Repository navigation
Conversation
thetwopct
force-pushed
the
safer-identifiers-when-cloning-themes
branch
2 times, most recently
from
September 30, 2026 05:22
16b40cb to
0e6b352
Compare
thetwopct
force-pushed
the
safer-identifiers-when-cloning-themes
branch
from
October 2, 2026 05:38
0e6b352 to
f1f3460
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Cloning a theme currently applies the same text replacement rules to human-readable theme names, slugs, PHP identifiers, and JavaScript identifiers. These values have different syntax requirements.
For example, cloning Ollie with the name
My Themecould produce invalid PHP such as:Using the slug directly is also unsafe because hyphens, spaces, symbols, and leading numbers are not valid in PHP or JavaScript identifiers.
This PR makes namespace replacement context-aware for PHP and JavaScript while preserving the existing replacement behaviour for other text content.
Contributing this as just ran a workshop on Create Block Theme, and the errors experienced by users because of this issue was confusing and off-putting for something that should be a smooth easy experience.
What changed
PHP identifiers
PHP files are now processed using
token_get_all()so identifiers can be handled separately from comments and string values.Generated PHP identifiers use an underscore-separated form:
My ThemeOllieMy_ThemeOllie_SetupMy_Theme_Setupollie_setupmy_theme_setup$ollie_setting$my_theme_settingolliemy-themeOllieMy ThemeNames beginning with a number receive a
theme_prefix so that the resulting PHP identifier remains valid.For example,
2024 Cloneproduces:JavaScript identifiers
JavaScript files now distinguish identifiers from quoted strings and comments.
JavaScript identifiers use the appropriate casing:
myThemefor variables and other camel-case identifiers.MyThemefor globals and other capitalized identifiers.my-themefor text domains, CSS classes, script handles, and other string values.My Themefor display-name strings.For example:
becomes:
Embedded identifier prefixes, such as custom event names, are also updated without inserting invalid hyphens:
'extendableAnimationSettingsChanged'becomes:
'myThemeAnimationSettingsChanged'Localized JavaScript globals
Object names passed to
wp_localize_script()are JavaScript identifiers even though they appear inside PHP string literals.These names are now converted using the same JavaScript identifier rules as the corresponding JavaScript files:
becomes:
This keeps the PHP registration and JavaScript global references aligned.
Clone and ZIP paths
The file extension is now passed into the replacement logic in both cloning paths:
This allows PHP and JavaScript content to receive the appropriate identifier handling while retaining the existing generic replacement behaviour for CSS, SCSS, HTML, and text files.
Why
I am contributing this after running a Create Block Theme workshop where participants encountered these errors. The failures were confusing and off-putting in a workflow that should otherwise be a smooth and straightforward experience.
Popular themes such as Ollie use PHP namespaces and prefixed identifiers. A literal replacement using the entered theme name can therefore generate invalid PHP and make the cloned theme impossible to activate.
Other themes use theme-prefixed JavaScript variables, globals, events, and localized data. Replacing those prefixes with a hyphenated slug can similarly generate invalid or mismatched JavaScript.
Handling PHP and JavaScript identifiers according to their respective syntax rules makes more existing themes safely clonable without restricting the theme name users can enter.
Scope
This is intentionally a focused improvement and does not fully resolve #777.
Issue #777 covers replacement problems across every eligible file type and a wider range of theme structures and naming conventions. This PR adds syntax-aware handling for the two executable languages where invalid identifiers can immediately break a cloned theme:
The existing generic replacement remains in place for other supported text files. Further language-specific or structural replacement cases can continue to be addressed separately under #777.
For that reason, this PR uses
Addresses #777rather than closing the issue, and hopefully this stop gap solution is enough to improve Create Block Theme until or if a larger fix is warranted (as per @t-hamano)Testing
Automated coverage has been added for:
wp_localize_script().The following checks pass locally:
npm run test:unitnpm run test:unit:php:basenpm run test:unit:php:multisite-apinpm run lint:phpnpm run lint:jsnpm run lint:cssnpm run lint:md-docsnpm run lint:pkg-jsonnpm run buildAdditional real-theme validation:
My Themeand verified that the generated PHP identifiers and namespaces are valid.Manual testing instructions
My Themeas the theme name.My_Theme.my_theme.my-theme.My Theme.2024 Clone, and confirm that generated identifiers receive a validthemeprefix.Screenshots
Not applicable. This change affects generated source code rather than the cloning interface.
Addresses #777.