WordPress Has An AI Team Now. What It Means If You Ship Plugins
WordPress has formed a team to work on AI in core, and by now every builder of any size has shipped something. If you write plugins for a living, the interesting question is not whether AI arrives. It is what it arrives as, and what it expects your code to look like.
The Part Nobody Announces
An agent that can build a page has to be able to read one first. That means it has to understand what your plugin registered, what your settings mean, and what will happen if it changes them. It learns that from the same places a developer would: your registered post types, your settings API entries, your REST routes, your block metadata.
Plugins that did all of that properly are about to look very good for reasons that have nothing to do with AI. Plugins that stored their configuration in one serialised blob under one option key, with no schema and no REST surface, are about to look like a black box, because that is what they are.
Three Things That Suddenly Matter More
Your settings have a shape, or they do not. register_setting() with a
real show_in_rest schema is the difference between a machine being able to describe your
plugin and having to guess. It was always the correct thing to do. It was also always the thing
people skipped, because a hand-built options page works fine for a human.
Your capabilities are the only thing standing between an agent and your data. If a
REST route leans on is_user_logged_in() and calls it authorisation, an agent running as an
editor will happily do things you assumed only an administrator would ever attempt. This is not a
new bug. It is an old bug that used to need somebody to go looking for it.
Your code will be read by something that never gets bored. Dead filters, options written and never read, two functions that do nearly the same thing: none of that ever hurt much, because nobody had time to notice. That is changing.
What We Are Not Doing
We are not adding an AI feature to a plugin because AI is what everyone is adding. A plugin that generates text you did not ask for is a plugin with an API key, a rate limit, a bill and a support burden, in exchange for a feature the site owner already has three of.
What we are doing is making sure everything we ship can be understood from the outside: real settings schemas, real capability checks, REST routes that describe themselves, and no configuration that only makes sense if you already know where it is stored.
The Honest Summary
Almost nothing in this list is new advice. Register your settings properly, check capabilities rather than logins, keep your options readable. What is new is the cost of ignoring it. For fifteen years the only thing reading your plugin was a developer who could work it out. That is no longer the case, and the plugins that were already built to be understood will need the least work.