Prep Plugin for release on WordPress.org

Escape everything that should be escaped.
Add nonce checks where needed.
Sanitize all inputs.
Apply Code style changes across the codebase.
Correct many deprecation notices.
Optimize load order of many filters.
This commit is contained in:
David Stone
2025-04-07 09:15:21 -06:00
parent f05ab77418
commit a815fdf179
290 changed files with 2999 additions and 3269 deletions

View File

@ -21,14 +21,14 @@ if (isset($_GET['coupon']) && wu_get_coupon($_GET['coupon']) !== false && isset(
el: "#coupon-code-app",
data: {
coupon_id: '',
coupon: '<?php echo json_encode($coupon); ?>',
type : '<?php echo json_encode(get_post_meta($coupon->id, 'wpu_type', true)); ?>',
value : parseFloat(<?php echo json_encode(get_post_meta($coupon->id, 'wpu_value', true)); ?>),
applies_to_setup_fee : <?php echo json_encode(get_post_meta($coupon->id, 'wpu_applies_to_setup_fee', true)); ?>,
setup_fee_discount_value : parseFloat(<?php echo json_encode(get_post_meta($coupon->id, 'wpu_setup_fee_discount_value', true)); ?>),
setup_fee_discount_type : '<?php echo json_encode(get_post_meta($coupon->id, 'wpu_setup_fee_discount_type', true)); ?>',
allowed_plans : '<?php echo json_encode(get_post_meta($coupon->id, 'wpu_allowed_plans', true)); ?>',
allowed_freqs : '<?php echo json_encode(get_post_meta($coupon->id, 'wpu_allowed_freqs', true)); ?>',
coupon: '<?php echo wp_json_encode($coupon); ?>',
type : '<?php echo wp_json_encode(get_post_meta($coupon->id, 'wpu_type', true)); ?>',
value : parseFloat(<?php echo wp_json_encode(get_post_meta($coupon->id, 'wpu_value', true)); ?>),
applies_to_setup_fee : <?php echo wp_json_encode(get_post_meta($coupon->id, 'wpu_applies_to_setup_fee', true)); ?>,
setup_fee_discount_value : parseFloat(<?php echo wp_json_encode(get_post_meta($coupon->id, 'wpu_setup_fee_discount_value', true)); ?>),
setup_fee_discount_type : '<?php echo wp_json_encode(get_post_meta($coupon->id, 'wpu_setup_fee_discount_type', true)); ?>',
allowed_plans : '<?php echo wp_json_encode(get_post_meta($coupon->id, 'wpu_allowed_plans', true)); ?>',
allowed_freqs : '<?php echo wp_json_encode(get_post_meta($coupon->id, 'wpu_allowed_freqs', true)); ?>',
success: false,
},
mounted: function() {
@ -87,7 +87,7 @@ if (isset($_GET['coupon']) && wu_get_coupon($_GET['coupon']) !== false && isset(
$(this).find('h4').after('<div class="old-price">--</div>');
} // end if;
}
let plan_id = $(this).data('plan');
@ -104,7 +104,7 @@ if (isset($_GET['coupon']) && wu_get_coupon($_GET['coupon']) !== false && isset(
is_allowed_plan = true;
}
} // end for;
}
} else {
is_allowed_plan = true;
@ -120,7 +120,7 @@ if (isset($_GET['coupon']) && wu_get_coupon($_GET['coupon']) !== false && isset(
is_allowed_freq = true;
}
} // end for;
}
} else {
is_allowed_freq = true;
@ -131,7 +131,7 @@ if (isset($_GET['coupon']) && wu_get_coupon($_GET['coupon']) !== false && isset(
$("body").unblock();
return;
} // end if;
}
if (!is_allowed_freq) {
@ -172,7 +172,7 @@ if (isset($_GET['coupon']) && wu_get_coupon($_GET['coupon']) !== false && isset(
$(this).find('.old-price').html(accounting.formatMoney(parseFloat(old_price)));
if (!$(this).find('.off-value').get(0)) {
$(this).find('.old-price').after('<div class="off-value">(' + off_with_symbol + ' ' + '<?php _e('OFF', 'wp-multisite-waas'); ?>' + ')</div>');
$(this).find('.old-price').after('<div class="off-value">(' + off_with_symbol + ' ' + '<?php esc_html_e('OFF', 'wp-multisite-waas'); ?>' + ')</div>');
}
@ -185,7 +185,7 @@ if (isset($_GET['coupon']) && wu_get_coupon($_GET['coupon']) !== false && isset(
if (!$(this).find('.setupfee-off-value').get(0)) {
$(this).find('.pricing-table-setupfee').after('<span class="setupfee-off-value"> (' + setupfee_off_with_symbol + ' ' + '<?php _e('OFF', 'wp-multisite-waas'); ?>' + ')</span>');
$(this).find('.pricing-table-setupfee').after('<span class="setupfee-off-value"> (' + setupfee_off_with_symbol + ' ' + '<?php esc_html_e('OFF', 'wp-multisite-waas'); ?>' + ')</span>');
}
@ -215,7 +215,7 @@ if (isset($_GET['coupon']) && wu_get_coupon($_GET['coupon']) !== false && isset(
}
} // end if;
}
if (applies_to_setup_fee) {
@ -227,13 +227,13 @@ if (isset($_GET['coupon']) && wu_get_coupon($_GET['coupon']) !== false && isset(
new_setupfee = old_setupfee - parseFloat(setup_fee_discount_value);
} // end if;
}
} else {
new_setupfee = old_setupfee;
} // end if;
}
if (new_yearly_value > 0) {

