Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

functions.php is loaded automatically for the active WordPress theme, making it a convenient place for theme-specific PHP. The most useful patterns are not risky “hacks”: use hooks to run code at the right time, enqueue assets through WordPress APIs, escape values for their output context, and keep functionality that must survive a theme change in a plugin.

The examples below focus on those foundations. Use them in a theme or child theme only when the behavior belongs to that theme; avoid copying a snippet into production without adapting its handle, path, or output to your site.

Start with the right home for the code

1. Use functions.php for theme-specific PHP

WordPress loads the active theme’s functions.php on page views. It can register theme features and connect callbacks to WordPress hooks. Both block and classic themes can use it. WordPress Theme Handbook: Custom Functionality

2. Keep durable site features in a plugin

If a feature should continue working after a theme change, put it in a plugin rather than the theme. A theme switch can remove code that lives in the old theme’s functions.php. Theme-dependent presentation and behavior are more natural fits for the theme.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Use the active child theme for child-theme behavior

The active child theme’s functions.php loads before its parent theme’s file. Add child-specific callbacks there rather than editing the parent theme, so the customization is associated with the active child theme.

4. Split longer code into helper files

As functions.php grows, move related code into separate PHP files and include them from it. The handbook demonstrates this organization pattern; the included code is still theme code and follows the same theme-versus-plugin boundary.

5. Choose a path helper based on override behavior

Use get_parent_theme_file_path() when you want a file path in the parent theme. Use get_theme_file_path() when a child theme should be able to provide an override. These are file-path helpers for locating theme files, not substitutes for deciding where functionality belongs. WordPress Theme Handbook: Custom Functionality

6. Omit the closing PHP tag

For a PHP-only functions.php file, leave off the final ?>. This reduces the chance that accidental whitespace after the closing tag will be sent as output.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Connect code to WordPress at the right time

7. Register theme setup on after_setup_theme

Theme setup commonly belongs on the after_setup_theme action. This gives WordPress a defined point in its loading process to run theme setup instead of executing setup logic merely because the file was included.

8. Use an action when the callback performs work

An action callback does something at a particular point, such as registering setup behavior. Connect it with the appropriate hook rather than running the operation directly at the top level of functions.php.

9. Use a filter when the callback changes data

A filter receives data to modify and returns the changed value. Do not treat an action and a filter as interchangeable: choose the hook type that matches whether the callback performs work or transforms data.

10. Keep callbacks focused on their hook’s purpose

Attach a callback to the lifecycle point that matches its job. Theme setup belongs with setup; front-end asset loading belongs with the front-end enqueue hook. This makes the timing and purpose of the code easier to understand.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Load front-end assets through WordPress

11. Enqueue front-end scripts on wp_enqueue_scripts

Use the wp_enqueue_scripts hook for front-end scripts and styles rather than printing asset markup directly. WordPress’s theme guidance recommends the enqueue APIs rather than hard-coded tags. Including Assets · wp_enqueue_scripts hook reference

12. Enqueue a script with wp_enqueue_script()

Use wp_enqueue_script() to register a script for loading. Its arguments include a unique handle, dependencies, a version, and placement information; supplying those deliberately gives WordPress information that a literal <script> tag does not convey through the enqueue API. wp_enqueue_script() reference

13. Give each script a unique handle

Choose a distinctive, theme-prefixed handle for a script. The handle identifies the asset in WordPress’s enqueue system, so avoid generic names likely to collide with another theme or plugin.

14. Declare script dependencies

When an enqueued script relies on another registered script, declare that dependency in the enqueue call rather than assuming a load order. The function reference documents dependencies as an argument to wp_enqueue_script().

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

15. Provide a script version where appropriate

The wp_enqueue_script() API accepts a version argument. Set version information intentionally for the asset instead of leaving WordPress and site maintainers without an explicit version value in the enqueue declaration.

16. Choose the script’s placement deliberately

The enqueue function accepts placement information. Decide where the script should be loaded based on its needs rather than hard-coding a tag in a template; consult the function reference for the current argument details.

17. Enqueue styles instead of printing stylesheet markup

Use WordPress asset functions and the appropriate hook to load styles, just as you do scripts. Avoid emitting a literal stylesheet tag from functions.php; the Theme Handbook’s asset guidance covers both scripts and styles. Including Assets

Escape values when they are output

18. Escape HTML text with esc_html()

When a dynamic value is printed as HTML text, use esc_html() for that context. Escaping should happen where the value is rendered, not as a general-purpose transformation applied long before its output context is known.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

19. Escape a printed URL with esc_url()

When outputting a dynamic URL, use esc_url(). A URL is not ordinary HTML text, so use the escaping helper intended for URL output.

20. Escape an HTML attribute with esc_attr()

When a dynamic value is printed inside an HTML attribute, use esc_attr(). Do not substitute esc_html() simply because both values appear in HTML; the output contexts differ.

21. Choose escaping by the exact output context

Text, URLs, attributes, JavaScript, textarea, XML, and permitted HTML each call for context-appropriate handling. WordPress’s escaping guidance describes the distinction; one escaping function is not interchangeable with every other one. Escaping Data

22. Escape at the point of rendering

Keep values in their useful form while working with them, then apply the matching escaping function as they are printed. This keeps the escaping decision tied to the destination context, where it can be made correctly.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

23. Do not confuse escaping with allowing HTML

If output is meant to permit some HTML, plain text escaping is not the same operation as allowing selected markup. Follow WordPress’s guidance for permitted HTML rather than assuming that an escaped text value will preserve intended tags.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Make functions.php easier to maintain

24. Make the theme or plugin ownership clear

Before adding a callback, ask whether it expresses this theme’s design or supplies a site-wide feature. Put design-dependent code with the theme; put behavior that should persist across theme changes in a plugin. This avoids making a theme switch unexpectedly remove a durable site feature.

25. Follow WordPress PHP coding and escaping conventions

Keep the code aligned with WordPress’s PHP coding standards, especially when outputting dynamic values in HTML or XML attributes. The standards reinforce context-aware escaping rather than treating printed data as automatically safe. WordPress PHP Coding Standards

Quick decision guide

Question Use
Should this behavior disappear when the theme changes? Theme code in functions.php or a theme helper file
Should this behavior remain when the theme changes? A plugin
Does this code need to run at a particular WordPress lifecycle point? An action or filter at the appropriate hook
Are you loading a front-end script or style? WordPress enqueue APIs on the appropriate hook
Are you printing a dynamic value? Escape it for its specific output context

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.