Book me

The WordPress developer skills that matter most in 2026 are the ones AI tools can’t supply on their own: diagnosing performance with field data, understanding the full request from browser to database, knowing WordPress internals such as hooks, queries and autoloaded options, building with modern core features like block themes and the Interactivity API, handling security and maintenance, getting technical SEO right in the server response, and explaining technical decisions to people who don’t write code. PHP, JavaScript and CSS are still the base. The skills on top of that base are what clients now pay for.

I review a lot of WordPress code and a lot of WordPress sites, and the gap I see most often is not syntax. Most developers can write a working plugin. Far fewer can tell me why a page is slow for real users, or what a plugin does to the database on every request. This list is ordered by how often the missing skill turns into a real problem in the projects I audit. It is the practical side of the argument I make in WordPress engineer vs developer.

Which WordPress developer skills still matter in 2026?

Here is the short version, then each one in more detail.

SkillWhat it coversHow you know you have it
———
Performance diagnosisCore Web Vitals, field vs lab data, profilingYou can name the slow layer before proposing a fix
Request lifecycleServer, PHP-FPM, OPcache, database, caches, CDNYou can explain where an uncached request spends its time
WordPress internalsHooks, WP_Query, options, transients, cron, REST APIYou can predict what a plugin does on every page load
Modern coreBlock themes, theme.json, blocks, Interactivity APIYou build features without adding a library for each one
Security and maintenanceUpdates, permissions, escaping, backupsYour last backup restore actually worked
Technical SEOStatus codes, redirects, canonicals, rendered HTMLA migration you ran kept its rankings
CommunicationAudits, estimates, trade-offsA non-technical manager can act on what you wrote

Why is performance diagnosis first?

Because it touches every other skill on the list, and because it is measurable. Google reports Core Web Vitals at the 75th percentile of real visits, with LCP good at 2.5 seconds or less, INP good at 200 milliseconds or less and CLS good at 0.1 or less. INP replaced FID in March 2024, and a lot of WordPress sites that passed before now fail on interaction, usually because of JavaScript from page builders and third-party tags.

The skill is not running PageSpeed Insights. The skill is reading the field data in CrUX or Search Console, finding which metric fails on which template, and tracing it to a cause. A slow LCP with a fast TTFB points to render-blocking assets or the hero image. A slow LCP with a slow TTFB points to the server. Bad INP points to the main thread. If you can make that call quickly, you are already ahead of most of the market. The full method is in Core Web Vitals for WordPress.

What should you know about the request lifecycle?

Enough to follow one request all the way through. The browser resolves DNS and opens a TLS connection. The CDN either answers from cache or forwards the request. The web server hands it to PHP-FPM, which runs WordPress using bytecode cached by OPcache. WordPress loads autoloaded options, runs plugins and the theme, queries the database, maybe checks a persistent object cache, and builds the HTML. Then the browser parses it and starts fetching everything else.

Each step can be the bottleneck. When I see a developer reach for a front-end optimization plugin while the server takes two seconds to send the first byte, the missing skill is this one. Start with reducing TTFB in WordPress.

Which WordPress internals are worth learning deeply?

The parts that run on every request, because that is where small mistakes multiply.

  • The hook system: when actions and filters fire, and what it costs to hook into init or wp_head with heavy work.
  • WP_Query and the main query: how to change it with pre_get_posts instead of running a second query, and which arguments avoid expensive counts.
  • Options and autoload: what plugins store with autoload on, and why a large autoloaded set slows every uncached page. Site Health checks autoload size since WordPress 6.6.
  • Transients and the object cache: how they behave with and without Redis or Memcached.
  • WP-Cron: why it depends on traffic, and when to replace it with a real system cron.
  • The REST API: permission callbacks, schema, and what you expose by default.

Query Monitor (wordpress.org/plugins/query-monitor/) is the tool I would give every developer on day one. It shows queries, hooks, HTTP calls and which plugin or theme triggered each one. The official developer documentation covers the rest.

How much of modern WordPress core do you need?

More than many developers use. Core now ships features that used to require a plugin or a framework: block themes and theme.json for design tokens and layout, the block editor APIs, the Interactivity API (WordPress 6.5) for front-end behavior without shipping a full framework, the Font Library (6.5), script loading strategies with defer and async (6.3), fetchpriority on images (6.3) and speculative loading (6.8).

I count this as a performance skill as much as a development one. Every feature you build with core instead of a third-party library is one less dependency to load, update and audit. Developers who still build everything with a page builder and a dozen add-ons are often building slow sites without noticing.

What does security and maintenance mean in practice?

Mostly boring habits, done every time. Escape output, sanitize input, check capabilities and nonces. Keep core, plugins and PHP on supported versions. Give each user and each service the least access it needs. Keep backups off the server, and restore one now and then to prove it works. Remove plugins nobody uses instead of only deactivating them.

None of this is glamorous, and clients rarely ask for it until something breaks. That is exactly why developers who do it without being asked get trusted with bigger projects.

Why should a developer care about technical SEO?

Because most technical SEO problems are created by developers. A staging site left open to crawlers, a redirect chain after a migration, canonicals pointing to the wrong URL, a template returning 200 for empty pages, important content rendered only by JavaScript. Marketing finds these problems in reports months later, and a developer has to fix them.

You don’t need to become an SEO specialist. You need to know what search engines, and now AI systems, read from your server response and why that matters. The developer view is in technical SEO starts in the server response, and migrations are covered in migrating a WordPress site without losing rankings.

Is communication really a technical skill?

On real projects, yes. I have seen good technical work rejected because the person who did it could not explain it, and mediocre work approved because someone explained it well. The skills I mean are specific:

  1. Writing an audit that lists the problem, the evidence, the fix and the expected effect, in that order.
  2. Estimating with ranges and stating what you don’t know yet.
  3. Explaining a trade-off in terms of money, risk or time, not in terms of tools.
  4. Saying no to a request, and offering what you would do instead.

If you want to practice in public, the WordPress community is a good place to do it. Writing posts, answering forum questions and eventually speaking at meetups or WordCamps trains exactly this skill. My talks are listed on the talks page.

How do these skills fit together?

They form a path more than a checklist. Performance diagnosis makes you learn the request lifecycle. The request lifecycle makes you learn WordPress internals. Internals make you better at choosing core features over plugins. Communication is what lets you get paid for all of it. If you want a step-by-step plan for building these skills, read how to become a WordPress developer and grow into an engineer. If you work on large sites, enterprise WordPress shows where these skills get tested hardest.

If you lead a team and want an outside view of where its skills fall short on a real project, see how I work on the WordPress expert page.

Work with Daniel More in Career