We need to talk about Claude Code. The standard advice in the ecosystem has become “just prompt and pray,” and it is wrecking site stability. I’ve spent more than 14 years fixing broken WordPress sites, and this habit of shipping unverified AI output is building a mountain of technical debt that we will be cleaning up for years.
The tool itself isn’t the problem. Claude Code is one of the most capable agentic coders we’ve seen. The issue is how we use it. Treat it like a junior dev who needs no supervision and you get junior-level bugs. Treat it like a high-powered engine that needs a roadmap and you get code you can actually ship. Building robust code with Claude Code means shifting from writing prompts to designing workflows.
The Plan Mode discipline
One of the biggest mistakes I see is developers letting the agent jump straight into the source code. You wouldn’t start a complex WooCommerce AI workflow without a technical spec, so why let your agent do it? Claude Code has a dedicated Plan Mode for exactly this. It lets the model map out dependencies before touching a single line of PHP.
In Plan Mode, the agent spots potential race conditions or transient conflicts that a standard chat interface might miss. It is far more useful to have the LLM ask you questions than for you to guess what it needs. So insist on a breakdown of the logic before you authorize any file writes.
Maintaining skill files (CLAUDE.md)
If you want to write truly robust code, the repository needs a long-term memory. I use what I call a skill file, usually a CLAUDE.md in the root directory. It acts as a persistent knowledge base for the agent, documenting past bugs, site-specific hooks, and your agency’s coding standards.
Every time you fix a bug with Claude Code, have the agent write that fix back into the skill file as a general rule. Say you found a conflict between a caching plugin and your custom AJAX handler: record it. Next time the agent works on that site, it won’t repeat the mistake. That is how you move from one-off hacks to a codebase that improves itself.
The robustness example: PHP security
Take a common scenario. A naive AI prompt can generate code that technically works but is wide open to exploits. This is where senior oversight stops being optional.
// The "Lazy" AI Approach - No security, high risk
function update_product_price_ajax() {
update_post_meta($_POST['id'], '_price', $_POST['price']);
}
To get Claude Code to write something you can actually ship, your CLAUDE.md should require nonces and capability checks. This is the version the agent produces when you guide it properly:
<?php
/**
* Robust AJAX handler generated via Claude Code with proper oversight.
*/
function bbioon_robust_update_price() {
// 1. Verify Nonce
check_ajax_referer('bbioon_price_update', 'security');
// 2. Check Permissions
if (!current_user_can('edit_products')) {
wp_send_json_error('Unauthorized access.');
}
// 3. Sanitize and Validate
$product_id = absint($_POST['id']);
$new_price = sanitize_text_field($_POST['price']);
if ($product_id > 0 && is_numeric($new_price)) {
update_post_meta($product_id, '_price', $new_price);
wp_send_json_success('Price updated.');
}
wp_send_json_error('Invalid data provided.');
}
add_action('wp_ajax_update_price', 'bbioon_robust_update_price');
Context windows: the one million token trap
Anthropic recently expanded context windows by a lot. But just because you can feed Claude Code a million tokens doesn’t mean you should. In my experience, performance drops off once you push past the 300k mark. The noise starts to drown out the signal, the model loses focus on the task at hand, and it begins hallucinating legacy patterns from files that have nothing to do with the change.
Keep your context lean. Give it only the hooks, filters, and documentation for the feature you are refactoring. If you’re working on a WordPress Core AI integration, don’t hand it your entire front-end CSS library.
If this Claude Code work is eating up your dev hours, let me handle it. I’ve been wrestling with WordPress since the 4.x days.
Final takeaway
The future of development isn’t “AI vs. humans.” It’s “humans who manage AI vs. humans who get replaced by AI bugs.” Use Plan Mode, keep your skill files current, and manage your context tightly, and you can push Claude Code to build sites that are faster and more reliable than anything you’d write by hand. Stop shipping hacks and start shipping architecture. For more on what the tool can officially do, see the Claude Code documentation on GitHub.