Atlas / Skills / emdash-cms / Wordpress Plugin To Emdash

Wordpress Plugin To EmdashCAUTION

skills/emdash-cms/wordpress-plugin-to-emdash

EmDash is a full-stack TypeScript CMS based on Astro; the spiritual successor to WordPress

Verdict
CAUTION
Grade
B
Trust score
89 /100
Version
—
Hosts
—
License
MIT
Stars
13,442
01

Overview

EmDash is a full-stack TypeScript CMS based on Astro; the spiritual successor to WordPress

Read from source at commit 2e1ca292efe5OBSERVED · 2026-10-07
02

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: wordpress-plugin-to-emdash
description: Analyze and port WordPress plugin behavior, custom post types, shortcodes, admin workflows, and stored data to current EmDash extension points. Use for WordPress-plugin migrations or when deciding which behavior belongs in an EmDash plugin, site schema, seed, or Astro code. Do not use for visual theme ports without plugin functionality.
---

# Port a WordPress plugin to EmDash

Preserve the plugin's user-visible behavior and data model without translating PHP line by line. WordPress and EmDash divide responsibilities differently, so first decide whether each feature belongs in site schema, Astro code, a sandboxed plugin, or a trusted native plugin.

Load [creating-plugins](../creating-plugins/SKILL.md) before implementing plugin code. Load [building-emdash-site](../building-emdash-site/SKILL.md) when the port changes collections, seeds, queries, or frontend templates. Those skills define the current APIs; this skill covers migration decisions.

## Understand the source

Inspect the plugin source, installation behavior, database changes, hooks, REST endpoints, scheduled work, admin screens, shortcodes or blocks, frontend output, permissions, and external services. Identify behavior that users rely on separately from WordPress-specific implementation.

Record:

- required content and configuration data;
- actions that mutate or publish data;
- authorization and trust boundaries;
- background or retry behavior;
- frontend and administrator interactions;
- import, migration, and rollback needs;
- license obligations for copied assets or code.

If the source, expected behavior, or target EmDash environment is missing, report the gap instead of inventing an equivalent.

## Assign each responsibility

| WordPress responsibility                        | EmDash destination                                                                                           |
| ----------------------------------------------- | ------------------------------------------------------------------------------------------------------------ |
| Custom post type, taxonomy, or metadata         | Collection, taxonomy, and fields created through the site schema or seed                                     |
| Site-wide presentation setting                  | Site setting read by Astro templates                                                                         |
| Plugin-owned user settings                      | `ctx.settings`; declare credentials as encrypted `secret` fields                                             |
| Plugin-owned cursors, caches, or internal state | Plugin-scoped `ctx.kv`                                                                                       |
| Plugin-owned queryable records                  | Declared `ctx.storage.<collection>` storage                                                                  |
| Content discovery, translation, or publication  | Capability-gated `ctx.content` and `ctx.schema`; policy hooks and actions have separate authority            |
| Runtime taxonomy or redirect management         | `ctx.taxonomies` or `ctx.redirects` with narrow read/write capability                                        |
| Comment administration                          | `ctx.comments`; reads expose personal data and moderation uses expected status                               |
| WordPress REST endpoint                         | Declared plugin route with explicit methods, inputs, headers, and response mode                              |
| Scheduled event                                 | `cron` hook and `ctx.cron` scheduling                                                                        |
| Admin page or form                              | Block Kit for sandboxed plugins; React only for a trusted native plugin                                      |
| Post editor metabox or saved-entry action       | `admin.editorPanels` or `admin.editorActions` on private routes                                              |
| User or author lookup                           | `ctx.users` with `users:read`                                                                                |
| Outbound HTTP request                           | `ctx.http.fetch()` with `network:request` and an `allowedHosts` entry                                        |
| Media operation                                 | Separate metadata, byte-read, metadata-write, and upload/delete authorities                                  |
| `WP_Query` or template tag                      | EmDash content API in Astro site code                                                                        |
| Shortcode or editor block                       | Existing Portable Text content where possible; a custom Portable Text block requires a trusted native plugin |
| Raw head markup or scripts                      | Trusted native `page:fragments`; registry-installed plugins can contribute validated `page:metadata` only    |

Do not create collections or taxonomies by reaching into EmDash system tables. Use the public schema, seed, CLI, or admin boundary. Do not use internal REST routes to imitate a sandbox API that does not exist.

Keep authorities separate: reading media metadata does not grant bytes, moderation does not grant deletion, publication policy does not grant publication actions, and content restore does not grant ordinary content reads.

## Choose the plugin format

Use a sandboxed plugin by default. It supports portable hooks, routes, declared storage, media, network access, MCP tools, and Block Kit admin UI through an install-time trust contract.

Use a trusted native plugin only when the feature requires host-process access, React admin code, Astro rendering components, raw page fragments, or custom Portable Text block definitions. State the extra authority and distribution limitation in the migration plan.

Some WordPress plugins do not need an EmDash plu
03

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeNA
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (5)

MEDIUMInventory / provenance · inv.symlink · CWE-1104
.agents/skills
.agents/skills
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills
.claude/skills
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
templates/blank/.claude/skills
templates/blank/.claude/skills
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
templates/blog-cloudflare/.claude/skills
templates/blog-cloudflare/.claude/skills
Why it matters. link not followed
LOWInventory / provenance · inv.symlink · CWE-1104
.claude/CLAUDE.md
.claude/CLAUDE.md
Why it matters. link not followed

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 2e1ca292efe5full audit observations/trust-audit/skill/emdash-cms__wordpress-plugin-to-emdash.json · Report an issue / request a re-scan
04

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-072e1ca292efe5CAUTIONB89first audit
05

Questions

What does the Wordpress Plugin To Emdash skill do?

EmDash is a full-stack TypeScript CMS based on Astro; the spiritual successor to WordPress

Is Wordpress Plugin To Emdash safe to install?

With care. The audit graded it B (89/100) and found 5 things worth knowing before you trust this skill, listed below with the exact line each was found on.

What can Wordpress Plugin To Emdash access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

How current is this page?

The grade is for one exact copy of the source (2e1ca292efe5), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement