Changeset 15190
- Timestamp:
- 09/11/2026 06:56:36 PM (9 days ago)
- Location:
- sites/trunk
- Files:
-
- 187 edited
-
api.wordpress.org/public_html/core/browse-happy/1.0/index.php (modified) (2 diffs)
-
api.wordpress.org/public_html/core/browse-happy/1.0/test.php (modified) (2 diffs)
-
api.wordpress.org/public_html/core/credits/wp-credits.php (modified) (1 diff)
-
api.wordpress.org/public_html/core/importers/1.0/index.php (modified) (1 diff)
-
api.wordpress.org/public_html/core/serve-happy/1.0/index.php (modified) (1 diff)
-
api.wordpress.org/public_html/dotorg/github/activity.php (modified) (2 diffs)
-
api.wordpress.org/public_html/dotorg/helpscout/plugins-themes.php (modified) (2 diffs)
-
api.wordpress.org/public_html/dotorg/slack/community-deputies-calendly-webhook.php (modified) (1 diff)
-
api.wordpress.org/public_html/dotorg/slack/props.php (modified) (3 diffs)
-
api.wordpress.org/public_html/dotorg/slack/security-team.php (modified) (1 diff)
-
api.wordpress.org/public_html/dotorg/trac/oembed/index.php (modified) (3 diffs)
-
api.wordpress.org/public_html/dotorg/trac/pr/class-trac.php (modified) (1 diff)
-
api.wordpress.org/public_html/themes/info/1.0/index.php (modified) (3 diffs)
-
api.wordpress.org/public_html/themes/info/1.1/index.php (modified) (1 diff)
-
api.wordpress.org/public_html/themes/theme-directory/1.0/index.php (modified) (1 diff)
-
api.wordpress.org/public_html/translations/plugins/1.0/index.php (modified) (1 diff)
-
api.wordpress.org/public_html/translations/themes/1.0/index.php (modified) (1 diff)
-
browsehappy.com/public_html/functions.php (modified) (1 diff)
-
browsehappy.com/public_html/index.php (modified) (4 diffs)
-
buddypress.org/public_html/wp-content/themes/bb-base/functions.php (modified) (2 diffs)
-
common/includes/profiles/profiles.php (modified) (1 diff)
-
common/includes/slack/announce/lib.php (modified) (3 diffs)
-
common/includes/slack/props/lib.php (modified) (2 diffs)
-
common/includes/wporg-sso/class-wporg-sso.php (modified) (1 diff)
-
common/includes/wporg-sso/wp-plugin.php (modified) (1 diff)
-
environments/plugin-directory/bin/import-plugins.php (modified) (5 diffs)
-
global.wordpress.org/public_html/wp-content/mu-plugins/downloads/rosetta-downloads.php (modified) (1 diff)
-
global.wordpress.org/public_html/wp-content/mu-plugins/roles/class-translation-editors-list-table.php (modified) (5 diffs)
-
global.wordpress.org/public_html/wp-content/mu-plugins/roles/views/cross-locale-pte.php (modified) (1 diff)
-
global.wordpress.org/public_html/wp-content/mu-plugins/roles/views/edit-cross-locale-pte.php (modified) (2 diffs)
-
global.wordpress.org/public_html/wp-content/mu-plugins/roles/views/edit-translation-editor.php (modified) (2 diffs)
-
global.wordpress.org/public_html/wp-content/mu-plugins/roles/views/translation-editors.php (modified) (1 diff)
-
global.wordpress.org/public_html/wp-content/mu-plugins/showcase/rosetta-showcase.php (modified) (1 diff)
-
global.wordpress.org/public_html/wp-content/themes/rosetta/download.php (modified) (1 diff)
-
global.wordpress.org/public_html/wp-content/themes/rosetta/footer.php (modified) (1 diff)
-
global.wordpress.org/public_html/wp-content/themes/rosetta/front-page.php (modified) (2 diffs)
-
global.wordpress.org/public_html/wp-content/themes/rosetta/header.php (modified) (1 diff)
-
global.wordpress.org/public_html/wp-content/themes/rosetta/inc/template-tags.php (modified) (2 diffs)
-
jobs.wordpress.net/public_html/wp-content/plugins/jobswp/jobswp-template.php (modified) (2 diffs)
-
jobs.wordpress.net/public_html/wp-content/plugins/jobswp/jobswp.php (modified) (1 diff)
-
jobs.wordpress.net/public_html/wp-content/themes/jobswp/content-list.php (modified) (2 diffs)
-
jobs.wordpress.net/public_html/wp-content/themes/jobswp/inc/template-tags.php (modified) (1 diff)
-
phpcs.xml.dist (modified) (2 diffs)
-
profiles.wordpress.org/public_html/wp-content/plugins/wporg-profiles-activity-handler/wporg-profiles-activity-handler.php (modified) (4 diffs)
-
profiles.wordpress.org/public_html/wp-content/plugins/wporg-profiles-association-handler/wporg-profiles-association-handler.php (modified) (1 diff)
-
profiles.wordpress.org/public_html/wp-content/plugins/wporg-profiles-profile-handler/wporg-profiles-handler.php (modified) (2 diffs)
-
trac.wordpress.org/bin/mysql-migrate.php (modified) (1 diff)
-
trac.wordpress.org/bin/sqlite-migrate.php (modified) (2 diffs)
-
wordpress.org/public_html/wp-content/mu-plugins/pub/wporg-redirects.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/mu-plugins/pub/wporg-seo/robots.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/mu-plugins/pub/wporg-well-known.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/plugins/handbook/inc/admin-notices.php (modified) (4 diffs)
-
wordpress.org/public_html/wp-content/plugins/handbook/inc/glossary.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/plugins/handbook/inc/widgets.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/plugins/handbook/phpunit/bootstrap.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/plugins/official-wordpress-events/official-wordpress-events.php (modified) (3 diffs)
-
wordpress.org/public_html/wp-content/plugins/phpunit-test-reporter/parts/result-set-all.php (modified) (3 diffs)
-
wordpress.org/public_html/wp-content/plugins/phpunit-test-reporter/parts/result-set-single.php (modified) (2 diffs)
-
wordpress.org/public_html/wp-content/plugins/phpunit-test-reporter/parts/single-result.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/plugins/plugin-directory/admin/metabox/class-support-reps.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/plugins/plugin-directory/api/routes/class-locale-banner.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/plugins/plugin-directory/api/routes/class-plugin-blueprint.php (modified) (3 diffs)
-
wordpress.org/public_html/wp-content/plugins/plugin-directory/api/routes/class-plugin.php (modified) (3 diffs)
-
wordpress.org/public_html/wp-content/plugins/plugin-directory/api/routes/class-svn-access.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/plugins/plugin-directory/bin/check-block.php (modified) (2 diffs)
-
wordpress.org/public_html/wp-content/plugins/plugin-directory/bin/email-bulk-security-vulnerabilities.php (modified) (4 diffs)
-
wordpress.org/public_html/wp-content/plugins/plugin-directory/bin/import-plugin-to-glotpress.php (modified) (3 diffs)
-
wordpress.org/public_html/wp-content/plugins/plugin-directory/bin/import-plugin.php (modified) (2 diffs)
-
wordpress.org/public_html/wp-content/plugins/plugin-directory/bin/process-blocks.php (modified) (2 diffs)
-
wordpress.org/public_html/wp-content/plugins/plugin-directory/bin/quick-stats.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/plugins/plugin-directory/bin/rebuild-update_source-table.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/plugins/plugin-directory/bin/rebuild-zip.php (modified) (2 diffs)
-
wordpress.org/public_html/wp-content/plugins/plugin-directory/bin/resync-ratings.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/plugins/plugin-directory/class-plugin-directory.php (modified) (2 diffs)
-
wordpress.org/public_html/wp-content/plugins/plugin-directory/class-plugin-search.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/plugins/plugin-directory/class-template.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/plugins/plugin-directory/cli/class-import.php (modified) (9 diffs)
-
wordpress.org/public_html/wp-content/plugins/plugin-directory/cli/class-svn-watcher.php (modified) (2 diffs)
-
wordpress.org/public_html/wp-content/plugins/plugin-directory/cli/i18n/class-code-import.php (modified) (3 diffs)
-
wordpress.org/public_html/wp-content/plugins/plugin-directory/cli/i18n/class-readme-import.php (modified) (2 diffs)
-
wordpress.org/public_html/wp-content/plugins/plugin-directory/jobs/class-plugin-scan.php (modified) (6 diffs)
-
wordpress.org/public_html/wp-content/plugins/plugin-directory/shortcodes/class-upload-handler.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/plugins/plugin-directory/standalone/class-plugins-info-api.php (modified) (9 diffs)
-
wordpress.org/public_html/wp-content/plugins/plugin-directory/tests/bootstrap.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/plugins/plugin-directory/tests/wporg-plugin-api-performance.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/plugins/plugin-directory/zip/class-builder.php (modified) (4 diffs)
-
wordpress.org/public_html/wp-content/plugins/plugin-directory/zip/class-serve.php (modified) (3 diffs)
-
wordpress.org/public_html/wp-content/plugins/support-forums/inc/class-ratings-compat.php (modified) (2 diffs)
-
wordpress.org/public_html/wp-content/plugins/support-helphub/inc/helphub-front-page-blocks/includes/widget-front-end.php (modified) (2 diffs)
-
wordpress.org/public_html/wp-content/plugins/support-helphub/inc/helphub-manager/class-helphub-manager.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/plugins/support-helphub/inc/helphub-post-types/classes/class-helphub-post-types-post-type.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/plugins/theme-directory/admin-edit.php (modified) (2 diffs)
-
wordpress.org/public_html/wp-content/plugins/theme-directory/class-wporg-themes-upload.php (modified) (2 diffs)
-
wordpress.org/public_html/wp-content/plugins/theme-directory/jobs/class-svn-import.php (modified) (2 diffs)
-
wordpress.org/public_html/wp-content/plugins/theme-directory/rest-api.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/plugins/theme-directory/rest-api/class-internal.php (modified) (2 diffs)
-
wordpress.org/public_html/wp-content/plugins/theme-directory/theme-directory.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/plugins/wp-i18n-teams/views/all-locales.php (modified) (6 diffs)
-
wordpress.org/public_html/wp-content/plugins/wp-i18n-teams/views/locale-details.php (modified) (5 diffs)
-
wordpress.org/public_html/wp-content/plugins/wporg-badge-management/admin.php (modified) (2 diffs)
-
wordpress.org/public_html/wp-content/plugins/wporg-bbp-term-subscription/inc/class-plugin.php (modified) (2 diffs)
-
wordpress.org/public_html/wp-content/plugins/wporg-bbp-topic-resolution/inc/class-plugin.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/plugins/wporg-bbp-user-badges/inc/class-plugin.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/plugins/wporg-cli/inc/class-markdown-import.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/plugins/wporg-github-invite/admin.php (modified) (3 diffs)
-
wordpress.org/public_html/wp-content/plugins/wporg-gp-customizations/inc/cli/class-duplicate-translations.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/plugins/wporg-gp-customizations/templates/footer.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/plugins/wporg-gp-customizations/templates/header.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/plugins/wporg-gp-help/wporg-gp-help.php (modified) (2 diffs)
-
wordpress.org/public_html/wp-content/plugins/wporg-gp-profiles/tests/e2e.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/plugins/wporg-gp-rosetta-roles/inc/admin/list-table/class-translators.php (modified) (5 diffs)
-
wordpress.org/public_html/wp-content/plugins/wporg-gp-translation-suggestions/templates/other-languages-suggestions.php (modified) (3 diffs)
-
wordpress.org/public_html/wp-content/plugins/wporg-gp-translation-suggestions/templates/translation-memory-suggestions.php (modified) (2 diffs)
-
wordpress.org/public_html/wp-content/plugins/wporg-markdown/inc/class-editor.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/plugins/wporg-profiles-wp-activity-notifier/tests/e2e.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/plugins/wporg-trac-watcher/svn.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-breathe-2024/archive-component.php (modified) (2 diffs)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-breathe-2024/footer.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-breathe-2024/functions.php (modified) (2 diffs)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-breathe-2024/header.php (modified) (2 diffs)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-breathe-2024/o2-comment.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-login/functions-registration.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-main/front-page.php (modified) (5 diffs)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-main/header-child-page.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-main/header-top-level-page.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-main/page-about-requirements.php (modified) (3 diffs)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-main/page-download.php (modified) (2 diffs)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-main/page-hosting.php (modified) (4 diffs)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-openverse/header.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/build/blocks/archive-page/render.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/build/blocks/category-navigation/render.php (modified) (2 diffs)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/build/blocks/filter-bar/render.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/build/blocks/front-page/render.php (modified) (3 diffs)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/build/blocks/plugin-card/render.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/build/blocks/search-page/render.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/embed-plugin.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/inc/template-tags.php (modified) (5 diffs)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/src/blocks/archive-page/render.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/src/blocks/category-navigation/render.php (modified) (2 diffs)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/src/blocks/filter-bar/render.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/src/blocks/front-page/render.php (modified) (3 diffs)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/src/blocks/plugin-card/render.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/src/blocks/search-page/render.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/template-parts/plugin-single.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/template-parts/section-blocks.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/template-parts/section.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-showcase/404.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-showcase/comments.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-showcase/feed-extras.php (modified) (3 diffs)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-showcase/footer.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-showcase/functions.php (modified) (2 diffs)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-showcase/header.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-showcase/page-submit.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-showcase/single.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-support-2024/archive-forum.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-support-2024/archive.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-support-2024/bbpress/form-topic.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-support-2024/bbpress/loop-forums-homepage.php (modified) (2 diffs)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-support-2024/bbpress/loop-single-forum-homepage.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-support-2024/footer.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-support-2024/front-page.php (modified) (2 diffs)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-support-2024/functions.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-support-2024/header.php (modified) (6 diffs)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-support-2024/page-homepage.php (modified) (2 diffs)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-support-2024/sidebar.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg-support-2024/template-parts/content-page.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg/bin/build.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg/comments.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg/footer-wporg.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg/footer.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg/header-wporg.php (modified) (1 diff)
