plugin shows an error notice to admins in wp-admin.
Requirements
- PHP 7.4+, WordPress 6.3+
- Composer
- Node 20+ (development only, to build
assets/intodist/)
Setup
composer install
npm install
npm run build:production
What's in it
Everything lives under the DEV TOOLS menu in wp-admin. Various tools, settings, and diagnostic tools to help in development without messing with command line.
Logging custom errors
mh_log_error( $text, $level = 'e' ) writes to wp-content/mh_logs.log. Levels are e/error, i/info and d/debug.
Uninstall
Deleting the plugin from the Plugins screen deletes the mh_dt_options option and wp-content/mh_logs.log.
Security note
Adminer gives full read/write access to the site's database. This plugin makes that very convenient, which is also why it must never reach a live site.
- Automatic login.
adminer/index.phplogs Adminer in withDB_USER/DB_PASSWORDfromwp-config.php. Anyone who gets past the WordPress check gets the whole database. - WordPress check.
adminer/index.phponly runs for a logged-in user withmanage_options, on alocalordevelopmentenvironment, while the plugin is active. - The Adminer file itself is not protected. Composer installs the compiled Adminer file. That file can be requested directly by URL, which skips the WP check. It shows Adminer's normal login form, so a visitor still needs database credentials, but it is exposed.
- Before going live, DELETE the plugin. Don't just deactivate it.
Structure
mh-devtools.php Plugin startup.
uninstall.php Deletes the option and log file when the plugin is deleted
adminer/index.php Protected Adminer entry point (DEV TOOLS → Database)
lib/ Shared building blocks
class-file-loader.php Requires every PHP file in a folder (alphabetical, recursive)
class-card.php Card markup
class-tool.php Base class for Tools page cards
class-setting.php Base class for Settings page toggles
class-registry.php Registry of tools and settings (Registry::tools(), Registry::settings())
inc/ The plugin
functions.php
tools/ Various tools (auto-loaded)
settings/ Various settings (auto-loaded)
assets/ Source files (edit these)
dist/ Compiled output (don't edit these)
Scripts
| Command | Description |
|---|---|
npm run watch |
Rebuild on change, with source maps |
npm run build |
Lint everything, then minified production build |
npm run build:production |
Minified production build only |
npm run lint |
Stylelint + ESLint + PHPCS |
npm run fix |
Auto-fix what each linter can |
composer lint |
PHPCS (WordPress Coding Standards) only |
composer lint:fix |
PHPCBF only |
Autoprefixer reads browser targets from browserslist in package.json; esbuild targets es2020.
Coding standards
- PHP: WordPress Coding Standards (
phpcs.xml.dist), PHP 7.4+ compatibility, text domainmh-devtools, prefixesmh_devtools/mh_dt. - SCSS:
stylelint-config-sass-guidelineswith alphabetical properties and logical properties (config inpackage.json). Classes are prefixedmh-and use BEM (.mh-card,.mh-card--full,.mh-card__title). - JS:
@wordpress/eslint-plugin.