View File

@ -22,5 +22,5 @@ if ( ! defined('ABSPATH')) {
?>
<div class="wu-setup-content-error">
<p><?php _e('There are no Plans created in the platform.', 'wp-multisite-waas'); ?></p><br>
<p><?php esc_html_e('There are no Plans created in the platform.', 'wp-multisite-waas'); ?></p><br>
</div>

View File

@ -33,7 +33,7 @@ $plan_attrs = '';
foreach ([1, 3, 12] as $type) {
$price = $plan->free ? __('Free!', 'wp-multisite-waas') : str_replace(wu_get_currency_symbol(), '', wu_format_currency((((float) $plan->{'price_' . $type}) / $type)));
$plan_attrs .= " data-price-$type='$price'";
} // end foreach;
}
$plan_attrs = apply_filters('wu_pricing_table_plan', $plan_attrs, $plan);
@ -53,7 +53,7 @@ $plan_attrs = apply_filters('wu_pricing_table_plan', $plan_attrs, $plan);
<?php if ($plan->is_free()) : ?>
<h5>
<span class="plan-price"><?php _e('Free!', 'wp-multisite-waas'); ?></span>
<span class="plan-price"><?php esc_html_e('Free!', 'wp-multisite-waas'); ?></span>
</h5>
<?php elseif ($plan->is_contact_us()) : ?>
@ -101,7 +101,7 @@ $plan_attrs = apply_filters('wu_pricing_table_plan', $plan_attrs, $plan);
} else {
echo "<li class='total-price total-price-$freq'>$text</li>";
}
} // end foreach;
}
/**
* Loop and Displays Pricing Table Lines

View File

@ -60,7 +60,7 @@ $accent_color_2 = wu_color($accent_color->darken(4));
*/
if ( ! isset($is_shortcode) || ! $is_shortcode || $atts['show_selector']) {
wu_get_template('/legacy/signup/pricing-table/frequency-selector');
} // end if;
}
/**
* Displays error message if there are no plans
@ -103,7 +103,7 @@ if (empty($plans)) {
'current_plan' => $current_plan,
]
);
} // end foreach;
}
?>

View File

@ -45,9 +45,9 @@ foreach ($admin_actions as $action => $handlers) {
foreach ($handlers as $handler => $priority) {
if ( ! has_action($action, $handler) && function_exists($handler)) {
add_action($action, $handler, $priority);
} // end foreach;
} // end foreach;
} // end foreach;
}
}
}
do_action('wu_checkout_scripts');

View File

@ -38,7 +38,7 @@ $nav_links = apply_filters(
if ( ! isset($signup->step)) {
return;
} // end if;
}
?>

View File

@ -21,7 +21,7 @@ if ( ! defined('ABSPATH')) {
if ( ! $signup) {
return;
} // end if;
}
?>
@ -52,7 +52,7 @@ $percent = 100 / $count;
$class = 'active';
} elseif (array_search($signup->step, array_keys($signup->steps)) > array_search($step_key, array_keys($signup->steps))) {
$class = 'done';
} // end if;
}
?>
@ -72,7 +72,7 @@ $percent = 100 / $count;
<a class="wu-signup-back-link" href="<?php echo $prev_link; ?>">
<?php _e('&larr; Go Back to Previous Step', 'wp-multisite-waas'); ?>
<?php esc_html_e('&larr; Go Back to Previous Step', 'wp-multisite-waas'); ?>
</a>

View File

@ -21,7 +21,7 @@ if ( ! defined('ABSPATH')) {
?>
<div class="wu-setup-content wu-content-<?php echo $signup->step; ?>">
<div class="wu-setup-content wu-content-<?php echo esc_attr($signup->step); ?>">
<!-- <p class="message" style="width: 320px; margin-left: auto; margin-right: auto; box-sizing: border-box;">
Please enter your username or email address. You will receive a link to create a new password via email.
@ -37,7 +37,7 @@ if ( ! defined('ABSPATH')) {
* Prints each of our fields using a helper function
*/
wu_print_signup_field($field_slug, $field, $results);
} // end foreach;
}
?>

View File

@ -23,7 +23,7 @@ if ( ! defined('ABSPATH')) {
<div id="wu-your-site-block">
<small><?php _e('Your URL will be', 'wp-multisite-waas'); ?></small><br>
<small><?php esc_html_e('Your URL will be', 'wp-multisite-waas'); ?></small><br>
<?php
/**