-
wordpress.org/public_html/wp-content/themes/pub/wporg/inc/template-tags.php (modified) (5 diffs)
-
wordpress.tv/public_html/wp-content/themes/wptv2/anon-upload-template.php (modified) (4 diffs)
-
wordpress.tv/public_html/wp-content/themes/wptv2/archive.php (modified) (2 diffs)
-
wordpress.tv/public_html/wp-content/themes/wptv2/footer.php (modified) (1 diff)
-
wordpress.tv/public_html/wp-content/themes/wptv2/functions.php (modified) (6 diffs)
-
wordpress.tv/public_html/wp-content/themes/wptv2/plugins/wordpresstv-anon-upload/anon-upload.php (modified) (4 diffs)
-
wordpress.tv/public_html/wp-content/themes/wptv2/plugins/wordpresstv-oembed/wordpresstv-oembed.php (modified) (1 diff)
-
wordpress.tv/public_html/wp-content/themes/wptv2/plugins/wordpresstv-rest/wordpresstv-rest.php (modified) (1 diff)
-
wordpress.tv/public_html/wp-content/themes/wptv2/plugins/wordpresstv-unisubs/wordpresstv-unisubs.php (modified) (1 diff)
-
wordpress.tv/public_html/wp-content/themes/wptv2/plugins/wordpresstv-upload-subtitles/wordpresstv-upload-subtitles.php (modified) (2 diffs)
-
wordpress.tv/public_html/wp-content/themes/wptv2/upload-subtitles-template.php (modified) (2 diffs)
-
wp15.wordpress.net/public_html/content/mu-plugins/locales.php (modified) (1 diff)
-
wp15.wordpress.net/public_html/content/plugins/wp15-meetup-events/libraries/class-meetup-client.php (modified) (3 diffs)
-
wp15.wordpress.net/public_html/content/plugins/wp15-meetup-events/wp15-meetup-events.php (modified) (1 diff)
-
wp15.wordpress.net/public_html/content/themes/twentyseventeen-wp15/functions.php (modified) (1 diff)
-
wp15.wordpress.net/public_html/content/themes/twentyseventeen-wp15/page-swag.php (modified) (1 diff)
Legend:
- Unmodified
- Added
- Removed
-
sites/trunk/api.wordpress.org/public_html/core/browse-happy/1.0/index.php
r13103 r15190 27 27 if ( $jsonp ) { 28 28 header( 'Access-Control-Allow-Origin: *' ); 29 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- API response body (JSONP or serialized PHP); escaping would corrupt the format. 29 30 echo $jsonp.'('.json_encode($data).')'; 30 31 } elseif ( defined( 'JSON_RESPONSE' ) ) { … … 34 35 } else { 35 36 header( 'Content-Type: text/plain' ); 37 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- API response body (JSONP or serialized PHP); escaping would corrupt the format. 36 38 echo serialize( $data ); 37 39 } -
sites/trunk/api.wordpress.org/public_html/core/browse-happy/1.0/test.php
r1 r15190 1 1 <?php 2 2 3 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Standalone script; WordPress is never loaded here, so esc_html() does not exist. 3 4 echo htmlspecialchars( $_SERVER['HTTP_USER_AGENT'], ENT_QUOTES ) . "<br/><br/>"; 4 5 … … 8 9 9 10 foreach ( $output as $k => $v ) 11 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Standalone script; WordPress is never loaded here, so esc_html() does not exist. 10 12 echo htmlspecialchars( $k . ' = ' . ( is_bool( $v ) ? (int) $v : $v ), ENT_QUOTES ) . "<br/>"; -
sites/trunk/api.wordpress.org/public_html/core/credits/wp-credits.php
r15086 r15190 449 449 echo json_encode( $results ); 450 450 } else { 451 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- API response body (serialized PHP); escaping would corrupt the format. 451 452 echo serialize( $results ); 452 453 } -
sites/trunk/api.wordpress.org/public_html/core/importers/1.0/index.php
r13762 r15190 22 22 23 23 $response = array( 'importers' => $popular_importers, 'translated' => false ); 24 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- API response body (JSON or serialized PHP); escaping would corrupt the format. 24 25 echo defined( 'JSON_RESPONSE' ) ? json_encode( $response ) : serialize( $response ); 25 26 -
sites/trunk/api.wordpress.org/public_html/core/serve-happy/1.0/index.php
r13102 r15190 44 44 45 45 echo '/**/' . 46 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- JSONP callback name, restricted to [a-zA-Z0-9_.] inline. 46 47 preg_replace('/[^a-zA-Z0-9_.]/', '', $_GET['callback'] ) . 48 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- JSONP response body; json_encode() output, which an HTML escaper would corrupt. 47 49 '(' . $json_data . ')'; 48 50 } else { 49 51 call_headers( 'application/json' ); 50 52 53 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- JSON response body; json_encode() output, which an HTML escaper would corrupt. 51 54 echo $json_data; 52 55 } -
sites/trunk/api.wordpress.org/public_html/dotorg/github/activity.php
r11276 r15190 164 164 if ( ! in_array( $payload->action, [ 'opened', 'edited', 'closed', 'deleted' ] ) ) { 165 165 header( 'HTTP/1.0 422 Unprocessable Entity', true, 422 ); 166 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Plain-text webhook acknowledgement; the payload is signature-verified upstream. 166 167 die( "NO; $event:{$payload->action} not required." ); 167 168 } … … 216 217 if ( ! in_array( $payload->action, [ 'opened', 'reopened', 'edited', 'closed' ] ) ) { 217 218 header( 'HTTP/1.0 422 Unprocessable Entity', true, 422 ); 219 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Plain-text webhook acknowledgement; the payload is signature-verified upstream. 218 220 die( "NO; $event:{$payload->action} not required." ); 219 221 } -
sites/trunk/api.wordpress.org/public_html/dotorg/helpscout/plugins-themes.php
r14337 r15190 67 67 68 68 if ( $post_ids ) { 69 echo '<p><strong>' . ucwords( $type) . ' mentioned in this email:</strong></p>';69 echo '<p><strong>' . esc_html( ucwords( $type ) ) . ' mentioned in this email:</strong></p>'; 70 70 71 71 display_items( $post_ids ); … … 85 85 if ( $items ) { 86 86 $url = add_query_arg( [ 'post_type' => $repo_post_types[ $type ], 'author' => $user->ID ], admin_url( 'edit.php' ) ); 87 echo '<p><strong><a href="' . esc_url( $url ) . '">' . ucwords( $type) . ' owned by this user:</a></strong></p>';87 echo '<p><strong><a href="' . esc_url( $url ) . '">' . esc_html( ucwords( $type ) ) . ' owned by this user:</a></strong></p>'; 88 88 89 89 display_items( $items ); -
sites/trunk/api.wordpress.org/public_html/dotorg/slack/community-deputies-calendly-webhook.php
r15087 r15190 41 41 'The Calendly token has probably been revoked, the password was probably changed.' . 42 42 'Please update the COMMUNITY_CALENDLY_TOKEN secrets constant with a new PAT created on https://calendly.com/integrations/api_webhooks from the WordCamp Calendly account.' . 43 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Written to the error log by trigger_error(), not rendered. 43 44 wp_remote_retrieve_body( $req ), 44 45 E_USER_WARNING -
sites/trunk/api.wordpress.org/public_html/dotorg/slack/props.php
r12395 r15190 41 41 header( 'X-Slack-No-Retry', 1 ); // Don't retry this event again. 42 42 trigger_error( 43 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Written to the error log, or returned to Slack as the plain-text challenge response. 43 44 sprintf( 'Received retry for %s because: %s', $message_id, $headers['X-Slack-Retry-Reason'] ), 44 45 E_USER_NOTICE … … 52 53 53 54 } catch ( Exception $exception ) { 55 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Written to the error log, or returned to Slack as the plain-text challenge response. 54 56 trigger_error( $exception->getMessage(), E_USER_WARNING ); 55 57 … … 60 62 */ 61 63 http_response_code( 200 ); 64 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Written to the error log, or returned to Slack as the plain-text challenge response. 62 65 die( $result ); 63 66 } -
sites/trunk/api.wordpress.org/public_html/dotorg/slack/security-team.php
r15087 r15190 96 96 } 97 97 98 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Plain-text response listing usernames; the trailing newline is significant. 98 99 echo implode( "\n", $team ) . "\n"; // Trailing newline critical. 99 100 exit; -
sites/trunk/api.wordpress.org/public_html/dotorg/trac/oembed/index.php
r15149 r15190 160 160 $cache_key = sha1( $url ); 161 161 if ( $data = wp_cache_get( $cache_key, 'trac-oembed' ) ) { 162 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- oEmbed response body (JSON or XML); escaping would corrupt the format. 162 163 die( $data ); 163 164 } … … 192 193 $output = '<h1>Temporarily Unavailable</h1>'; 193 194 wp_cache_set( $cache_key, $output, 'trac-oembed', MINUTE_IN_SECONDS ); 195 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- oEmbed response body (JSON or XML); escaping would corrupt the format. 194 196 die( $output ); 195 197 } … … 357 359 wp_cache_set( $cache_key, $data, 'trac-oembed', HOUR_IN_SECONDS ); 358 360 361 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- oEmbed response body (JSON or XML); escaping would corrupt the format. 359 362 echo $data; -
sites/trunk/api.wordpress.org/public_html/dotorg/trac/pr/class-trac.php
r14781 r15190 149 149 150 150 } elseif ( $json && isset( $json->error ) ) { 151 // phpcs:ignore WordPress.Security.EscapeOutput.ExceptionNotEscaped -- Trac API client; the message is caught by the calling method, not rendered. 151 152 throw new \Exception( 'JSON Error: ' . $json->error->code . ' ' . $json->error->message ); 152 153 } elseif ( ! $json ) { -
sites/trunk/api.wordpress.org/public_html/themes/info/1.0/index.php
r14891 r15190 31 31 ) { 32 32 header( 'Content-Type: text/html; charset=utf-8' ); 33 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Themes API response body in the requested format; escaping would corrupt it. 33 34 die( "<p>{$error}</p>" ); 34 35 } … … 43 44 44 45 if ( 'php' === $format ) { 46 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Themes API response body in the requested format; escaping would corrupt it. 45 47 echo serialize( $response ); 46 48 } else { … … 141 143 $api->set_status_header(); 142 144 145 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Themes API response body in the requested format; escaping would corrupt it. 143 146 echo $api->get_result( $format ); 144 147 -
sites/trunk/api.wordpress.org/public_html/themes/info/1.1/index.php
r14799 r15190 21 21 if ( $callback ) { 22 22 header( 'Content-Type: text/javascript; charset=UTF-8' ); 23 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Themes API response body (JSONP or JSON); escaping would corrupt the format. 23 24 echo "$callback($response);"; 24 25 } else { 25 26 header( 'Content-Type: application/json; charset=UTF-8' ); 27 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Themes API response body (JSONP or JSON); escaping would corrupt the format. 26 28 echo $response; 27 29 } -
sites/trunk/api.wordpress.org/public_html/themes/theme-directory/1.0/index.php
r12632 r15190 33 33 if ( $callback ) { 34 34 header( 'Content-Type:application/javascript; charset=' . get_option( 'blog_charset' ) ); 35 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Themes API response body (JSONP or JSON); escaping would corrupt the format. 35 36 echo "$callback( $json );"; 36 37 } else { 37 38 header( 'Content-Type: application/json; charset=' . get_option( 'blog_charset' ) ); 39 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Themes API response body (JSONP or JSON); escaping would corrupt the format. 38 40 echo $json; 39 41 } -
sites/trunk/api.wordpress.org/public_html/translations/plugins/1.0/index.php
r10998 r15190 14 14 if ( $$field && ! is_string( $$field ) ) { 15 15 header( $_SERVER['SERVER_PROTOCOL'] . ' 400 Bad Request' ); 16 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Field name comes from the literal list iterated above, not from the request. 16 17 die( "?{$field}= invalid." ); 17 18 } -
sites/trunk/api.wordpress.org/public_html/translations/themes/1.0/index.php
r10998 r15190 14 14 if ( $$field && ! is_string( $$field ) ) { 15 15 header( $_SERVER['SERVER_PROTOCOL'] . ' 400 Bad Request' ); 16 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Field name comes from the literal list iterated above, not from the request. 16 17 die( "?{$field}= invalid." ); 17 18 } -
sites/trunk/browsehappy.com/public_html/functions.php
r15179 r15190 100 100 101 101 function browsehappy_echo_version( $browser ) { 102 echo browsehappy_fetch_version( $browser);102 echo esc_html( browsehappy_fetch_version( $browser ) ); 103 103 } 104 104 -
sites/trunk/browsehappy.com/public_html/index.php
r15179 r15190 43 43 <ul id="browserlist" class="wrap"> 44 44 <?php foreach ( browsehappy_get_browser_data() as $browser => $data ) : ?> 45 <li id="<?php echo $browser; ?>">45 <li id="<?php echo esc_attr( $browser ); ?>"> 46 46 <a href="<?php echo esc_url( $data->url ); ?>" title="<?php echo esc_attr( $data->long_name ); ?>"> 47 47 <div class="icon"></div> 48 <h2 lang="en"><?php echo $data->name; ?></h2>49 <p class="info"><?php echo $data->info; ?></p>48 <h2 lang="en"><?php echo esc_html( $data->name ); ?></h2> 49 <p class="info"><?php echo esc_html( $data->info ); ?></p> 50 50 <?php /* translators: %s: Browser version. */ ?> 51 51 <p class="version"><?php printf( esc_html__( 'Latest Version: %s', 'browsehappy' ), '<strong>' . esc_html( apply_filters( 'get_browsehappy_version', $browser ) ) . '</strong>' ); ?></p> … … 53 53 </a> 54 54 <?php do_action( 'browsehappy_browser_after', $browser ); ?> 55 </li><!-- #<?php echo $browser; ?> -->55 </li><!-- #<?php echo esc_html( $browser ); ?> --> 56 56 <?php endforeach; ?> 57 57 </ul><!-- #browserlist --> … … 62 62 <section id="about"> 63 63 <h2><?php esc_html_e( 'What is Browse Happy?', 'browsehappy' ); ?></h2> 64 < p><?php $what = __( 'Using an outdated browser makes your computer unsafe. Browse Happy is a way for you to find out what are the latest versions of the major browsers around. You can also learn about alternative browsers that may fit you even better than the one you are currently using.', 'browsehappy' );65 echo $what; ?></p>64 <?php $what = __( 'Using an outdated browser makes your computer unsafe. Browse Happy is a way for you to find out what are the latest versions of the major browsers around. You can also learn about alternative browsers that may fit you even better than the one you are currently using.', 'browsehappy' ); ?> 65 <p><?php echo esc_html( $what ); ?></p> 66 66 </section><!-- #about --> 67 67 <section id="share"> … … 91 91 if ( isset( $_GET['locale'] ) ) 92 92 $redirect_uri = add_query_arg( 'locale', urlencode( $_GET['locale'] ), $redirect_uri ); 93 $facebook_pieces = array( 94 'app_id=180651631983617', // Browse Happy app 95 'link=' . home_url( '/' ), 96 'picture=' . get_template_directory_uri() . '/imgs/apple-touch-icon-114x114.png', 97 'name=' . urlencode( __( 'Browse Happy', 'browsehappy' ) ), 98 'description=' . urlencode( $what ), 99 'message=' . urlencode( __( 'Online. Worry-free. Upgrade your browser today!', 'browsehappy' ) ), 100 'display=popup', 101 'redirect_uri=' . $redirect_uri, 93 94 $facebook_args = array( 95 'app_id' => '180651631983617', // Browse Happy app. 96 'link' => home_url( '/' ), 97 'picture' => get_template_directory_uri() . '/imgs/apple-touch-icon-114x114.png', 98 'name' => __( 'Browse Happy', 'browsehappy' ), 99 'description' => $what, 100 'message' => __( 'Online. Worry-free. Upgrade your browser today!', 'browsehappy' ), 101 'display' => 'popup', 102 'redirect_uri' => $redirect_uri, 102 103 ); 104 105 // add_query_arg() leaves the values it is given alone, so they are encoded here. 106 $facebook_url = add_query_arg( rawurlencode_deep( $facebook_args ), 'https://www.facebook.com/dialog/feed' ); 103 107 ?> 104 <li class="facebook"><a onclick="window.open(this.href, 'fbshare', 'status=0,toolbar=0,location=0,menubar=0,directories=0,resizable=0,scrollbars=0,height=325,width=540'); return false;" href=" https://www.facebook.com/dialog/feed?<?php echo implode( '&', $facebook_pieces); ?>" title="<?php esc_attr_e( 'Share on Facebook', 'browsehappy' ); ?>">Facebook</a></li>108 <li class="facebook"><a onclick="window.open(this.href, 'fbshare', 'status=0,toolbar=0,location=0,menubar=0,directories=0,resizable=0,scrollbars=0,height=325,width=540'); return false;" href="<?php echo esc_url( $facebook_url ); ?>" title="<?php esc_attr_e( 'Share on Facebook', 'browsehappy' ); ?>">Facebook</a></li> 105 109 </ul> 106 110 </nav> -
