Prep Plugin for release on WordPress.org

Escape everything that should be escaped.
Add nonce checks where needed.
Sanitize all inputs.
Apply Code style changes across the codebase.
Correct many deprecation notices.
Optimize load order of many filters.
This commit is contained in:
David Stone
2025-04-07 09:15:21 -06:00
parent f05ab77418
commit a815fdf179
290 changed files with 2999 additions and 3269 deletions

View File

@ -47,7 +47,7 @@ wp_enqueue_script('wu-field-button-upload', WP_Ultimo()->get_asset("wu-field-ima
</a>
<a data-default="<?php echo $field['default']; ?>" href="#" class="button wu-field-button-upload-remove" data-target="<?php echo $field_slug; ?>">
<?php _e('Remove Image', 'wp-multisite-waas'); ?>
<?php esc_html_e('Remove Image', 'wp-multisite-waas'); ?>
</a>
<?php if ( ! empty($field['desc'])) : ?>

View File

@ -35,13 +35,13 @@
unset($_settings[ $key ]);
continue;
} // end if;
}
$value = $field['options'][ $key ];
} // end foreach;
}
$field['options'] = $_settings + $field['options'];
} // end if;
}
?>
@ -71,7 +71,7 @@
</div>
<button type="button" data-select-all="multiselect-<?php echo $field_slug; ?>" class="button wu-select-all"><?php _e('Check / Uncheck All', 'wp-multisite-waas'); ?></button>
<button type="button" data-select-all="multiselect-<?php echo $field_slug; ?>" class="button wu-select-all"><?php esc_html_e('Check / Uncheck All', 'wp-multisite-waas'); ?></button>
<br>

View File

@ -13,7 +13,7 @@
<label for="<?php echo esc_attr($field->id); ?>">
<?php echo $field->title; ?>
<?php echo esc_html($field->title); ?>
</label>
@ -21,17 +21,17 @@
<div class="wu-w-2/3">
<input <?php echo $field->html_attr ? $field->get_html_attributes() : ''; ?> <?php echo $field->disabled ? 'disabled="disabled"' : ''; ?> name="<?php echo esc_attr($field->id); ?>" type="<?php echo esc_attr($field->type); ?>" id="<?php echo esc_attr($field->id); ?>" class="regular-text" value="<?php echo wu_get_setting($field->id); ?>" placeholder="<?php echo $field->placeholder ?: ''; ?>">
<input <?php echo $field->html_attr ? $field->get_html_attributes() : ''; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?> <?php echo $field->disabled ? 'disabled="disabled"' : ''; ?> name="<?php echo esc_attr($field->id); ?>" type="<?php echo esc_attr($field->type); ?>" id="<?php echo esc_attr($field->id); ?>" class="regular-text" value="<?php echo esc_attr(wu_get_setting($field->id)); ?>" placeholder="<?php echo esc_attr($field->placeholder ?: ''); ?>">
<?php if (isset($field->append) && ! empty($field->append)) : ?>
<?php echo $field->append; ?>
<?php echo wp_kses_post($field->append); ?>
<?php endif; ?>
<?php if ($field->desc) : ?>
<p class="description" id="<?php echo $field->id; ?>-desc">
<p class="description" id="<?php echo esc_attr($field->id); ?>-desc">
<?php echo $field->desc; ?>
@ -43,6 +43,4 @@
</div>
<?php // if (isset($field['tooltip'])) {echo WU_Util::tooltip($field['tooltip']);} ?>
</div>