Nonces on every form, sanitization on input, escaping on output, and a capability check before any privileged action runs, so a subscriber and an administrator never get access to the same functions by accident. We also run the plugin through PHPCS’s security sniffs as part of the WPCS review before it ships.

Something in here sound like your project?

Tell us what you're building and we'll tell you honestly whether we're a fit.

From the blog

More from the blog

All posts