sites/trunk/buddypress.org/public_html/wp-content/themes/bb-base/functions.php
r15188 r15190 425 425 */ 426 426 function bb_base_homepage_topics( $args = false ) { 427 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Buffered bbPress loop-topics template part; escaping would print the rendered markup. 427 428 echo bb_base_get_homepage_topics( $args ); 428 429 } … … 497 498 */ 498 499 function bb_base_support_topics() { 500 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Buffered bbPress content-archive-topic template part; escaping would print the rendered markup. 499 501 echo bb_base_get_support_topics(); 500 502 } -
sites/trunk/common/includes/profiles/profiles.php
r12255 r15190 67 67 } finally { 68 68 if ( $error ) { 69 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Written to the error log by trigger_error(), not rendered. 69 70 trigger_error( $error, E_USER_WARNING ); 70 71 } -
sites/trunk/common/includes/slack/announce/lib.php
r14899 r15190 108 108 $channels = array_filter( $channels, function( $c ) use ( $channel ) { return $c !== $channel; } ); 109 109 if ( $channels ) { 110 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Plain-text response body, not HTML. 110 111 printf( "You are allowed to use these commands in #%s (also %s).", $channel, '#' . implode( ' #', $channels ) ); 111 112 } else { 113 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Plain-text response body, not HTML. 112 114 echo "You are allowed to use these commands in in #$channel."; 113 115 } 114 116 } else { 117 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Plain-text response body, not HTML. 115 118 printf( "You are not allowed to use these commands in #%s, but you are in #%s.", $channel, implode( ' #', $channels ) ); 116 119 } … … 118 121 echo "\n"; 119 122 123 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Plain-text response body, not HTML. 120 124 printf( "If you are a team lead and need to be granted access, contact an admin in <#%s|%s> for assistance.\n", SLACKHELP_CHANNEL_ID, SLACKHELP_CHANNEL_NAME ); 125 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Plain-text response body, not HTML. 121 126 printf( "Your linked WordPress.org account that needs to be granted access is '%s'.", $user ); 122 127 } … … 256 261 257 262 if ( str_word_count( $data['text'] ) <= 2 ) { 263 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Plain-text response body, not HTML. 258 264 printf( "When making announcements, please use a descriptive message for notifications. %s is too short.", $data['text'] ); 259 265 return; -
sites/trunk/common/includes/slack/props/lib.php
r12396 r15190 23 23 // Don't throw if a recipient lookup fails, since we still want other recipients to get props. 24 24 if ( empty( $giver_user ) ) { 25 // phpcs:ignore WordPress.Security.EscapeOutput.ExceptionNotEscaped -- Slack request handler; the message is returned to Slack as plain text, not rendered as HTML. 25 26 throw new Exception( 'w.org user lookup for slack ID '. $request->event->user .' failed' ); 26 27 } … … 240 241 $success = false; 241 242 243 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Plain-text response body, not HTML. 242 244 trigger_error( 'Adding activity failed with error: ' . $response_body, E_USER_WARNING ); 243 245 } -
sites/trunk/common/includes/wporg-sso/class-wporg-sso.php
r14486 r15190 291 291 '<meta http-equiv="refresh" content="1;url=%1$s" />' . 292 292 '<a href="%1$s">%1$s</a>', 293 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Escaped above, with a fallback for environments without WordPress helpers. 293 294 $to 294 295 ); -
sites/trunk/common/includes/wporg-sso/wp-plugin.php
r15178 r15190 607 607 sprintf( 608 608 "<h1>Logged in!</h1><p>You are currently logged in as <code>%s</code>.</p><p><a href='%s'>Would you like to logout?</a>", 609 wp_get_current_user()->user_login,609 esc_html( wp_get_current_user()->user_login ), 610 610 esc_url( wp_logout_url() ) 611 611 ) -
sites/trunk/environments/plugin-directory/bin/import-plugins.php
r14720 r15190 223 223 224 224 foreach ( $browse_sections as $section ) { 225 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI import progress written to the console, not HTML. 225 226 echo "Fetching plugins in '{$section}' section...\n"; 226 227 … … 240 241 $missing = array_diff( $batch, array_keys( $batch_data ) ); 241 242 if ( $missing ) { 243 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI import progress written to the console, not HTML. 242 244 echo " Skipped (not found): " . implode( ', ', $missing ) . "\n"; 243 245 } … … 256 258 if ( $existing ) { 257 259 wp_set_object_terms( $existing[0]->ID, $section, 'plugin_section', true ); 260 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI import progress written to the console, not HTML. 258 261 echo " {$slug}... {$existing[0]->post_title} (tagged)\n"; 259 262 } … … 267 270 } 268 271 272 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI import progress written to the console, not HTML. 269 273 echo " {$slug}..."; 270 274 … … 277 281 wp_set_object_terms( $post->ID, $section, 'plugin_section', true ); 278 282 $imported_slugs[] = $slug; 283 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI import progress written to the console, not HTML. 279 284 echo " {$post->post_title} (done)\n"; 280 285 $imported++; 281 286 } 282 287 288 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI import progress written to the console, not HTML. 283 289 echo " {$section}: {$imported} new, " . count( $existing_slugs ) . " tagged.\n\n"; 284 290 } -
sites/trunk/global.wordpress.org/public_html/wp-content/mu-plugins/downloads/rosetta-downloads.php
r15188 r15190 173 173 </td> 174 174 </tr> 175 <?php echo implode( "\n", $rows ); ?>175 <?php echo implode( "\n", $rows ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Table row markup assembled above from escaped parts. ?> 176 176 </tbody> 177 177 -
sites/trunk/global.wordpress.org/public_html/wp-content/mu-plugins/roles/class-translation-editors-list-table.php
r15179 r15190 271 271 ?> 272 272 <label class="screen-reader-text" for="cb-select-<?php echo (int) $user->ID; ?>"><?php esc_html_e( 'Select translation editor', 'rosetta' ); ?></label> 273 <input id="cb-select-<?php echo $user->ID; ?>" type="checkbox" name="translation-editors[]" value="<?php echo$user->ID; ?>">273 <input id="cb-select-<?php echo (int) $user->ID; ?>" type="checkbox" name="translation-editors[]" value="<?php echo (int) $user->ID; ?>"> 274 274 <?php 275 275 } … … 297 297 } 298 298 299 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Avatar and edit-link markup assembled above from escaped parts. 299 300 echo "$avatar $edit"; 300 301 } … … 306 307 */ 307 308 public function column_name( $user ) { 308 echo "$user->first_name $user->last_name";309 echo esc_html( "$user->first_name $user->last_name" ); 309 310 } 310 311 … … 315 316 */ 316 317 public function column_email( $user ) { 317 echo "<a href='" . esc_url( "mailto:$user->user_email" ) . "'>$user->user_email</a>";318 printf( '<a href="%1$s">%2$s</a>', esc_url( "mailto:$user->user_email" ), esc_html( $user->user_email ) ); 318 319 } 319 320 … … 361 362 } 362 363 364 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Project links are assembled above from escaped URLs and names. 363 365 echo implode( '<br>', $projects ); 364 366 } -
sites/trunk/global.wordpress.org/public_html/wp-content/mu-plugins/roles/views/cross-locale-pte.php
r15179 r15190 12 12 </h2> 13 13 14 <?php echo $feedback_message; ?>14 <?php echo $feedback_message; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Notice markup assembled by get_feedback_message() from escaped parts. ?> 15 15 16 16 <p><?php esc_html_e( 'This is the list of our current Cross-Locale PTEs.', 'rosetta' ); ?></p> -
sites/trunk/global.wordpress.org/public_html/wp-content/mu-plugins/roles/views/edit-cross-locale-pte.php
r15179 r15190 10 10 <h2><?php esc_html_e( 'Edit Cross-Locale PTE', 'rosetta' ); ?></h2> 11 11 12 <?php echo $feedback_message; ?>12 <?php echo $feedback_message; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Notice markup assembled by get_feedback_message() from escaped parts. ?> 13 13 14 14 <p><?php … … 17 17 esc_html__( 'You are currently editing the user %s.', 'rosetta' ), 18 18 sprintf( '<a href="%1$s">%2$s</a>', 19 'https://profiles.wordpress.org/' . $user->user_nicename . '/',20 $user->user_login19 esc_url( 'https://profiles.wordpress.org/' . $user->user_nicename . '/' ), 20 esc_html( $user->user_login ) 21 21 ) 22 22 ); -
sites/trunk/global.wordpress.org/public_html/wp-content/mu-plugins/roles/views/edit-translation-editor.php
r15179 r15190 10 10 <h2><?php esc_html_e( 'Edit Translation Editor', 'rosetta' ); ?></h2> 11 11 12 <?php echo $feedback_message; ?>12 <?php echo $feedback_message; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Notice markup assembled by get_feedback_message() from escaped parts. ?> 13 13 14 14 <p><?php … … 18 18 esc_html__( 'You are currently editing the user %s.', 'rosetta' ), 19 19 sprintf( '<a href="%1$s">%2$s</a>', 20 'https://profiles.wordpress.org/' . $user->user_nicename . '/',21 $user->user_login20 esc_url( 'https://profiles.wordpress.org/' . $user->user_nicename . '/' ), 21 esc_html( $user->user_login ) 22 22 ) 23 23 ); -
sites/trunk/global.wordpress.org/public_html/wp-content/mu-plugins/roles/views/translation-editors.php
r15179 r15190 11 11 </h2> 12 12 13 <?php echo $feedback_message; ?>13 <?php echo $feedback_message; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Notice markup assembled by get_feedback_message() from escaped parts. ?> 14 14 15 15 <form method="get"> -
sites/trunk/global.wordpress.org/public_html/wp-content/mu-plugins/showcase/rosetta-showcase.php
r15179 r15190 209 209 /* translators: %s: post title */ 210 210 esc_attr( sprintf( __( '“%s” (Edit)', 'rosetta' ), $title ) ), 211 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Title markup assembled above from escaped parts. 211 212 $title 212 213 ); -
sites/trunk/global.wordpress.org/public_html/wp-content/themes/rosetta/download.php
r15179 r15190 25 25 <h3 id="latest"><?php esc_html_e( 'Latest release', 'rosetta' ); ?></h3> 26 26 <table class="releases latest"> 27 <?php echo rosetta_release_row( $releases['latest'], 'alt' ); ?>27 <?php echo rosetta_release_row( $releases['latest'], 'alt' ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Release table row markup assembled by rosetta_release_row(). ?> 28 28 </table> 29 29 <?php -
sites/trunk/global.wordpress.org/public_html/wp-content/themes/rosetta/footer.php
r11495 r15190 4 4 __('Code is Poetry.', 'rosetta'); 5 5 6 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 6 7 echo do_blocks( '<!-- wp:wporg/global-footer /-->' ); -
sites/trunk/global.wordpress.org/public_html/wp-content/themes/rosetta/front-page.php
r15179 r15190 9 9 <div class="section"> 10 10 <div class="col-12" role="main"> 11 <h3>The <?php echo $rosetta->rosetta->get_glotpress_locale()->english_name; ?> translation of WordPress is inactive</h3>11 <h3>The <?php echo esc_html( $rosetta->rosetta->get_glotpress_locale()->english_name ); ?> translation of WordPress is inactive</h3> 12 12 <p><a href="https://wordpress.org/download/">Download the English version instead</a>.</p> 13 <p>If you’re interested in translating WordPress to <?php echo $rosetta->rosetta->get_glotpress_locale()->english_name; ?>,13 <p>If you’re interested in translating WordPress to <?php echo esc_html( $rosetta->rosetta->get_glotpress_locale()->english_name ); ?>, 14 14 join <a href="https://make.wordpress.org/polyglots/">the Polyglots team</a> and find out how.</p> 15 15 </div> … … 33 33 printf( 34 34 '<img class="shot" %ssrc="%s" alt="" />', 35 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Image dimension attribute pair built above from the image size. 35 36 $hw, 36 37 esc_url( $header_image ) -
sites/trunk/global.wordpress.org/public_html/wp-content/themes/rosetta/header.php
r11495 r15190 16 16 } 17 17 18 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 18 19 echo do_blocks( '<!-- wp:wporg/global-header /-->' ); -
sites/trunk/global.wordpress.org/public_html/wp-content/themes/rosetta/inc/template-tags.php
r15188 r15190 23 23 /* translators: 1: post date 2: post author */ 24 24 esc_html__( 'Posted on %1$s by %2$s.', 'rosetta' ), 25 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Date, author and category markup assembled above from escaped parts. 25 26 $time_string, 27 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Date, author and category markup assembled above from escaped parts. 26 28 $author_string 27 29 ); … … 38 40 /* translators: %s: list of categories */ 39 41 esc_html__( 'Filed under %s.', 'rosetta' ), 42 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Date, author and category markup assembled above from escaped parts. 40 43 $categories_string 41 44 ); -
sites/trunk/jobs.wordpress.net/public_html/wp-content/plugins/jobswp/jobswp-template.php
r15179 r15190 115 115 </div>'; 116 116 117 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Field and help-text markup assembled by the template helpers. 117 118 echo $output; 118 119 } … … 149 150 150 151 if ( $help_text ) { 152 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Field and help-text markup assembled by the template helpers. 151 153 echo '<div class="job-help-text">' . $help_text . "</div>\n"; 152 154 } -
sites/trunk/jobs.wordpress.net/public_html/wp-content/plugins/jobswp/jobswp.php
r15185 r15190 431 431 return; 432 432 433 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Close-link markup assembled by _get_close_link(). 433 434 echo $this->_get_close_link( $post, 'button button-large alignright' ); 434 435 } -
sites/trunk/jobs.wordpress.net/public_html/wp-content/themes/jobswp/content-list.php
r15179 r15190 7 7 8 8 $evenodd = abs( $evenodd - 1 ); 9 echo '<div class="row row-' . $evenodd. '">';9 echo '<div class="row row-' . esc_attr( $evenodd ) . '">'; 10 10 11 11 echo '<div class="job-date">' . get_the_date( 'M j' ) . '</div>'; … … 13 13 echo '<a href="'; the_permalink(); echo '" rel="bookmark">'; the_title(); echo '</a></div>'; 14 14 echo '<div class="job-type">'; 15 echo jobswp_get_job_meta( get_the_ID(), 'jobtype');15 echo esc_html( jobswp_get_job_meta( get_the_ID(), 'jobtype' ) ); 16 16 echo '</div>'; 17 17 echo '<div class="job-location">'; 18 echo jobswp_get_job_meta( get_the_ID(), 'location');18 echo esc_html( jobswp_get_job_meta( get_the_ID(), 'location' ) ); 19 19 echo '</div>'; 20 20 -
sites/trunk/jobs.wordpress.net/public_html/wp-content/themes/jobswp/inc/template-tags.php
r15179 r15190 31 31 32 32 ?> 33 <nav role="navigation" id="<?php echo esc_attr( $nav_id ); ?>" class="<?php echo $nav_class; ?>">33 <nav role="navigation" id="<?php echo esc_attr( $nav_id ); ?>" class="<?php echo esc_attr( $nav_class ); ?>"> 34 34 <h1 class="screen-reader-text"><?php esc_html_e( 'Post navigation', 'jobswp' ); ?></h1> 35 35 -
sites/trunk/phpcs.xml.dist
r15179 r15190 21 21 <exclude-pattern>*/plugins/theme-directory/lib/*</exclude-pattern> 22 22 <exclude-pattern>*/plugins/wpf-stripe/stripe-php/*</exclude-pattern> 23 <!-- Near-verbatim copy of vendor/google/cloud-storage/src/StreamWrapper.php; kept diffable against upstream. --> 24 <exclude-pattern>*/plugins/photo-directory/inc/google-cloud-storage-stream-metadata.php</exclude-pattern> 23 25 24 26 <!-- Exclude generated wp-scripts asset files. --> … … 150 152 <!-- Returns selected() markup or an esc_attr()'d value attribute; see jobs.wordpress.net plugins/jobswp/jobswp-template.php. --> 151 153 <element value="jobswp_field_value"/> 154 <!-- Returns esc_html( $text ); see themes/pub/wporg-main/functions.php. --> 155 <element value="esc_html___"/> 152 156 </property> 153 157 </properties> -
sites/trunk/profiles.wordpress.org/public_html/wp-content/plugins/wporg-profiles-activity-handler/wporg-profiles-activity-handler.php
r15126 r15190 188 188 189 189 if ( $missing ) { 190 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Plain-text API response, or written to the error log. 190 191 die( '-1 Required argument(s) are missing: ' . implode( ', ', $missing ) ); 191 192 } … … 214 215 $status = $result->get_error_data()['status'] ?? 500; 215 216 status_header( $status ); 217 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Plain-text API response, or written to the error log. 216 218 trigger_error( $result->get_error_message(), E_USER_WARNING ); 219 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Plain-text API response, or written to the error log. 217 220 die( '-1 ' . $result->get_error_message() ); 218 221 } … … 221 224 } catch ( Exception $exception ) { 222 225 status_header( 500 ); 226 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Plain-text API response, or written to the error log. 223 227 trigger_error( $exception->getMessage(), E_USER_WARNING ); 228 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Plain-text API response, or written to the error log. 224 229 die( '-1 ' . $exception->getMessage() ); 225 230 } … … 381 386 382 387 if ( ! $user ) { 388 // phpcs:ignore WordPress.Security.EscapeOutput.ExceptionNotEscaped -- Plain-text API response; the interpolated user ID is intval()'d above. 383 389 throw new Exception( '-1 Activity reported for unrecognized user ID: ' . $activity['user_id'] ); 384 390 } -
sites/trunk/profiles.wordpress.org/public_html/wp-content/plugins/wporg-profiles-association-handler/wporg-profiles-association-handler.php
r15026 r15190 180 180 $status = $result->get_error_data()['status'] ?? 500; 181 181 status_header( $status ); 182 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Plain-text API response, or written to the error log. 182 183 die( '-1 ' . $result->get_error_message() ); 183 184 } -
sites/trunk/profiles.wordpress.org/public_html/wp-content/plugins/wporg-profiles-profile-handler/wporg-profiles-handler.php
r15026 r15190 55 55 $status = $result->get_error_data()['status'] ?? 500; 56 56 status_header( $status ); 57 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Plain-text API response, or written to the error log. 57 58 trigger_error( $result->get_error_message(), E_USER_WARNING ); 59 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Plain-text API response, or written to the error log. 58 60 die( '-1 ' . $result->get_error_message() ); 59 61 } … … 62 64 } catch ( Exception $exception ) { 63 65 status_header( 500 ); 66 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Plain-text API response, or written to the error log. 64 67 trigger_error( $exception->getMessage(), E_USER_WARNING ); 68 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Plain-text API response, or written to the error log. 65 69 die( '-1 ' . $exception->getMessage() ); 66 70 } -
sites/trunk/trac.wordpress.org/bin/mysql-migrate.php
r155 r15190 55 55 } 56 56 57 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI migration progress written to the console, not HTML. 57 58 echo "Done. " . ( microtime( true ) - $start ) . " seconds.\n"; 58 59 -
sites/trunk/trac.wordpress.org/bin/sqlite-migrate.php
r3595 r15190 65 65 $query = $sqlite->prepare( $sql ); 66 66 $results = $mysql->get_results( "SELECT * FROM $table" ); 67 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI migration progress written to the console, not HTML. 67 68 printf( "Processing $table with %d results.\n", count( $results ) ); 68 69 … … 83 84 } 84 85 86 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI migration progress written to the console, not HTML. 85 87 echo "Done.. " . ( microtime( true ) - $start ) . " seconds.\n"; 86 88 -
sites/trunk/wordpress.org/public_html/wp-content/mu-plugins/pub/wporg-redirects.php
r14971 r15190 273 273 // Headers should not have been sent at this point in time. 274 274 // On some pages, such as wp-cron.php the request has been terminated prior to WordPress loading, and so headers were "sent". 275 echo "<a href='$location'>$location</a>";275 printf( '<a href="%1$s">%2$s</a>', esc_url( $location ), esc_html( $location ) ); 276 276 } 277 277 exit; -
sites/trunk/wordpress.org/public_html/wp-content/mu-plugins/pub/wporg-seo/robots.php
r9861 r15190 29 29 } 30 30 31 echo '<meta name="robots" content="' . $noindex. '" />' . "\n";31 echo '<meta name="robots" content="' . esc_attr( $noindex ) . '" />' . "\n"; 32 32 } 33 33 } -
sites/trunk/wordpress.org/public_html/wp-content/mu-plugins/pub/wporg-well-known.php
r13988 r15190 40 40 ?> 41 41 Contact: https://hackerone.com/wordpress 42 Expires: <?php echo gmdate( 'Y-m-d', $expires); ?>T15:00:00.000Z42 Expires: <?php echo esc_html( gmdate( 'Y-m-d', $expires ) ); ?>T15:00:00.000Z 43 43 Acknowledgments: https://hackerone.com/wordpress/thanks 44 44 Canonical: https://wordpress.org/.well-known/security.txt -
sites/trunk/wordpress.org/public_html/wp-content/plugins/handbook/inc/admin-notices.php
r15179 r15190 88 88 /* translators: 1: example landing page title that includes post type name, 2: comma-separated list of acceptable post slugs */ 89 89 wp_kses_post( __( '<strong>Welcome to your new handbook!</strong> It is recommended that the first post you create is the landing page for the handbook. You can title it anything you like (suggestions: <code>%1$s</code> or <code>Welcome</code>). However, you must ensure that it has one of the following slugs: %2$s. The slug will ultimately be omitted from the page‘s permalink URL, but will still appear in the permalinks for sub-pages.', 'wporg' ) ), 90 WPorg_Handbook::get_name( $current_screen->post_type ), 90 esc_html( WPorg_Handbook::get_name( $current_screen->post_type ) ), 91 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Slug list is deliberately <code>-wrapped markup, built above. 91 92 implode( ', ', $suggested_slugs ) 92 93 ); … … 128 129 /* translators: 1: example landing page title that includes post type name, 2: comma-separated list of acceptable post slugs */ 129 130 wp_kses_post( __( '<strong>Warning:</strong> A landing page for this handbook has not been created or is not published. You can title it anything you like (suggestions: <code>%1$s</code> or <code>Welcome</code>). However, you must ensure that it has one of the following slugs: %2$s. The slug will ultimately be omitted from the page‘s permalink URL, but will still appear in the permalinks for its sub-pages. Without this page your handbook‘s URL will show a seemingly random handbook page.', 'wporg' ) ), 130 WPorg_Handbook::get_name( $handbook_post_type ), 131 esc_html( WPorg_Handbook::get_name( $handbook_post_type ) ), 132 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Slug list is deliberately <code>-wrapped markup, built above. 131 133 implode( ', ', $suggested_slugs ) 132 134 ); … … 174 176 /* translators: 1: URL to remote manifest. 2: cron interval. */ 175 177 wp_kses_post( __( '<strong>This is an imported handbook!</strong> This handbook is imported according to a <a href="%1$s">remote manifest</a>. Any local changes will be overwritten during the next import, so make any changes at the remote location. Import interval: <strong>%2$s</strong>.', 'wporg' ) ), 176 $handbook_config['manifest'],177 $interval_display178 esc_url( $handbook_config['manifest'] ), 179 esc_html( $interval_display ) 178 180 ); 179 181 echo "</p></div>\n"; … … 225 227 /* translators: %s: cron interval. */ 226 228 wp_kses_post( __( '<strong>Misconfigured cron interval!</strong> This imported handbook has a misconfigured cron interval. The config defines an interval of <strong>%s</strong>, which has not been defined. The fallback import interval shown in a notice above includes the default cron interval currently in use.', 'wporg' ) ), 227 $interval_display229 esc_html( $interval_display ) 228 230 ); 229 231 echo "</p></div>\n"; -
sites/trunk/wordpress.org/public_html/wp-content/plugins/handbook/inc/glossary.php
r9331 r15190 116 116 117 117 static function page_content() { 118 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Shortcode output rendered by the handbook glossary. 118 119 echo self::shortcode(); 119 120 } -
sites/trunk/wordpress.org/public_html/wp-content/plugins/handbook/inc/widgets.php
r15179 r15190 52 52 ?> 53 53 <p> 54 <input class="widefat" id="<?php echo esc_attr( $this->get_field_id( 'show_home') ); ?>" name="<?php echo esc_attr( $this->get_field_name( 'show_home' ) ); ?>" type="checkbox" value="1" <?php echo $checked?> />54 <input class="widefat" id="<?php echo esc_attr( $this->get_field_id( 'show_home' ) ); ?>" name="<?php echo esc_attr( $this->get_field_name( 'show_home' ) ); ?>" type="checkbox" value="1" <?php echo $checked; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Widget form markup with the escaped field ids assembled on the same line. ?> /> 55 55 <label for="<?php echo esc_attr( $this->get_field_id( 'show_home' ) ); ?>"><?php esc_html_e( 'List the home page', 'wporg' ); ?></label> 56 56 </p> -
sites/trunk/wordpress.org/public_html/wp-content/plugins/handbook/phpunit/bootstrap.php
r15020 r15190 25 25 26 26 if ( ! file_exists( $_tests_dir . '/includes/functions.php' ) ) { 27 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Test bootstrap console output, not HTML. 27 28 echo "Could not find $_tests_dir/includes/functions.php\n"; 28 29 exit( 1 ); -
sites/trunk/wordpress.org/public_html/wp-content/plugins/official-wordpress-events/official-wordpress-events.php
r15170 r15190 551 551 if ( ! $successful_response || ! $body_is_valid ) { 552 552 trigger_error( 553 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Written to the error log, not rendered. 553 554 "This function had to abort because the request failed. If it didn't, it would mark scheduled events as postponed. Failed response: " . var_export( $response, true ), 554 555 E_USER_WARNING … … 889 890 __METHOD__, 890 891 esc_html( parse_url( site_url(), PHP_URL_HOST ) ), 892 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Written to the error log, not rendered. 891 893 sanitize_text_field( $error ) 892 894 ), E_USER_WARNING ); … … 924 926 925 927 if ( 'cli' === php_sapi_name() ) { 928 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI console output; the guard above restricts this to php_sapi_name() === 'cli'. 926 929 echo "\n" . $message; 927 930 } -
sites/trunk/wordpress.org/public_html/wp-content/plugins/phpunit-test-reporter/parts/result-set-all.php
r14061 r15190 2 2 use PTR\Display; 3 3 4 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Display::get_display_css() returns the report stylesheet. 4 5 echo Display::get_display_css(); ?> 5 6 … … 26 27 href="<?php echo esc_url( sprintf( 'https://core.trac.wordpress.org/changeset/%d', $rev_id ) ); ?>" 27 28 title="<?php echo esc_attr( apply_filters( 'the_title', $revision->post_title ) ); ?>"> 28 r<?php echo $rev_id; ?>29 r<?php echo esc_html( $rev_id ); ?> 29 30 </a> 30 31 </td> … … 32 33 <td> 33 34 <span class="ptr-status-badge ptr-status-badge-passed"> 34 <?php echo$num_passed; ?>35 <?php echo (int) $num_passed; ?> 35 36 </span> 36 37 </td> 37 38 <td> 38 39 <span class="ptr-status-badge ptr-status-badge-failed"> 39 <?php echo$num_failed; ?>40 <?php echo (int) $num_failed; ?> 40 41 </span> 41 42 </td> -
sites/trunk/wordpress.org/public_html/wp-content/plugins/phpunit-test-reporter/parts/result-set-single.php
r14061 r15190 2 2 use PTR\Display; 3 3 4 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Display::get_display_css() returns the report stylesheet. 4 5 echo Display::get_display_css(); 5 6 … … 11 12 <div class="ptr-test-reporter-single-revision"> 12 13 <a href="<?php echo esc_url( sprintf( 'https://core.trac.wordpress.org/changeset/%d', $rev_id ) ); ?>"> 13 r<?php echo $rev_id; ?>14 r<?php echo esc_html( $rev_id ); ?> 14 15 </a>: <?php echo esc_attr( apply_filters( 'the_title', $revision->post_title ) ); ?> 15 16 </div> -
sites/trunk/wordpress.org/public_html/wp-content/plugins/phpunit-test-reporter/parts/single-result.php
r15181 r15190 31 31 } ?> 32 32 33 <?php echo Display::get_display_css(); ?>33 <?php echo Display::get_display_css(); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Display::get_display_css() returns the report stylesheet, and the link markup is built here. ?> 34 34 35 35 <?php -
sites/trunk/wordpress.org/public_html/wp-content/plugins/plugin-directory/admin/metabox/class-support-reps.php
r6287 r15190 108 108 $result = Tools::remove_plugin_support_rep( $plugin_slug, $support_rep ); 109 109 110 wp_die( $result);110 wp_die( esc_html( $result ) ); 111 111 } 112 112 } -
sites/trunk/wordpress.org/public_html/wp-content/plugins/plugin-directory/api/routes/class-locale-banner.php
r14686 r15190 212 212 header( 'Content-Type: text/plain' ); 213 213 if ( ! empty( $result['suggest_string'] ) ) { 214 echo '<p>' . $result['suggest_string']. '</p>';214 echo '<p>' . wp_kses_post( $result['suggest_string'] ) . '</p>'; 215 215 } 216 216 -
sites/trunk/wordpress.org/public_html/wp-content/plugins/plugin-directory/api/routes/class-plugin-blueprint.php
r14575 r15190 84 84 85 85 // We already have a json string, returning would double-encode it. 86 die( $blueprint['contents'] ); 86 die( $blueprint['contents'] ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Blueprint JSON served to WordPress Playground; escaping would corrupt it. 87 87 } 88 88 … … 115 115 if ( $output ) { 116 116 header( 'Access-Control-Allow-Origin: https://playground.wordpress.net' ); 117 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Blueprint JSON served to WordPress Playground; escaping would corrupt it. 117 118 die( $output ); 118 119 } … … 136 137 if ( $output ) { 137 138 header( 'Access-Control-Allow-Origin: https://playground.wordpress.net' ); 139 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Blueprint JSON served to WordPress Playground; escaping would corrupt it. 138 140 die( $output ); 139 141 } -
sites/trunk/wordpress.org/public_html/wp-content/plugins/plugin-directory/api/routes/class-plugin.php
r15179 r15190 400 400 <div class="star-rating"> 401 401 <?php 402 /* Core has .star-rating .star colour styling, which is why we use a custom wrapper and template */ 403 echo Template::dashicons_stars( array( 404 'rating' => $review->post_rating, 405 'template' => '<span class="star %1$s"></span>', 406 ) ); 402 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Core has .star-rating .star colour styling, so this uses a custom wrapper and template; dashicons_stars() returns that markup. 403 echo Template::dashicons_stars( 404 array( 405 'rating' => (int) $review->post_rating, 406 'template' => '<span class="star %1$s"></span>', 407 ) 408 ); 407 409 ?> 408 410 </div> … … 423 425 /* translators: 1: Review author, 2: Review date. */ 424 426 esc_html__( 'By %1$s on %2$s', 'wporg-plugins' ), 427 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Star and byline markup built by Template helpers from escaped values. 425 428 $review_author_markup, 429 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Star and byline markup built by Template helpers from escaped values. 426 430 '<span class="review-date">' . date_i18n( get_option( 'date_format' ), strtotime( $review->post_modified ) ) . '</span>' 427 431 ); … … 430 434 </div> 431 435 </div> 432 <div class="review-body"><?php echo $review->post_content; ?></div>436 <div class="review-body"><?php echo wp_kses_post( $review->post_content ); ?></div> 433 437 </div> 434 438 <?php -
sites/trunk/wordpress.org/public_html/wp-content/plugins/plugin-directory/api/routes/class-svn-access.php
