Skip to content

WordPress plugin development

A plugin written for your WordPress site, for what no existing plugin does, for code that sits in a theme's functions.php, or in place of a plugin nobody maintains. Sold as developer time by the hour, in blocks, and quoted before work starts.

In short

  • For a site that has to do something no existing plugin does, that runs its own code from a theme's functions.php, or that depends on a plugin nobody maintains.
  • WordPress's documentation says a feature belongs in a plugin, and a theme should deal with the site's design only.
  • An edit to someone else's plugin or theme is gone at its next update. Hooks are what WordPress offers instead.
  • The questions on this page come from WordPress's own handbooks. Put them to anyone who writes a plugin for you.
  • Sold as developer time, by the hour, in blocks, with a quote before any work starts.
  • No listing in WordPress.org's plugin directory and no delivery date is promised on this page.

A plugin is how WordPress means new functionality to be added. Its Plugin Handbook opens with one rule: do not edit WordPress's own files, because each update overwrites them. Anything you add or change goes in a plugin.

You can ask for things like a small plugin that does one job for your business, a custom block for the block editor, an extra step in a WooCommerce checkout, or a link between your site and another system you use.

We sell this as developer time: by the hour, in blocks, with a quote before work starts. This page sets out what the job involves, from WordPress's and WooCommerce's own documentation, so that you can judge a quote from anyone.

Who it is for, and who it is not

A plugin of your own fits three situations.

  • Your site has to do something no existing plugin does.
  • Code was pasted into your theme's functions.php, and is tied to that theme.
  • You depend on a plugin nobody maintains any more, and use one part of it. You can ask for a small plugin that does that one job.

A different page fits better in these cases.

Where code belongs on a WordPress site

Custom code can sit in four places. WordPress's documentation says what happens to it in each.

WhereWhat WordPress does with itWhat that means for you
A pluginKeeps it in a folder of its own, normally under wp-content/plugins, and lists it on the "Plugins" screen.It runs whichever theme is active.
The theme's functions.phpLoads it on every page view, for the active theme only.Change the theme and it stops running. Update the theme and your edit is gone.
A child theme's functions.phpLoads it just before the parent's. The parent's updates do not touch it.Right for changes to that theme, and tied to it.
A must-use pluginRuns each PHP file placed directly in wp-content/mu-plugins. It cannot be switched off from the dashboard and shows no update notices.For code that must always run. Someone has to track its updates.

The Theme Handbook's rule of thumb is that a theme deals only with the site's design, and a feature that should be there whatever the design belongs in a plugin. Where the code really is about the theme, a child theme is the place for it.

Why not edit the plugin you already have

Because the edit does not last. WooCommerce's documentation says changes made directly in the files of a plugin or a parent theme disappear when it updates: the old version is deleted and a fresh copy is put in its place.

What WordPress offers instead is hooks: set points where one piece of code can add to another, or change it, without editing it. An action runs your code at such a point. A filter hands it a piece of data to change and hand back.

So a change to another plugin is written as a small plugin that uses the other one's hooks. The other plugin has to provide them, and the handbook says authors often overlook that.

Questions to ask whoever writes your plugin

WordPress's handbooks say what a plugin should do. These are fair questions for anyone who writes one for you, us included.

  • Is everything it names prefixed? Plugins' functions and classes share one space by default, so one can override another's. The handbook asks for a unique prefix of at least four letters on them, and on options and transients.
  • Who is allowed to do each thing? A plugin that lets users submit data should check their capabilities, the permissions that come with a role. A nonce protects a form or a link from misuse, and does not replace that check.
  • What happens to what people type in, and to what it prints? Trust no data, the site's own database included. Input is validated or sanitized before use. Output is escaped as it is printed.
  • How does it load scripts and styles? Through WordPress's enqueue functions, and only on the pages that need them.
  • What does it do when activated, deactivated and deleted? Activation sets up, for example default settings or a database table. Deactivation clears temporary data. Deleting the plugin from the dashboard is when it should remove its settings and tables. Ask what is left behind.
  • What does its header say? The comment at the top of its main file can give the lowest WordPress version it works on (Requires at least), the minimum PHP version (Requires PHP) and the plugins it depends on (Requires Plugins). The end-of-life checker shows whether your PHP version still gets security fixes.
  • Can it be translated? Text wrapped in WordPress's translation functions can be translated without changing the code.

How a plugin of your own gets updates

A plugin listed in WordPress.org's directory can be updated from the dashboard. For a plugin written for one site, two things in WordPress's documentation matter.

  • The Update URI header. Before WordPress 5.8, a custom plugin with the same slug as one hosted on WordPress.org risked being overwritten by an update of that plugin. Since 5.8, WordPress does not attempt to update a plugin whose Update URI is not its WordPress.org address.
  • Updates of its own. The same release added a filter a plugin outside the directory can use to offer updates from the address its header names.

Ask which yours uses, and who puts a new version on the site.

On a WooCommerce store

From WooCommerce 8.2, released in October 2023, High-Performance Order Storage is on by default for new installations. It keeps orders in tables of their own. WooCommerce's documentation asks this of a plugin that touches orders.

  • It uses WooCommerce's own order functions, not WordPress's functions for posts. Code that goes straight to the old tables may read an outdated order, or write to one that is never read.
  • It declares whether it is compatible. With an incompatible plugin active, the storage option is disabled under "WooCommerce > Settings > Advanced > Features".

What you get

  • The cost known first. We quote the plugin in hours, and you have the quote before work starts.
  • A written quote for a larger job. A plugin too large to price as a few hours gets one.
  • Nothing is started without your yes.
  • Extra work quoted first. If the job grows, or you want the plugin to do more, the extra hours are quoted before they are worked.
  • What was quoted, built. We build what is quoted.

The hourly price is shown on this page. It is sold the same way as custom development: as developer time.

How it works

  1. Step 1: Describe the plugin

    Write to us on the contact page with the site's address and what the plugin should do.

  2. Step 2: Get a quote

    We quote the job in hours. A larger job gets a written quote.

  3. Step 3: Agree before anything starts

    Work starts only after you say yes to the quote.

  4. Step 4: Further work is quoted the same way

    If the job grows, the extra hours are quoted before they are worked.

What we need from you to start

The contact form asks for your name, an email address and your message. We reply by email. A clear description gets a closer quote, so put these in the message:

  • the site's address
  • what the plugin should do, in plain words: who uses it, what they do, and what should happen next
  • where the code is now, if it exists: the theme's functions.php, or an older plugin and the part you use, such as a shortcode or a task it schedules through WP-Cron
  • the plugins it has to work with, and whether the site is a store. The platform and theme detector lists the plugins that show.
  • the other system it has to exchange data with, if any, for example through WordPress's REST API
  • your deadline, if there is one

What it does not cover

  • A listing in WordPress.org's plugin directory. A plugin is listed there only after WordPress.org's own team has reviewed and approved it, so no listing is promised.
  • Edits to the files of someone else's plugin or theme. An update would remove them. Where that plugin offers a hook, the change is made there.
  • Paid plugins, licenses and outside services your job depends on. Developer time pays for the work only.
  • Upkeep afterwards. Updates, backups and monitoring are a care plan. See WordPress maintenance.
  • A delivery date. If you have a deadline, put it in your message.
  • Results in your business. We build what is quoted. We do not promise more sales from it.

Before you buy: do it yourself, or check first

A plugin of your own is for what is left once a ready-made one has been ruled out.

What it costs

Common questions

Is a snippet in functions.php enough, or do I need a plugin?

It depends on what the code is about. WordPress's Theme Handbook keeps a theme to the site's design, and puts a feature that should be there whatever the design in a plugin.

Can you change a plugin I already use?

Not by editing its files, because its next update would replace them. Where the plugin offers hooks, a small plugin of your own can use them.

Should mine be a must-use plugin?

WordPress's documentation says must-use plugins suit code that should always run. It advises against them for a plugin that relies on activation, deactivation or uninstall hooks, or needs ordinary update notices.

How much will my plugin cost?

The hourly price is on this page. The total depends on the hours the plugin takes, and you get that number as a quote before work starts.

Do I need a care plan to buy developer time?

No. Developer time is bought on its own. Custom code, like the rest of a site, needs checking when WordPress and PHP are updated, so decide who will do that once the work is finished.

Not sure what is wrong?

Tell us what you see. We reply with the cause and a fixed quote, and the diagnosis is free.