ADVANCED

Code Checks

FanCoolo checks your code so a broken block doesn't reach the site.

PHP syntax check

When you save PHP in a block or symbol, FanCoolo parses it first. If the syntax is invalid, the editor shows a PHP Syntax Error with the line number and the code around it, so you can fix it before the block is generated.

FanCoolo uses the PHP parser library nikic/php-parser for this check.

Security check

FanCoolo can also scan a block, symbol or SCSS partial for common security problems in the code you wrote:

  • output that is printed without escaping (XSS risk);
  • input that is used without sanitization;
  • risky patterns in JavaScript and SCSS.

Run it from the command line:

wp fancoolo validate-security block hero
wp fancoolo validate-security symbol button

The result is printed as JSON. AI agents connected through the WordPress Abilities API can run the same check (fancoolo/validate-block-security).