r6287 r15190 47 47 foreach ( $svn_access as $slug => $users ) { 48 48 $slug = ltrim( $slug, '/' ); 49 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Generates SVN authz config text, not HTML. 49 50 echo "\n[/$slug]\n"; 50 51 51 52 foreach ( $users as $user => $access ) { 53 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Generates SVN authz config text, not HTML. 52 54 echo "$user = $access\n"; 53 55 } -
sites/trunk/wordpress.org/public_html/wp-content/plugins/plugin-directory/bin/check-block.php
r14987 r15190 72 72 $plugin = get_post(); 73 73 74 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 74 75 echo "Checking $plugin->post_name\n"; 75 76 … … 99 100 } 100 101 102 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 101 103 echo "Good plugins:\n" . join( "\n", $good_plugins ) . "\n\n"; 104 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 102 105 echo "Problem plugins:\n" . join( "\n", $error_plugins ) . "\n\n"; 103 106 -
sites/trunk/wordpress.org/public_html/wp-content/plugins/plugin-directory/bin/email-bulk-security-vulnerabilities.php
r12763 r15190 229 229 if ( ! $plugin ) { 230 230 $stats['error']++; 231 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 231 232 echo "ERROR: Plugin not found: $plugin_slug\n\n"; 232 233 continue; … … 235 236 if ( 'publish' != $plugin->post_status ) { 236 237 $stats['error']++; 238 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 237 239 echo "ERROR: Plugin not published: $plugin_slug\n\n"; 238 240 continue; … … 267 269 $body = str_replace( 'LINK<br /><br />DETAILS', '<pre>' . $vuln_desc . '</pre>', $body ); 268 270 271 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 269 272 echo "Subject: $subject\n\n"; 273 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 270 274 echo "To: $to\n"; 275 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 271 276 echo "CC: $cc_list\n"; 277 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 272 278 echo str_replace( "<br />", "\n", $body ); 273 279 … … 293 299 $body = str_replace( 'REPORT<br /><br />OPTIONAL_ADDITIONAL', '<pre>' . $vuln_desc . '</pre>', $body ); 294 300 301 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 295 302 echo "Subject: $subject\n\n"; 303 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 296 304 echo "To: $to\n"; 305 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 297 306 echo "CC: $cc_list\n"; 307 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 298 308 echo str_replace( "<br />", "\n", $body ); 299 309 -
sites/trunk/wordpress.org/public_html/wp-content/plugins/plugin-directory/bin/import-plugin-to-glotpress.php
r6287 r15190 86 86 } 87 87 88 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 88 89 echo "Processing I18N Import for $plugin_slug...\n"; 89 90 try { … … 121 122 } 122 123 124 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 123 125 echo "OK. Took {$runtime}s\n"; 124 126 } catch ( Exception $e ) { … … 148 150 } 149 151 152 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 150 153 echo "Failed. Took {$runtime}s\n"; 151 154 -
sites/trunk/wordpress.org/public_html/wp-content/plugins/plugin-directory/bin/import-plugin.php
r8728 r15190 69 69 70 70 if ( is_wp_error( $create_result ) ) { 71 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 71 72 echo "Failed. {$plugin_slug} post was not be found, and failed to be created.\n"; 72 73 fwrite( STDERR, "[{$plugin_slug}] Plugin Import Failed: " . $create_result->get_error_message() . "\n" ); … … 78 79 if ( $opts['async'] ) { 79 80 Jobs\Plugin_Import::queue( $plugin_slug, array( 'tags_touched' => $changed_tags ) ); 81 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 80 82 echo "Queueing Import for $plugin_slug... OK\n"; 81 83 die(); 82 84 } 83 85 86 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 84 87 echo "Processing Import for $plugin_slug... "; 85 88 try { 86 89 $importer = new CLI\Import(); 87 90 $importer->import_from_svn( $plugin_slug, $changed_tags ); 91 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 88 92 echo 'OK. Took ' . round( microtime( 1 ) - $start_time, 2 ) . "s\n"; 89 93 } catch ( \Exception $e ) { 94 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 90 95 echo 'Failed. Took ' . round( microtime( 1 ) - $start_time, 2 ) . "s\n"; 91 96 -
sites/trunk/wordpress.org/public_html/wp-content/plugins/plugin-directory/bin/process-blocks.php
r9896 r15190 52 52 $plugin = get_post(); 53 53 54 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 54 55 echo $plugin->post_name; 55 56 echo "\n"; … … 93 94 echo number_format( $count_with_files ) . " have asset files\n"; 94 95 echo "\n"; 96 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 95 97 echo "Plugins missing blocks:\n" . join( "\n", $plugins_missing_blocks ) . "\n\n"; 98 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 96 99 echo "Plugins missing assets:\n" . join( "\n", $plugins_missing_assets ) . "\n\n"; -
sites/trunk/wordpress.org/public_html/wp-content/plugins/plugin-directory/bin/quick-stats.php
r6287 r15190 43 43 foreach ( $top as $row ) { 44 44 // $vals = array_values( (array) $row ); 45 echo $row[0] . "\t\t\t" . number_format( $row[1] ) . "\n"; 45 echo $row[0] . "\t\t\t" . number_format( $row[1] ) . "\n"; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 46 46 } 47 47 48 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 48 49 echo "Top $n Total: " . number_format( array_reduce( $top, __NAMESPACE__ . '\callback_sum' ) ) . "\n"; 49 50 50 51 $tail_n = count( $tail ); 52 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 51 53 echo "Other $tail_n: " . number_format( array_reduce( $tail, __NAMESPACE__ . '\callback_sum' ) ) . "\n"; 52 54 -
sites/trunk/wordpress.org/public_html/wp-content/plugins/plugin-directory/bin/rebuild-update_source-table.php
r7072 r15190 46 46 47 47 foreach ( $slugs as $i => $slug ) { 48 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 48 49 echo ++$i . '/' . count( $slugs ) . "\t" . $slug . "\n"; 49 50 -
sites/trunk/wordpress.org/public_html/wp-content/plugins/plugin-directory/bin/rebuild-zip.php
r15063 r15190 97 97 } 98 98 99 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 99 100 echo "Rebuilding ZIPs for $plugin_slug... "; 100 101 try { … … 123 124 } 124 125 126 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 125 127 echo 'OK. Took ' . round( microtime( 1 ) - $start_time, 2 ) . "s\n"; 126 128 } catch ( Exception $e ) { 127 129 fwrite( STDERR, "{$plugin_slug}: Zip Rebuild failed: " . $e->getMessage() . "\n" ); 130 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 128 131 echo 'Failed. Took ' . round( microtime( 1 ) - $start_time, 2 ) . "s\n"; 129 132 exit( 1 ); -
sites/trunk/wordpress.org/public_html/wp-content/plugins/plugin-directory/bin/resync-ratings.php
r7030 r15190 48 48 } 49 49 50 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI script; the php_sapi_name() guard above exits for web requests and this is console output. 50 51 echo $i . '/' . count( $slugs ) . "\t" . $post->post_name . "\n"; 51 52 -
sites/trunk/wordpress.org/public_html/wp-content/plugins/plugin-directory/class-plugin-directory.php
r15102 r15190 1352 1352 status_header( 200 ); 1353 1353 header( 'Content-type: text/plain' ); 1354 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Generated markup: a text/plain readme and GeoPattern SVG, neither of which survives escaping. 1354 1355 echo file_get_contents( __DIR__ . '/readme/readme.txt' ); 1355 1356 die(); … … 1506 1507 header( 'Expires: ' . gmdate( 'D, d M Y H:i:s \G\M\T', time() + YEAR_IN_SECONDS ) ); 1507 1508 1509 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Generated markup: a text/plain readme and GeoPattern SVG, neither of which survives escaping. 1508 1510 echo $icon->toSVG(); 1509 1511 die(); -
sites/trunk/wordpress.org/public_html/wp-content/plugins/plugin-directory/class-plugin-search.php
r14809 r15190 97 97 ]; 98 98 $export = preg_replace(array_keys($patterns), array_values($patterns), $export); 99 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Local var_export() debug helper; the export is PHP source, not HTML. 99 100 if ((bool)$return) return $export; else echo $export; 100 101 } -
sites/trunk/wordpress.org/public_html/wp-content/plugins/plugin-directory/class-template.php
r15036 r15190 176 176 } 177 177 178 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Meta tags assembled above from esc_attr()-escaped values. 178 179 echo implode( "\n", $metas ); 179 180 } -
sites/trunk/wordpress.org/public_html/wp-content/plugins/plugin-directory/cli/class-import.php
r15169 r15190 202 202 $this->warnings['invalid_update_uri'] = $headers->UpdateURI; 203 203 204 // phpcs:ignore WordPress.Security.EscapeOutput.ExceptionNotEscaped -- CLI context, callers write the message to STDERR. 204 205 throw new Exception( Readme_Validator::instance()->translate_code_to_message( 'invalid_update_uri' ) ); 205 206 } … … 227 228 $this->warnings['unmet_dependencies'] = $unmet_dependencies; 228 229 230 // phpcs:ignore WordPress.Security.EscapeOutput.ExceptionNotEscaped -- CLI context, callers write the message to STDERR. 229 231 throw new Exception( Readme_Validator::instance()->translate_code_to_message( 'unmet_dependencies', $unmet_dependencies ) ); 230 232 } … … 241 243 foreach ( $svn_tags_deleted as $svn_deleted_tag ) { 242 244 if ( Plugin_Directory::remove_release( $plugin, $svn_deleted_tag ) ) { 245 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI context, callers write the message to STDERR. 243 246 echo "Plugin tag {$svn_deleted_tag} deleted; release removed.\n"; 244 247 } … … 366 369 $release = Plugin_Directory::get_release( $plugin, $stable_tag ); 367 370 if ( ! $release ) { 371 // phpcs:ignore WordPress.Security.EscapeOutput.ExceptionNotEscaped -- CLI context, callers write the message to STDERR. 368 372 throw new Exception( "Plugin release {$stable_tag} not found." ); 369 373 } … … 429 433 do_action( 'wporg_plugins_import_release_pending', $plugin, $release, $data ); 430 434 435 // phpcs:ignore WordPress.Security.EscapeOutput.ExceptionNotEscaped -- CLI context, callers write the message to STDERR. 431 436 throw new Exception( "Plugin release {$stable_tag} not confirmed." ); 432 437 } … … 717 722 718 723 if ( $versions_to_build ) { 724 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI context, callers write the message to STDERR. 719 725 echo "Building ZIPs for {$plugin_slug}: " . implode( ', ', $versions_to_build ) . "\n"; 720 726 } … … 867 873 868 874 if ( ! $svn_info['result'] ) { 875 // phpcs:ignore WordPress.Security.EscapeOutput.ExceptionNotEscaped -- CLI context, callers write the message to STDERR. 869 876 throw new Exception( 'Could not find stable SVN URL: ' . ( $svn_info['errors'] ? implode( ' ', reset( $svn_info['errors'] ) ) : 'Unknown error' ) ); 870 877 } … … 885 892 */ 886 893 if ( ! wp_list_filter( SVN::ls( $stable_url, true ), [ 'kind' => 'file' ] ) ) { 894 // phpcs:ignore WordPress.Security.EscapeOutput.ExceptionNotEscaped -- CLI context, callers write the message to STDERR. 887 895 throw new Exception( "Could not create SVN export of {$stable_url}: Path appears not to have any files." ); 888 896 } … … 902 910 } 903 911 912 // phpcs:ignore WordPress.Security.EscapeOutput.ExceptionNotEscaped -- CLI context, callers write the message to STDERR. 904 913 throw new Exception( 'Could not create SVN export: ' . ( $svn_export['errors'] ? implode( ' ', reset( $svn_export['errors'] ) ) : 'Unknown error' ) ); 905 914 } -
sites/trunk/wordpress.org/public_html/wp-content/plugins/plugin-directory/cli/class-svn-watcher.php
r15083 r15190 24 24 $last_rev_processed = $this->get_option( $svn_rev_option_name ); 25 25 if ( ! $last_rev_processed ) { 26 // phpcs:ignore WordPress.Security.EscapeOutput.ExceptionNotEscaped -- CLI context, callers write the message to STDERR. 26 27 throw new Exception( "Unknown Revision to parse from, please check the value of {$svn_rev_option_name} in the options table." ); 27 28 } … … 93 94 wp_schedule_single_event( time() + 30, 'plugin_directory_check_cronjobs' ); 94 95 96 // phpcs:ignore WordPress.Security.EscapeOutput.ExceptionNotEscaped -- CLI context, callers write the message to STDERR. 95 97 throw new Exception( 'Could not fetch plugins.svn logs: ' . implode( ', ', $logs['errors'] ) ); 96 98 } else { -
sites/trunk/wordpress.org/public_html/wp-content/plugins/plugin-directory/cli/i18n/class-code-import.php
r14627 r15190 33 33 $files = SVN::ls( $svn_url ); 34 34 if ( ! $files ) { 35 // phpcs:ignore WordPress.Security.EscapeOutput.ExceptionNotEscaped -- CLI context, callers write the message to STDERR. 35 36 throw new Exception( "Plugin has no files in {$tag}." ); 36 37 } … … 46 47 $valid = $this->is_plugin_valid( $export_directory ); 47 48 if ( is_wp_error( $valid ) ) { 49 // phpcs:ignore WordPress.Security.EscapeOutput.ExceptionNotEscaped -- CLI context, callers write the message to STDERR. 48 50 throw new Exception( 'Plugin is not compatible with language packs: ' . $valid->get_error_message() ); 49 51 } … … 67 69 $result = $this->set_glotpress_for_plugin( $this->plugin, 'code' ); 68 70 if ( is_wp_error( $result ) ) { 71 // phpcs:ignore WordPress.Security.EscapeOutput.ExceptionNotEscaped -- CLI context, callers write the message to STDERR. 69 72 throw new Exception( $result->get_error_message() ); 70 73 } -
sites/trunk/wordpress.org/public_html/wp-content/plugins/plugin-directory/cli/i18n/class-readme-import.php
r14814 r15190 28 28 $files = SVN::ls( $svn_url ); 29 29 if ( ! $files ) { 30 // phpcs:ignore WordPress.Security.EscapeOutput.ExceptionNotEscaped -- CLI context, callers write the message to STDERR. 30 31 throw new Exception( "Plugin has no files in {$tag}." ); 31 32 } … … 145 146 $result = $this->set_glotpress_for_plugin( $this->plugin, 'readme' ); 146 147 if ( is_wp_error( $result ) ) { 148 // phpcs:ignore WordPress.Security.EscapeOutput.ExceptionNotEscaped -- CLI context, callers write the message to STDERR. 147 149 throw new Exception( $result->get_error_message() ); 148 150 } -
sites/trunk/wordpress.org/public_html/wp-content/plugins/plugin-directory/jobs/class-plugin-scan.php
r15115 r15190 109 109 $local_path = self::export_plugin_locally( $plugin->post_name, $tag ); 110 110 if ( ! $local_path ) { 111 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI cron log output, not HTML. 111 112 echo "Failed to export plugin {$plugin->post_name} tag {$tag} for scanning.\n"; 112 113 continue; … … 152 153 public static function notify_plugin_authors( $plugin, $results, $tag ) { 153 154 ob_start(); 155 156 // phpcs:disable WordPress.Security.EscapeOutput.OutputNotEscaped -- Plain-text email body composed in an output buffer; escaping would corrupt it. 154 157 155 158 printf( … … 196 199 } 197 200 201 // phpcs:enable WordPress.Security.EscapeOutput.OutputNotEscaped 202 198 203 $body = ob_get_clean(); 199 204 … … 204 209 if ( wp_doing_cron() ) { 205 210 // During cron, output the body to the log. 206 echo "\n==== Plugin Check Results for {$plugin->post_name} EMAIL ====\n"; 211 echo "\n==== Plugin Check Results for {$plugin->post_name} EMAIL ====\n"; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI cron log output, not HTML. 212 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI cron log output, not HTML. 207 213 echo $body; 208 214 } … … 354 360 if ( wp_doing_cron() ) { 355 361 // During cron, output the body to the log. 356 echo "\n==== Plugin Check Results for {$plugin->post_name} {$tag} SLACK LOG ====\n"; 362 echo "\n==== Plugin Check Results for {$plugin->post_name} {$tag} SLACK LOG ====\n"; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI cron log output, not HTML. 357 363 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI cron log output, not HTML. 358 364 echo $fallback . "\n" . $table; … … 476 482 if ( wp_doing_cron() ) { 477 483 // During cron, output the body to the log. 478 echo "\n==== Plugin Check Results for {$plugin_slug} ====\n"; 484 echo "\n==== Plugin Check Results for {$plugin_slug} ====\n"; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI cron log output, not HTML. 485 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI cron log output, not HTML. 479 486 echo "Total Time: {$total_time}s\nReturn Code:{$return_code}.\n"; 487 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI cron log output, not HTML. 480 488 if ( $stderr ) echo "STDERR: {$stderr}\n"; 489 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI cron log output, not HTML. 481 490 if ( $output ) echo "OUTPUT: {$output}\n"; 482 491 } -
