Add Admin Shortcuts to the WordPress Admin Bar

The WordPress admin bar is the one menu you see both on the front end and in wp-admin, yet the screens you open most, Plugins, Themes and Updates, are two or three clicks away from the front end. This snippet adds a single Shortcuts menu to the admin bar with those links, plus a link that opens a new Scripts Organizer code block.

Each link only appears for users who are allowed to use that screen, so editors and shop managers never see a link that ends on a “Sorry, you are not allowed” page.

The snippet

<?php
/**
 * Shortcuts menu in the admin bar.
 * Each link is shown only to users who can open its destination.
 */
add_action( 'admin_bar_menu', 'dpc_admin_bar_shortcuts', 100 );

function dpc_admin_bar_shortcuts( WP_Admin_Bar $admin_bar ): void {
	$links = array();

	$code_blocks = get_post_type_object( 'scorg' );
	if ( $code_blocks && current_user_can( $code_blocks->cap->create_posts ) ) {
		$links['dpc-shortcut-code-block'] = array(
			'title' => __( 'New Code Block', 'dpc' ),
			'url'   => admin_url( 'post-new.php?post_type=scorg' ),
		);
	}

	// Same check WordPress uses for the Updates screen.
	if ( current_user_can( 'update_core' ) || current_user_can( 'update_plugins' ) || current_user_can( 'update_themes' ) || current_user_can( 'update_languages' ) ) {
		$links['dpc-shortcut-updates'] = array(
			'title' => __( 'Updates', 'dpc' ),
			'url'   => is_multisite() ? network_admin_url( 'update-core.php' ) : admin_url( 'update-core.php' ),
		);
	}

	if ( current_user_can( 'activate_plugins' ) ) {
		$links['dpc-shortcut-plugins'] = array(
			'title' => __( 'Plugins', 'dpc' ),
			'url'   => admin_url( 'plugins.php' ),
		);
	}

	if ( current_user_can( 'switch_themes' ) ) {
		$links['dpc-shortcut-themes'] = array(
			'title' => __( 'Themes', 'dpc' ),
			'url'   => admin_url( 'themes.php' ),
		);
	}

	if ( empty( $links ) ) {
		return;
	}

	$admin_bar->add_node(
		array(
			'id'    => 'dpc-shortcuts',
			'title' => esc_html__( 'Shortcuts', 'dpc' ),
		)
	);

	// The admin bar escapes href itself; titles are printed as HTML, so escape them here.
	foreach ( $links as $id => $link ) {
		$admin_bar->add_node(
			array(
				'parent' => 'dpc-shortcuts',
				'id'     => $id,
				'title'  => esc_html( $link['title'] ),
				'href'   => $link['url'],
			)
		);
	}
}

How it works

  • admin_bar_menu passes the WP_Admin_Bar object to dpc_admin_bar_shortcuts(). Priority 100 runs after the core items, so the menu sits at the end of the bar.
  • Every link is gated by the capability WordPress itself checks on that screen: activate_plugins for Plugins, switch_themes for Themes, and for Updates any of update_core, update_plugins, update_themes or update_languages, the same check as the Updates screen.
  • The New Code Block link asks the scorg post type which capability creates a code block ($code_blocks->cap->create_posts), so it follows Scripts Organizer’s own permissions. When Scripts Organizer is not active the post type does not exist and the link is skipped.
  • On multisite the Updates link points to the network admin, where updates are managed.
  • Titles go through esc_html(), because the admin bar prints node titles as HTML. The parent node has no link, so it opens the dropdown on touch screens too.

Compared with the older One-Click Import version, the Oxygen and Code Snippets groups are gone, is_plugin_active() and the include of wp-admin/includes/plugin.php are no longer needed, and each link has its own capability check instead of one manage_options check for everything.

Add it with Scripts Organizer

In Scripts Organizer go to Code Blocks → Add New and give the block a name. Set Trigger location to Everywhere, tick PHP under Script location, paste the code into the PHP editor and publish. Leave Action/Hook empty. The admin bar shows on the front end as well as in wp-admin, so Admin only would hide the menu on the site itself. current_user_can() is only called inside the admin_bar_menu callback, after WordPress has loaded the current user.

The same code also works unchanged in a small plugin or an mu-plugin.

Customise it

  • Add a link: append another entry to $links with an id starting with dpc-shortcut-, a title and a url, wrapped in the capability check that screen uses. The admin bar escapes href itself; keep esc_html() on titles because they are printed as HTML.
  • Show the menu only on the front end: add if ( is_admin() ) { return; } as the first line of dpc_admin_bar_shortcuts().
  • Promote a link to the top level: remove the parent key from that node.

For one-off links, see Add link inside WP-Admin topbar and Add Media Link To Admin Bar.

Gotchas

  • Scripts Organizer has its own admin bar menu that lists every code block. Turn it on with Code Blocks in admin bar on the Scripts Organizer Features page. This snippet only adds the New Code Block link, so the two do not overlap.
  • The admin bar only renders on the front end when Show Toolbar when viewing site is ticked in the user’s profile.
  • Node ids must be unique across the whole bar. The dpc- prefix keeps them clear of core ids such as updates and themes.

In the Scripts Organizer library Import it with one click from Scripts Organizer.

// newsletter

Three tested WordPress snippets a week

Blocks, security, performance, Tailwind, PHP and React. Copy, paste, ship. You’ll also get DPlugins product updates. No spam, and you can unsubscribe anytime.

// newsletter

Three tested WordPress snippets a week

Blocks, security, performance, Tailwind, PHP and React. Copy, paste, ship. You'll also get DPlugins product updates. No spam, and you can unsubscribe anytime.