FanCoolo checks your code so a broken block doesn't reach the site.
PHP syntax check
When you save PHP in a block or symbol, FanCoolo parses it first. If the syntax is invalid, the editor shows a PHP Syntax Error with the line number and the code around it, so you can fix it before the block is generated.
FanCoolo uses the PHP parser library nikic/php-parser for this check.
Security check
FanCoolo can also scan a block, symbol or SCSS partial for common security problems in the code you wrote:
- output that is printed without escaping (XSS risk);
- input that is used without sanitization;
- risky patterns in JavaScript and SCSS.
Run it from the command line:
wp fancoolo validate-security block hero
wp fancoolo validate-security symbol button
The result is printed as JSON. AI agents connected through the WordPress Abilities API can run the same check (fancoolo/validate-block-security).