sites/trunk/wordpress.org/public_html/wp-content/plugins/plugin-directory/shortcodes/class-upload-handler.php
r15183 r15190 1054 1054 1055 1055 if ( ! $success ) { 1056 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Written to the error log by trigger_error(), not rendered. 1056 1057 trigger_error( "Helpscout update failed: $http_response_code: " . var_export( $result, true ), E_USER_WARNING ); 1057 1058 } -
sites/trunk/wordpress.org/public_html/wp-content/plugins/plugin-directory/standalone/class-plugins-info-api.php
r14800 r15190 357 357 $json = function_exists( 'wp_json_encode' ) ? wp_json_encode( $response ) : json_encode( $response ); 358 358 if ( 'jsonp' == $this->format ) { 359 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- API response body (JSON, JSONP, serialized PHP or XML); escaping would corrupt the format. 359 360 echo "{$this->jsonp}($json)"; 360 361 } else { 362 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- API response body (JSON, JSONP, serialized PHP or XML); escaping would corrupt the format. 361 363 echo $json; 362 364 } … … 364 366 365 367 case 'php': 368 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- API response body (JSON, JSONP, serialized PHP or XML); escaping would corrupt the format. 366 369 echo serialize( $response ? (object) $response : $response ); 367 370 break; … … 446 449 } 447 450 451 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- API response body (JSON, JSONP, serialized PHP or XML); escaping would corrupt the format. 448 452 echo str_repeat( "\t", $tabs ); 449 453 switch ( $type = gettype( $data ) ) { … … 455 459 case 'float': 456 460 list( $start, $close ) = $xml_tag( $key, $type, false ); 461 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- API response body (JSON, JSONP, serialized PHP or XML); escaping would corrupt the format. 457 462 echo "$start$data$close"; 458 463 break; 459 464 case 'NULL': 460 465 list( $start, $close ) = $xml_tag( $key, $type, true ); 466 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- API response body (JSON, JSONP, serialized PHP or XML); escaping would corrupt the format. 461 467 echo $start; 462 468 break; … … 464 470 if ( empty( $data ) ) { 465 471 list( $start, $close ) = $xml_tag( $key, $type, true ); 472 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- API response body (JSON, JSONP, serialized PHP or XML); escaping would corrupt the format. 466 473 echo $start; 467 474 break; … … 469 476 470 477 list( $start, $close ) = $xml_tag( $key, $type, false ); 478 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- API response body (JSON, JSONP, serialized PHP or XML); escaping would corrupt the format. 471 479 echo "$start\n"; 472 480 foreach ( $data as $k => $v ) { 473 481 $this->php_to_xml( $v, $tabs + 1, is_int( $k ) ? '' : $k ); 474 482 } 483 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- API response body (JSON, JSONP, serialized PHP or XML); escaping would corrupt the format. 475 484 echo str_repeat( "\t", $tabs ); 485 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- API response body (JSON, JSONP, serialized PHP or XML); escaping would corrupt the format. 476 486 echo $close; 477 487 break; … … 483 493 484 494 list( $start, $close ) = $xml_tag( $key, $type, true ); 495 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- API response body (JSON, JSONP, serialized PHP or XML); escaping would corrupt the format. 485 496 echo $start; 486 497 break; … … 489 500 list( $start, $close ) = $xml_tag( $key, $type, false ); 490 501 if ( $tabs ) { 502 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- API response body (JSON, JSONP, serialized PHP or XML); escaping would corrupt the format. 491 503 echo $start; 492 504 } … … 494 506 $this->php_to_xml( $v, $tabs + 1, $k ); 495 507 } 508 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- API response body (JSON, JSONP, serialized PHP or XML); escaping would corrupt the format. 496 509 echo str_repeat( "\t", $tabs ); 497 510 if ( $tabs ) { 511 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- API response body (JSON, JSONP, serialized PHP or XML); escaping would corrupt the format. 498 512 echo $close; 499 513 } -
sites/trunk/wordpress.org/public_html/wp-content/plugins/plugin-directory/tests/bootstrap.php
r14720 r15190 31 31 32 32 if ( ! file_exists( $_tests_dir . '/includes/functions.php' ) ) { 33 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Test harness console output, not HTML. 33 34 echo "Could not find $_tests_dir/includes/functions.php\n"; 34 35 exit( 1 ); -
sites/trunk/wordpress.org/public_html/wp-content/plugins/plugin-directory/tests/wporg-plugin-api-performance.php
r14720 r15190 68 68 global $wporg_plugin_api_performance; 69 69 70 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Test harness console output, not HTML. 70 71 echo 'Performance summary for ' . get_called_class() . ":\n"; 71 72 foreach ( $wporg_plugin_api_performance[ get_called_class() ] as $type => $deltas ) { 73 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Test harness console output, not HTML. 72 74 echo "$type: " . self::averages( $deltas ) . "\n"; 73 75 } -
sites/trunk/wordpress.org/public_html/wp-content/plugins/plugin-directory/zip/class-builder.php
r15063 r15190 93 93 } 94 94 if ( ! $res['result'] ) { 95 // phpcs:ignore WordPress.Security.EscapeOutput.ExceptionNotEscaped -- CLI context, callers write the message to STDERR. 95 96 throw new Exception( __METHOD__ . ": Failed to create {$plugin_folder}." ); 96 97 } 97 98 } else { 99 // phpcs:ignore WordPress.Security.EscapeOutput.ExceptionNotEscaped -- CLI context, callers write the message to STDERR. 98 100 throw new Exception( __METHOD__ . ': Failed to create checkout of ' . PLUGIN_ZIP_SVN_URL . '.' ); 99 101 } … … 414 416 ! wp_list_filter( $remote_files, [ 'kind' => 'file' ] ) 415 417 ) { 418 // phpcs:ignore WordPress.Security.EscapeOutput.ExceptionNotEscaped -- CLI context, callers write the message to STDERR. 416 419 throw new Exception( __METHOD__ . ": Could not create SVN export of {$this->plugin_version_svn_url}: Path appears not to have any files." ); 417 420 } … … 425 428 } 426 429 if ( ! $res['result'] ) { 430 // phpcs:ignore WordPress.Security.EscapeOutput.ExceptionNotEscaped -- CLI context, callers write the message to STDERR. 427 431 throw new Exception( __METHOD__ . ': ' . ( $res['errors'][0]['error_message'] ?? 'unknown error' ), 404 ); 428 432 } … … 490 494 491 495 if ( $return_value ) { 496 // phpcs:ignore WordPress.Security.EscapeOutput.ExceptionNotEscaped -- CLI context, callers write the message to STDERR. 492 497 throw new Exception( __METHOD__ . ': ZIP generation failed, return code: ' . $return_value, 503 ); 493 498 } -
sites/trunk/wordpress.org/public_html/wp-content/plugins/plugin-directory/zip/class-serve.php
r13071 r15190 139 139 } 140 140 if ( ! $version ) { 141 // phpcs:ignore WordPress.Security.EscapeOutput.ExceptionNotEscaped -- Caught by serve(), which discards the message and renders a generic error. 141 142 throw new Exception( __METHOD__ . ": A version for $plugin_slug cannot be determined." ); 142 143 } … … 164 165 165 166 if ( ! $post_id ) { 167 // phpcs:ignore WordPress.Security.EscapeOutput.ExceptionNotEscaped -- Caught by serve(), which discards the message and renders a generic error. 166 168 throw new Exception( __METHOD__ . ": A post_id for $plugin_slug cannot be determined." ); 167 169 } … … 218 220 } else { 219 221 header( 'Content-Type: text/plain' ); 222 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Served as text/plain per the header above; not rendered as HTML. 220 223 echo "This is a request for $file, this server isn't currently configured to serve files.\n"; 221 224 } -
sites/trunk/wordpress.org/public_html/wp-content/plugins/support-forums/inc/class-ratings-compat.php
r15188 r15190 225 225 <div> 226 226 <div style="font-weight:bold;"><?php esc_html_e( 'Average Rating', 'wporg-forums' ); ?></div> 227 <?php echo do_blocks( '<!-- wp:wporg/ratings-stars /-->' ); ?>227 <?php echo do_blocks( '<!-- wp:wporg/ratings-stars /-->' ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. ?> 228 228 <div class="reviews-submit-link"> 229 229 <?php … … 263 263 ); 264 264 ?></div> 265 <?php echo do_blocks( '<!-- wp:wporg/ratings-bars /-->' ); ?>265 <?php echo do_blocks( '<!-- wp:wporg/ratings-bars /-->' ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. ?> 266 266 </div> 267 267 </div> -
sites/trunk/wordpress.org/public_html/wp-content/plugins/support-helphub/inc/helphub-front-page-blocks/includes/widget-front-end.php
r9092 r15190 8 8 ?> 9 9 <?php 10 echo $args['before_widget']; // WPCS: XSS OK. 10 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Widget wrapper markup supplied by register_sidebar(). 11 echo $args['before_widget']; 11 12 ?> 12 13 … … 42 43 43 44 <?php 44 echo $args['after_widget']; // WPCS: XSS OK. 45 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Widget wrapper markup supplied by register_sidebar(). 46 echo $args['after_widget']; -
sites/trunk/wordpress.org/public_html/wp-content/plugins/support-helphub/inc/helphub-manager/class-helphub-manager.php
r9159 r15190 203 203 <?php foreach ( $helphub_roles as $role => $label ) : ?> 204 204 205 <option <?php selected( $user_role, $role ); ?> value="<?php echo esc_attr( $role ); ?>"><?php echo $label; ?></option>205 <option <?php selected( $user_role, $role ); ?> value="<?php echo esc_attr( $role ); ?>"><?php echo $label; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Select markup with the escaped value assembled on the same line. ?></option> 206 206 207 207 <?php endforeach; ?> -
sites/trunk/wordpress.org/public_html/wp-content/plugins/support-helphub/inc/helphub-post-types/classes/class-helphub-post-types-post-type.php
r14527 r15190 555 555 } // End if(). 556 556 557 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Markup assembled above from escaped parts. 557 558 echo $html; 558 559 /* @codingStandardsIgnoreLine */ -
sites/trunk/wordpress.org/public_html/wp-content/plugins/theme-directory/admin-edit.php
r15179 r15190 512 512 case 'ticket': 513 513 if ( $theme->ticket ) { 514 printf( '<a href="%1$s">%2$s</a>', esc_url( 'https://themes.trac.wordpress.org/ticket/' . $theme->ticket ), '#' . $theme->ticket);514 printf( '<a href="%1$s">%2$s</a>', esc_url( 'https://themes.trac.wordpress.org/ticket/' . $theme->ticket ), esc_html( '#' . $theme->ticket ) ); 515 515 } 516 516 break; 517 517 case 'theme-url': 518 518 case 'author-url': 519 echo make_clickable( $theme->$column);519 echo wp_kses_post( make_clickable( $theme->$column ) ); 520 520 break; 521 521 default: 522 echo $theme->$column;522 echo esc_html( $theme->$column ); 523 523 } 524 524 } … … 587 587 } 588 588 ?> 589 <p><?php echo $text; ?> -590 <select name="wporg_themes_status[<?php echo base64_encode( $version ); // base64 because version numbers don't work so well as parts of keys?>]">589 <p><?php echo $text; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Version label built above with esc_html() and an (int)-cast ticket id. ?> - 590 <select name="wporg_themes_status[<?php echo esc_attr( base64_encode( $version ) ); // base64 because version numbers don't work so well as parts of keys. ?>]"> 591 591 <option value="new" <?php selected( $status, 'new' ); ?>><?php esc_html_e( 'New', 'wporg-themes' ); ?></option> 592 592 <?php if ( 'approved' === $status ) : ?> -
sites/trunk/wordpress.org/public_html/wp-content/plugins/theme-directory/class-wporg-themes-upload.php
r15179 r15190 1028 1028 1029 1029 // Output the Theme Check results. This is the only HTML that this function outputs. 1030 echo $theme_check_output;1030 echo wp_kses_post( $theme_check_output ); 1031 1031 1032 1032 if ( ! $result && $args['block_on_themecheck'] ) { … … 1443 1443 /* translators: %s: Scan verdict. */ 1444 1444 echo '<h2>' . sprintf( esc_html__( 'Results of Automated Theme Scanning: %s', 'wporg-themes' ), vsprintf( '<span class="%1$s">%2$s</span>', array_map( 'esc_html', $verdict ) ) ) . '</h2>'; 1445 echo '<ul class="tc-result">' . display_themechecks() . '</ul>';1445 echo '<ul class="tc-result">' . wp_kses_post( display_themechecks() ) . '</ul>'; 1446 1446 echo '<div class="notice notice-info"><p>' . esc_html__( 'Note: While the automated theme scan is based on the Theme Review Guidelines, it is not a complete review. A successful result from the scan does not guarantee that the theme will pass review. All submitted themes are reviewed manually before approval.', 'wporg-themes' ) . '</p></div>'; 1447 1447 -
sites/trunk/wordpress.org/public_html/wp-content/plugins/theme-directory/jobs/class-svn-import.php
r15115 r15190 59 59 60 60 if ( ! $last_revision ) { 61 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Written to the error log by trigger_error(), not rendered. 61 62 trigger_error( "Theme Importing aborting, no starting revision known. Set 'svn_import_last_revision' option. Latest Revision: [{$latest_revision}]", E_USER_WARNING ); 62 63 return; … … 145 146 return; 146 147 } else { 148 // phpcs:ignore WordPress.Security.EscapeOutput.ExceptionNotEscaped -- Cron import task; the message is logged, not rendered. 147 149 throw new Exception( 'Theme Import Failure: ' . $return->get_error_code() . ' ' . $return->get_error_message() ); 148 150 } -
sites/trunk/wordpress.org/public_html/wp-content/plugins/theme-directory/rest-api.php
r15082 r15190 38 38 39 39 if ( defined( 'THEMES_API_VERSION' ) && '1.0' === THEMES_API_VERSION ) { 40 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- API response body (serialized PHP); escaping would corrupt the format. 40 41 echo serialize( $result ); 41 42 exit; -
sites/trunk/wordpress.org/public_html/wp-content/plugins/theme-directory/rest-api/class-internal.php
r14896 r15190 74 74 echo "* = r\n"; 75 75 foreach ( array_unique( $all_access_users ) as $u ) { 76 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Generates SVN authz config text, not HTML. 76 77 echo "{$u} = rw\n"; 77 78 } … … 87 88 printf( 88 89 "[%s]\n%s = rw\n\n", 90 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Generates SVN authz config text, not HTML. 89 91 '/' . $r->slug, 92 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Generates SVN authz config text, not HTML. 90 93 $r->user 91 94 ); -
sites/trunk/wordpress.org/public_html/wp-content/plugins/theme-directory/theme-directory.php
r15179 r15190 380 380 $user = new WP_User($value); 381 381 382 echo "<input type='text' id='post_author_username' value='{$user->user_login}' />";383 echo "<input type='hidden' id='post_author_override' name='post_author_override' value='{$value}' />";382 printf( '<input type="text" id="post_author_username" value="%s" />', esc_attr( $user->user_login ) ); 383 printf( '<input type="hidden" id="post_author_override" name="post_author_override" value="%s" />', esc_attr( $value ) ); 384 384 ?> 385 385 <script> 386 386 jQuery( document ).ready( function( $ ) { 387 387 $( "#post_author_username" ).autocomplete( { 388 source: ajaxurl + '?action=author-lookup&_ajax_nonce=<?php echo wp_create_nonce( 'wporg_themes_author_lookup'); ?>',388 source: ajaxurl + '?action=author-lookup&_ajax_nonce=<?php echo esc_js( wp_create_nonce( 'wporg_themes_author_lookup' ) ); ?>', 389 389 minLength: 2, 390 390 delay: 700, -
sites/trunk/wordpress.org/public_html/wp-content/plugins/wp-i18n-teams/views/all-locales.php
