WordPress
Must-use plugin
Also called mu-plugin.
Must-use plugin is a PHP file placed in wp-content/mu-plugins that WordPress loads on every request without activation. Site owners cannot disable it from the Plugins screen.
How it is measured
WordPress scans the mu-plugins folder for .php files in the top level only and includes them in alphabetical order before regular plugins. Subfolders are ignored unless a loader file includes them. The folder path is the constant WPMU_PLUGIN_DIR.
The Plugins > Must-Use tab in wp-admin lists them. WP-CLI shows them with wp plugin list --status=must-use. They do not receive update notices from WordPress.org.
Worked example
A hosting company installs a file called 0-platform.php in mu-plugins on every customer site. It disables XML-RPC, sets the Heartbeat interval to 60 seconds, and blocks file editing in wp-admin. A customer deactivates all plugins to debug a white screen and the three settings still apply.
The same customer later wonders why xmlrpc.php returns 403 after switching plugins off. The answer is in the mu-plugins folder, which the Plugins list shows only under Must-Use.
How it differs
A must-use plugin is loaded automatically, while a regular plugin needs activating and can be turned off from the list. A normal plugin gets update checks and an install path, and an mu-plugin has neither. Use mu-plugins for site policy that must not be switched off, not for features a client may want to toggle.
Common errors
Dropping a folder in mu-plugins and expecting it to load. Forgetting a file is there while debugging a conflict. Putting something with frequent updates there and never updating it. Relying on load order without naming. Using it as a way to hide code from clients.
In practice
Open the Must-Use tab on every site you inherit and read each file. For your own code, use a single loader like 00-load.php that requires subfolder bootstrap files. Add a version comment to each file so you know when it last changed.