r15179 r15190 21 21 $string = translate_nooped_plural( $nooped_plural, $locale_data['status_counts'][ $status ] ); 22 22 $string = sprintf( $string, sprintf( '<strong class="i18n-label %s">%s</strong>', $status, $locale_data['status_counts'][ $status ] ) ); 23 printf( ' <a href="#%s" class="i18n-filter" data-filter="%s">%s</a>', $status, $status, $string);23 printf( ' <a href="#%s" class="i18n-filter" data-filter="%s">%s</a>', esc_attr( $status ), esc_attr( $status ), wp_kses_post( $string ) ); 24 24 } 25 25 ?> … … 49 49 $string = translate_nooped_plural( $nooped_plural, $locale_data['status_counts'][ $status ] ); 50 50 $string = sprintf( $string, sprintf( '<strong class="i18n-label %s">%s</strong>', $status, $locale_data['status_counts'][ $status ] ) ); 51 printf( ' <a href="#%s" class="i18n-filter" data-filter="%s">%s</a>', $status, $status, $string);51 printf( ' <a href="#%s" class="i18n-filter" data-filter="%s">%s</a>', esc_attr( $status ), esc_attr( $status ), wp_kses_post( $string ) ); 52 52 } 53 53 ?> … … 82 82 $classes .= ' ' . $locale_data[ $locale->wp_locale ]['language_pack_status']; 83 83 ?> 84 <tr class="<?php echo trim( $classes); ?>">84 <tr class="<?php echo esc_attr( trim( $classes ) ); ?>"> 85 85 <td data-column-title="<?php esc_attr_e( 'Locale', 'wporg' ); ?>" class="no-right-border"> 86 86 <?php if ( $locale_data[ $locale->wp_locale ]['rosetta_site_url'] ) : ?> … … 112 112 <?php 113 113 if ( isset( $language_packs_data[ $locale->wp_locale ] ) ) { 114 echo max( $language_packs_data[ $locale->wp_locale ]);114 echo esc_html( max( $language_packs_data[ $locale->wp_locale ] ) ); 115 115 } else { 116 116 esc_html_e( 'No LP', 'wporg' ); … … 126 126 $locale_slug = false !== strpos( $locale->slug, '/' ) ? $locale->slug : $locale->slug . '/default'; 127 127 ?> 128 <a href="https://translate.wordpress.org/locale/<?php echo $locale_slug; ?>/wp/dev">129 <?php echo $percentages[ $locale->wp_locale ] . '%'; ?>128 <a href="https://translate.wordpress.org/locale/<?php echo esc_attr( $locale_slug ); ?>/wp/dev"> 129 <?php echo esc_html( $percentages[ $locale->wp_locale ] . '%' ); ?> 130 130 </a> 131 131 <?php … … 138 138 </td> 139 139 <td class="center no-left-border nowrap"> 140 <a href="https://translate.wordpress.org/locale/<?php echo $locale->slug; ?>">141 <?php echo $locale->slug; ?>140 <a href="https://translate.wordpress.org/locale/<?php echo esc_attr( $locale->slug ); ?>"> 141 <?php echo esc_html( $locale->slug ); ?> 142 142 </a> 143 143 </td> -
sites/trunk/wordpress.org/public_html/wp-content/plugins/wp-i18n-teams/views/locale-details.php
r15179 r15190 22 22 <?php 23 23 if ( $locale_data['sites'] ) : 24 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Anchor list assembled above from esc_url() and esc_html() escaped parts. 24 25 echo implode( ', ', array_map( function( $site ) { 25 26 return sprintf( … … 36 37 <li> 37 38 <strong><?php esc_html_e( 'Latest release:', 'wporg' ); ?></strong> 38 <?php echo $locale_data['latest_release'] ? $locale_data['latest_release']: '—'; ?>39 <?php echo $locale_data['latest_release'] ? esc_html( $locale_data['latest_release'] ) : '—'; ?> 39 40 </li> 40 41 <li> … … 48 49 <li> 49 50 <strong><?php esc_html_e( 'Translation Projects:', 'wporg' ); ?></strong> 50 <a href="https://translate.wordpress.org/locale/<?php echo $locale->slug; ?>">translate.wordpress.org/locale/<?php echo $locale->slug; ?></a>51 <a href="https://translate.wordpress.org/locale/<?php echo esc_attr( $locale->slug ); ?>">translate.wordpress.org/locale/<?php echo esc_html( $locale->slug ); ?></a> 51 52 </li> 52 53 </ul> … … 156 157 ); 157 158 } 159 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Anchor list assembled above from esc_url() and esc_html() escaped parts. 158 160 echo wp_sprintf( '%l.', $translators ); 159 161 ?> … … 175 177 ); 176 178 } 179 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Anchor list assembled above from esc_url() and esc_html() escaped parts. 177 180 echo wp_sprintf( '%l.', $translators ); 178 181 ?> -
sites/trunk/wordpress.org/public_html/wp-content/plugins/wporg-badge-management/admin.php
r15188 r15190 121 121 } 122 122 echo '</ul>'; 123 echo '<textarea rows="10" style="width:100%">' . implode( ', ', wp_list_pluck( $users, 'user_login') ) . '</textarea>';123 echo '<textarea rows="10" style="width:100%">' . esc_textarea( implode( ', ', wp_list_pluck( $users, 'user_login' ) ) ) . '</textarea>'; 124 124 } else { 125 125 echo '<p><em>No users have this badge.</em></p>'; … … 155 155 156 156 if ( $messages ) { 157 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Notice built from a literal format string with intval()-cast counts. 157 158 echo '<div id="message" class="updated notice is-dismissible"><p>' . implode( '<br>', $messages ) . '</p></div>'; 158 159 } -
sites/trunk/wordpress.org/public_html/wp-content/plugins/wporg-bbp-term-subscription/inc/class-plugin.php
r14760 r15190 153 153 echo '<div class="notice notice-info notice-alt with-dashicon">'; 154 154 echo '<span class="dashicons dashicons-email-alt"></span>'; 155 echo "<p>{$message}</p>";155 printf( '<p>%s</p>', wp_kses_post( $message ) ); 156 156 echo '</div>'; 157 157 } … … 207 207 ' <a href="%6$s">%7$s</a>' . 208 208 '</form>', 209 get_bloginfo('name'),209 esc_html( get_bloginfo( 'name' ) ), 210 210 sprintf( 211 211 /* translators: 1: Plugin, Theme, or Tag name. */ 212 212 esc_html__( 'Do you wish to unsubscribe from future emails for %s?', 'wporg-forums' ), 213 $term->name213 esc_html( $term->name ) 214 214 ), 215 215 esc_attr( $_SERVER['REQUEST_URI'] ), -
sites/trunk/wordpress.org/public_html/wp-content/plugins/wporg-bbp-topic-resolution/inc/class-plugin.php
r15179 r15190 233 233 $user_id = get_current_user_id(); 234 234 if ( bbp_is_topic_edit() || ! $this->user_can_resolve( $user_id, $topic_id ) ) { 235 printf( esc_html__( 'Status: %s', 'wporg-forums' ), $resolutions[ $resolution ] ); 235 /* translators: %s: Resolution status. */ 236 printf( esc_html__( 'Status: %s', 'wporg-forums' ), esc_html( $resolutions[ $resolution ] ) ); 236 237 237 238 // Display the form to update the topic resolution. -
sites/trunk/wordpress.org/public_html/wp-content/plugins/wporg-bbp-user-badges/inc/class-plugin.php
r15044 r15190 256 256 257 257 if ( $output ) { 258 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Badge markup assembled by format_badge() from escaped parts. 258 259 echo $this->format_badge( $output['type'], $output['label'], $output['help'] ); 259 260 } -
sites/trunk/wordpress.org/public_html/wp-content/plugins/wporg-cli/inc/class-markdown-import.php
r15024 r15190 192 192 $response = self::update_post_from_markdown_source( $post_id ); 193 193 if ( is_wp_error( $response ) ) { 194 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI import error; the message is written to the console. 194 195 wp_die( $response->get_error_message() ); 195 196 } -
sites/trunk/wordpress.org/public_html/wp-content/plugins/wporg-github-invite/admin.php
r15188 r15190 66 66 printf( 67 67 '<div class="notice notice-%s is-dismissable"><p>%s</p></div>', 68 $class,69 $message68 esc_attr( $class ), 69 wp_kses_post( $message ) 70 70 ); 71 71 } … … 81 81 <tr> 82 82 <th scope="row"><label for="invite">GitHub Email, GitHub URL, WordPress.org user slug, or WordPress.org Profile URL</label></th> 83 <td><input type="text" name="invite" id="invite" class="regular-text" placeholder="https://profiles.wordpress.org/<?php echo wp_get_current_user()->user_nicename; ?>/"></td>83 <td><input type="text" name="invite" id="invite" class="regular-text" placeholder="https://profiles.wordpress.org/<?php echo esc_attr( wp_get_current_user()->user_nicename ); ?>/"></td> 84 84 </tr> 85 85 <tr> … … 120 120 %s 121 121 </p>', 122 $pending->login ?: $pending->email,122 esc_html( $pending->login ?: $pending->email ), 123 123 esc_html( human_time_diff( strtotime( $pending->created_at ) ) ), 124 124 $cancel_url ? '<a class="button" href="' . esc_url( $cancel_url ) . '">Cancel</a>' : '' -
sites/trunk/wordpress.org/public_html/wp-content/plugins/wporg-gp-customizations/inc/cli/class-duplicate-translations.php
r14672 r15190 155 155 $result['translation_set_id'], 156 156 ); 157 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI query output written to the console, not HTML. 157 158 echo $prepared_query . "\n"; 158 159 // phpcs:ignore WordPress.DB.PreparedSQL.NotPrepared -
sites/trunk/wordpress.org/public_html/wp-content/plugins/wporg-gp-customizations/templates/footer.php
r11494 r15190 3 3 <?php 4 4 5 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 5 6 echo do_blocks( '<!-- wp:wporg/global-footer /-->' ); -
sites/trunk/wordpress.org/public_html/wp-content/plugins/wporg-gp-customizations/templates/header.php
r15188 r15190 1 1 <?php 2 2 3 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 3 4 echo do_blocks( '<!-- wp:wporg/global-header /-->' ); 4 5 -
sites/trunk/wordpress.org/public_html/wp-content/plugins/wporg-gp-help/wporg-gp-help.php
r13164 r15190 27 27 function after_hello() { 28 28 if ( is_user_logged_in() || $this->is_notice_hidden() ) { 29 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Help link markup built here from a class constant. 29 30 echo '<em><a class="secondary" href="' . self::handbook_link . '">Need help?</a></em>'; 30 31 } … … 51 52 <p> 52 53 New to Translating WordPress? 53 Read through our <a href="<?php echo self::handbook_link; ?>" target="_blank">Translator Handbook</a> to get started.54 Read through our <a href="<?php echo esc_url( self::handbook_link ); ?>" target="_blank">Translator Handbook</a> to get started. 54 55 <a id="hide-help-notice" class="secondary" style="float: right;" href="<?php echo esc_url( $hide_url ); ?>">Hide</a> 55 56 </p> -
sites/trunk/wordpress.org/public_html/wp-content/plugins/wporg-gp-profiles/tests/e2e.php
r11975 r15190 36 36 add_action( 'gp_pre_can_user', __NAMESPACE__ . '\grant_editor_capabilities', 10, 2 ); 37 37 call_user_func( __NAMESPACE__ . "\\test_$case", $translator ); 38 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Test script console output, not HTML. 38 39 echo "\nThe daily digest count should have been bumped on https://profiles.wordpress.org/$translator->user_nicename/, and/or the reviewer. \n"; 39 40 40 41 } catch ( Exception $exception ) { 42 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Test script console output, not HTML. 41 43 echo $exception->getMessage(); 42 44 } -
sites/trunk/wordpress.org/public_html/wp-content/plugins/wporg-gp-rosetta-roles/inc/admin/list-table/class-translators.php
r15179 r15190 160 160 ?> 161 161 <label class="screen-reader-text" for="cb-select-<?php echo (int) $user->ID; ?>"><?php esc_html_e( 'Select translator', 'wporg-translate' ); ?></label> 162 <input id="cb-select-<?php echo $user->ID; ?>" type="checkbox" name="translators[]" value="<?php echo$user->ID; ?>">162 <input id="cb-select-<?php echo (int) $user->ID; ?>" type="checkbox" name="translators[]" value="<?php echo (int) $user->ID; ?>"> 163 163 <?php 164 164 } … … 185 185 } 186 186 187 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Avatar and edit-link markup assembled above from escaped parts. 187 188 echo "$avatar $edit"; 188 189 } … … 194 195 */ 195 196 public function column_name( $user ) { 196 echo "$user->first_name $user->last_name";197 echo esc_html( "$user->first_name $user->last_name" ); 197 198 } 198 199 … … 203 204 */ 204 205 public function column_email( $user ) { 205 echo "<a href='" . esc_url( "mailto:$user->user_email" ) . "'>$user->user_email</a>";206 printf( '<a href="%1$s">%2$s</a>', esc_url( "mailto:$user->user_email" ), esc_html( $user->user_email ) ); 206 207 } 207 208 … … 218 219 , $user->ID ) ); 219 220 220 echo implode( ', ', $locales);221 echo implode( ', ', array_map( 'esc_html', $locales ) ); 221 222 } 222 223 } -
sites/trunk/wordpress.org/public_html/wp-content/plugins/wporg-gp-translation-suggestions/templates/other-languages-suggestions.php
r12765 r15190 10 10 11 11 echo '<span class="translation-suggestion__translation">'; 12 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- esc_translation() escapes the markup and double-encodes existing entities so the translation renders exactly as written. 12 13 echo esc_translation( $suggestion['translation'] ); 13 14 … … 26 27 printf( 27 28 ' | By <a href="https://profiles.wordpress.org/%s">%s</a>', 28 $user->user_nicename,29 esc_html( $user->user_nicename ), 29 30 esc_html( $user->display_name ) 30 31 ); … … 35 36 echo '</span>'; 36 37 38 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- esc_translation() escapes the markup and double-encodes existing entities so the translation renders exactly as written. 37 39 echo '<span aria-hidden="true" class="translation-suggestion__translation-raw">' . esc_translation( $suggestion['translation'] ) . '</span>'; 38 40 -
sites/trunk/wordpress.org/public_html/wp-content/plugins/wporg-gp-translation-suggestions/templates/translation-memory-suggestions.php
r12765 r15190 17 17 echo '</span>'; 18 18 echo '<span class="translation-suggestion__translation">'; 19 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- esc_translation() escapes the markup and double-encodes existing entities so the translation renders exactly as written. 19 20 echo esc_translation( $suggestion['translation'] ); 20 21 … … 24 25 echo '</span>'; 25 26 27 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- esc_translation() escapes the markup and double-encodes existing entities so the translation renders exactly as written. 26 28 echo '<span aria-hidden="true" class="translation-suggestion__translation-raw">' . esc_translation( $suggestion['translation'] ) . '</span>'; 27 29 -
sites/trunk/wordpress.org/public_html/wp-content/plugins/wporg-markdown/inc/class-editor.php
r13074 r15190 68 68 '<div class="notice notice-warning"><p>%s</p><p><a href="%s">%s</a></p></div>', 69 69 'This page is maintained on GitHub. Content, title, and slug edits here will be discarded on next sync.', 70 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Edit link markup assembled above from escaped parts. 70 71 $this->get_markdown_edit_link( $post->ID ), 71 72 'Edit on GitHub' -
sites/trunk/wordpress.org/public_html/wp-content/plugins/wporg-profiles-wp-activity-notifier/tests/e2e.php
r12019 r15190 39 39 restore_current_blog(); 40 40 41 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Test script console output, not HTML. 41 42 echo "\nThere should be new activity on https://profiles.wordpress.org/$user->user_nicename/ \n"; 42 43 } -
sites/trunk/wordpress.org/public_html/wp-content/plugins/wporg-trac-watcher/svn.php
r15103 r15190 91 91 $last_revision = 0; 92 92 // When setting up a new table, this needs to be commented out to force the import. 93 trigger_error( "Can't find max row for {$db_table} to import {$svn_url} revisions.", E_USER_WARNING ); 93 trigger_error( "Can't find max row for {$db_table} to import {$svn_url} revisions.", E_USER_WARNING ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Written to the error log by trigger_error(), not rendered. 94 94 return false; 95 95 } -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-breathe-2024/archive-component.php
r14020 r15190 13 13 <div id="primary" class="content-area"> 14 14 <div role="main"> 15 <h1><?php printf( 'WordPress %s Components', $trac_name); ?></h1>15 <h1><?php printf( 'WordPress %s Components', esc_html( $trac_name ) ); ?></h1> 16 16 17 17 <?php 18 18 if ( $cached = get_transient( 'trac_components_page' ) ) { 19 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Component page content plus the table the component_table_row action renders. 19 20 echo $cached; 20 21 } else { … … 34 35 $cache = ob_get_clean(); 35 36 set_transient( 'trac_components_page', $cache, 300 ); 37 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Component page content plus the table the component_table_row action renders. 36 38 echo $cache; 37 39 } -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-breathe-2024/footer.php
r14020 r15190 14 14 <?php 15 15 16 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 16 17 echo do_blocks( '<!-- wp:wporg/global-footer /-->' ); -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-breathe-2024/functions.php
r15179 r15190 399 399 ><span><?php esc_html_e( 'Hide welcome box', 'wporg' ); ?></span></button> 400 400 </div> 401 <div class="entry-content clear" id="make-welcome-content" data-cookie="<?php echo $cookie; ?>" data-hash="<?php echo $content_hash; ?>">401 <div class="entry-content clear" id="make-welcome-content" data-cookie="<?php echo esc_attr( $cookie ); ?>" data-hash="<?php echo esc_attr( $content_hash ); ?>"> 402 402 <script type="text/javascript"> 403 403 const elContent = document.getElementById( 'make-welcome-content' ); … … 726 726 727 727 ?> 728 <nav role="navigation" id="<?php echo esc_attr( $nav_id ); ?>" class="<?php echo $nav_class; ?>">728 <nav role="navigation" id="<?php echo esc_attr( $nav_id ); ?>" class="<?php echo esc_attr( $nav_class ); ?>"> 729 729 <h2 class="screen-reader-text"><?php esc_html_e( 'Post navigation', 'wporg' ); ?></h2> 730 730 -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-breathe-2024/header.php
r14638 r15190 3 3 \WordPressdotorg\skip_to( '#primary' ); 4 4 5 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 5 6 echo do_blocks( '<!-- wp:wporg/global-header {"style":{"border":{"bottom":{"color":"var:preset|color|white-opacity-15","style":"solid","width":"1px"}}}} /-->' ); 6 7 7 8 if ( is_front_page() && is_home() ) { 9 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 8 10 echo do_blocks( '<!-- wp:wporg/local-navigation-bar {"className":"has-display-contents","backgroundColor":"charcoal-2","style":{"elements":{"link":{"color":{"text":"var:preset|color|white"},":hover":{"color":{"text":"var:preset|color|white"}}}}},"textColor":"white","fontSize":"small"} --> 9 11 … … 26 28 $before_name = ob_get_clean(); 27 29 30 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 28 31 echo do_blocks( 29 32 sprintf( -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-breathe-2024/o2-comment.php
r14020 r15190 13 13 14 14 // Remove `rel` attributes on comment urls. 15 echo str_replace( 'rel="external nofollow" ', '', $comment_template ); 15 echo str_replace( 'rel="external nofollow" ', '', $comment_template ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- o2 comment template markup with the rel attribute stripped. -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-login/functions-registration.php
r15179 r15190 67 67 if ( null !== ( $pre_register_error = apply_filters( 'wporg_login_pre_registration', null, $user_login, $user_email, $meta ) ) ) { 68 68 if ( is_wp_error( $pre_register_error ) ) { 69 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Registration error markup assembled from escaped parts. 69 70 wp_die( $pre_register_error ); 70 71 } -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-main/front-page.php
r15188 r15190 13 13 * @package WordPressdotorg\Theme 14 14 */ 15 16 // phpcs:disable WordPress.XSS.EscapeOutput.UnsafePrintingFunction, WordPress.XSS.EscapeOutput.OutputNotEscaped17 15 18 16 namespace WordPressdotorg\MainTheme; … … 82 80 } 83 81 </style> 84 <?php echo do_blocks( $banner_blocks ); ?>82 <?php echo do_blocks( $banner_blocks ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. ?> 85 83 86 84 <header id="masthead" class="site-header" role="banner"> … … 246 244 247 245 the_title( sprintf( '<h5><a href="%s" rel="bookmark">', esc_url( get_permalink() ) ), '</a></h5>' ); 246 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Thumbnail markup and the_excerpt filter output; escaping would print the markup. 248 247 echo '<div class="entry-summary">' . apply_filters( 'the_excerpt', get_the_excerpt() ) . '</div>'; 249 248 } … … 322 321 '<div class="col-3"><a href="%1$s">%2$s</a></div>', 323 322 esc_url( $post_url ), 323 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Thumbnail markup and the_excerpt filter output; escaping would print the markup. 324 324 $thumbnail 325 325 ); … … 344 344 '<li><a href="%1$s"><img src="https://s.w.org/images/notableusers/%2$s-2x.png?version=2" alt="%2$s" width="130" height="57" /></a></li>', 345 345 esc_url( $user_links[ $slug ] ), 346 $slug346 esc_attr( $slug ) 347 347 ); 348 348 endforeach; -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-main/header-child-page.php
r11448 r15190 20 20 <header id="masthead" class="site-header col-12" role="banner"> 21 21 <div class="site-branding"> 22 <p class="site-title"><a href="<?php echo esc_url( get_permalink( get_post()->post_parent ) ); ?>" rel="bookmark"><?php echo get_the_title( get_post()->post_parent); ?></a></p>22 <p class="site-title"><a href="<?php echo esc_url( get_permalink( get_post()->post_parent ) ); ?>" rel="bookmark"><?php echo esc_html( get_the_title( get_post()->post_parent ) ); ?></a></p> 23 23 24 24 <?php if ( ! empty( $menu_items ) ) : ?> -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-main/header-top-level-page.php
r11448 r15190 35 35 <h1 class="site-title"> 36 36 <a href="<?php echo esc_url( get_permalink() ); ?>" rel="bookmark"> 37 <?php echo get_the_title(); ?>37 <?php echo esc_html( get_the_title() ); ?> 38 38 </a> 39 39 </h1> -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-main/page-about-requirements.php
r11866 r15190 46 46 <?php 47 47 /* translators: 1: URL to PHP; 2: PHP Version */ 48 printf( wp_kses_post( __( '<a href="%1$s">PHP</a> version %2$s or greater.', 'wporg' ) ), 'https://www.php.net/', RECOMMENDED_PHP);48 printf( wp_kses_post( __( '<a href="%1$s">PHP</a> version %2$s or greater.', 'wporg' ) ), esc_url( 'https://www.php.net/' ), esc_html( RECOMMENDED_PHP ) ); 49 49 ?> 50 50 </li> … … 82 82 /* translators: 1: PHP Version including; 2: MySQL Version */ 83 83 wp_kses_post( __( 'Note: If you are in a legacy environment where you only have older PHP or MySQL versions, WordPress also works with PHP %1$s+ and MySQL %2$s+, but these versions have reached official End Of Life and as such <strong>may expose your site to security vulnerabilities</strong>.', 'wporg' ) ), 84 MINIMUM_PHP,84 esc_html( MINIMUM_PHP ), 85 85 '5.0' 86 86 ); … … 99 99 <?php 100 100 /* translators: PHP Version */ 101 printf( esc_html__( 'PHP %s or greater', 'wporg' ), RECOMMENDED_PHP);101 printf( esc_html__( 'PHP %s or greater', 'wporg' ), esc_html( RECOMMENDED_PHP ) ); 102 102 ?> 103 103 </li> -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-main/page-download.php
r15179 r15190 87 87 "fileFormat": "application/zip", 88 88 "downloadUrl": "<?php echo esc_url( $latest_release_zip_url ); ?>", 89 "dateModified": "<?php echo gmdate( 'Y-m-d\TH:i:s\+00:00', $latest_release_zip_ts); ?>",89 "dateModified": "<?php echo esc_attr( gmdate( 'Y-m-d\TH:i:s\+00:00', $latest_release_zip_ts ) ); ?>", 90 90 "applicationCategory": "WebApplication", 91 91 "offers": { … … 245 245 /* translators: 1: PHP version; 2: URL to PHP website; 3: URL to MySQL website; 4: MySQL version; 5: URL to MariaDB website; 6: MariaDB version */ 246 246 wp_kses_post( __( 'We recommend servers running version %1$s or greater of <a href="%2$s">PHP</a> and <a href="%3$s">MySQL</a> version %4$s <em>OR</em> <a href="%5$s">MariaDB</a> version %6$s or greater.', 'wporg' ) ), 247 RECOMMENDED_PHP,247 esc_html( RECOMMENDED_PHP ), 248 248 'https://www.php.net/', 249 249 'https://www.mysql.com/', -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-main/page-hosting.php
r14853 r15190 38 38 <img 39 39 alt="" 40 src="https://s.w.org/hosting/pressable.png?<?php echo $hosting_cache_buster; ?>"40 src="https://s.w.org/hosting/pressable.png?<?php echo esc_attr( $hosting_cache_buster ); ?>" 41 41 height="100" 42 42 width="100" … … 60 60 <img 61 61 alt="" 62 src="https://s.w.org/hosting/bluehost.png?<?php echo $hosting_cache_buster; ?>"62 src="https://s.w.org/hosting/bluehost.png?<?php echo esc_attr( $hosting_cache_buster ); ?>" 63 63 height="100" 64 64 width="100" … … 82 82 <img 83 83 alt="" 84 src="https://s.w.org/hosting/hostinger.png?<?php echo $hosting_cache_buster; ?>"84 src="https://s.w.org/hosting/hostinger.png?<?php echo esc_attr( $hosting_cache_buster ); ?>" 85 85 height="100" 86 86 width="100" … … 105 105 <img 106 106 alt="" 107 src="https://s.w.org/hosting/dreamhost.png?<?php echo $hosting_cache_buster; ?>"107 src="https://s.w.org/hosting/dreamhost.png?<?php echo esc_attr( $hosting_cache_buster ); ?>" 108 108 height="100" 109 109 width="100" -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-openverse/header.php
r11496 r15190 14 14 \WordPressdotorg\skip_to( '#content' ); 15 15 16 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 16 17 echo do_blocks( '<!-- wp:wporg/global-header /-->' ); 17 18 -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/build/blocks/archive-page/render.php
r13792 r15190 13 13 $archive_description = get_the_archive_description(); 14 14 15 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 15 16 echo do_blocks( <<<BLOCKS 16 17 <!-- wp:group {"align":"wide","style":{"spacing":{"padding":{"top":"var:preset|spacing|40"}}},"layout":{"type":"default"}} --> -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/build/blocks/category-navigation/render.php
r13692 r15190 19 19 FILTERS; 20 20 21 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 21 22 echo do_blocks( $filter_blocks ); 22 23 … … 24 25 } 25 26 27 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 26 28 echo do_blocks( '<!-- wp:navigation {"menuSlug":"section-bar","ariaLabel":"'. esc_attr( 'Category menu', 'wporg-plugins' ) .'","overlayMenu":"never","layout":{"type":"flex","orientation":"horizontal","justifyContent":"left","flexWrap":"nowrap"},"fontSize":"small","className":"is-style-button-list"} /-->' ); -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/build/blocks/filter-bar/render.php
r13927 r15190 7 7 $search_button = esc_attr__( 'Search plugins', 'wporg-plugins' ); 8 8 9 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 9 10 echo do_blocks( <<<BLOCKS 10 11 <!-- wp:group {"align":"wide","className":"wporg-filter-bar wporg-plugins__filters wporg-plugins__filters__no-count","layout":{"type":"flex","flexWrap":"wrap","justifyContent":"space-between"}} --> -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/build/blocks/front-page/render.php
r14487 r15190 20 20 ); 21 21 22 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 22 23 echo do_blocks( '<!-- wp:template-part {"slug":"grid-controls"} /-->' ); 23 24 … … 83 84 <section class="plugin-section"> 84 85 <header class="section-header"> 85 <?php echo $title; ?>86 <?php echo $title; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() output and Template::get_plugin_icon() markup; escaping would print the markup. ?> 86 87 <a class="section-link" href="<?php echo esc_url( home_url( "browse/$browse/" ) ); ?>"> 87 88 <?php … … 96 97 97 98 <?php 99 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 98 100 echo do_blocks( <<<BLOCKS 99 101 <!-- wp:query {"tagName":"div","className":"plugin-cards"} --> -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/build/blocks/plugin-card/render.php
r15153 r15190 12 12 <div class="entry"> 13 13 <div class="entry-thumbnail"> 14 <?php echo Template::get_plugin_icon( get_post(), 'html' ); ?>14 <?php echo Template::get_plugin_icon( get_post(), 'html' ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() output and Template::get_plugin_icon() markup; escaping would print the markup. ?> 15 15 </div> 16 16 -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/build/blocks/search-page/render.php
r13691 r15190 2 2 namespace WordPressdotorg\Theme\Plugins_2024\SearchPage; 3 3 4 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 4 5 echo do_blocks( <<<BLOCKS 5 6 <!-- wp:template-part {"slug":"grid-controls"} /--> -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/embed-plugin.php
r15153 r15190 121 121 <p class="wp-embed-heading"> 122 122 <a href="<?php the_permalink(); ?>" target="_top"> 123 <?php echo Template::get_plugin_icon( $post, 'html' ); /* phpcs:ignore WordPress. XSS.EscapeOutput.OutputNotEscaped */ ?>123 <?php echo Template::get_plugin_icon( $post, 'html' ); /* phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped */ ?> 124 124 <?php the_title(); ?> 125 125 </a> -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/inc/template-tags.php
r15179 r15190 59 59 */ 60 60 function the_plugin_banner( $post = null ) { 61 echo Template::get_plugin_banner( $post, 'html' ); // phpcs:ignore WordPress. XSS.EscapeOutput.OutputNotEscaped61 echo Template::get_plugin_banner( $post, 'html' ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped 62 62 } 63 63 … … 80 80 if ( $is_favorited ) { 81 81 /* translators: %s: plugin name */ 82 printf( esc_html__( 'Unfavorite %s', 'wporg-plugins' ), get_the_title() );82 printf( esc_html__( 'Unfavorite %s', 'wporg-plugins' ), esc_html( get_the_title() ) ); 83 83 } else { 84 84 /* translators: %s: plugin name */ 85 printf( esc_html__( 'Favorite %s', 'wporg-plugins' ), get_the_title() );85 printf( esc_html__( 'Favorite %s', 'wporg-plugins' ), esc_html( get_the_title() ) ); 86 86 } 87 87 ?> … … 310 310 printf( 311 311 '<div class="plugin-notice notice notice-warning notice-alt"><p>%s</p></div>', 312 $message312 wp_kses_post( $message ) 313 313 ); 314 314 } … … 565 565 $close_button_text = sprintf( __( 'I understand, please close %s.', 'wporg-plugins' ), get_the_title() ); 566 566 ?> 567 <div class="wp-block-button is-small"><button class="show-dialog wp-block-button__link" onclick="this.parentNode.nextElementSibling.showModal()"><?php echo $close_button_text; ?></button></div>567 <div class="wp-block-button is-small"><button class="show-dialog wp-block-button__link" onclick="this.parentNode.nextElementSibling.showModal()"><?php echo esc_html( $close_button_text ); ?></button></div> 568 568 <dialog> 569 569 <a onclick="this.parentNode.close()" class="close dashicons dashicons-no-alt"></a> … … 580 580 /* translators: %s: The plugin name. */ 581 581 esc_html__( 'Yes, I wish to close %s.', 'wporg-plugins' ), 582 '<code>' . get_the_title() . '</code>'582 '<code>' . esc_html( get_the_title() ) . '</code>' 583 583 ); ?> 584 584 </label> -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/src/blocks/archive-page/render.php
r13792 r15190 13 13 $archive_description = get_the_archive_description(); 14 14 15 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 15 16 echo do_blocks( <<<BLOCKS 16 17 <!-- wp:group {"align":"wide","style":{"spacing":{"padding":{"top":"var:preset|spacing|40"}}},"layout":{"type":"default"}} --> -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/src/blocks/category-navigation/render.php
r13692 r15190 19 19 FILTERS; 20 20 21 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 21 22 echo do_blocks( $filter_blocks ); 22 23 … … 24 25 } 25 26 27 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 26 28 echo do_blocks( '<!-- wp:navigation {"menuSlug":"section-bar","ariaLabel":"'. esc_attr( 'Category menu', 'wporg-plugins' ) .'","overlayMenu":"never","layout":{"type":"flex","orientation":"horizontal","justifyContent":"left","flexWrap":"nowrap"},"fontSize":"small","className":"is-style-button-list"} /-->' ); -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/src/blocks/filter-bar/render.php
r13927 r15190 7 7 $search_button = esc_attr__( 'Search plugins', 'wporg-plugins' ); 8 8 9 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 9 10 echo do_blocks( <<<BLOCKS 10 11 <!-- wp:group {"align":"wide","className":"wporg-filter-bar wporg-plugins__filters wporg-plugins__filters__no-count","layout":{"type":"flex","flexWrap":"wrap","justifyContent":"space-between"}} --> -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/src/blocks/front-page/render.php
r14487 r15190 20 20 ); 21 21 22 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 22 23 echo do_blocks( '<!-- wp:template-part {"slug":"grid-controls"} /-->' ); 23 24 … … 83 84 <section class="plugin-section"> 84 85 <header class="section-header"> 85 <?php echo $title; ?>86 <?php echo $title; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() output and Template::get_plugin_icon() markup; escaping would print the markup. ?> 86 87 <a class="section-link" href="<?php echo esc_url( home_url( "browse/$browse/" ) ); ?>"> 87 88 <?php … … 96 97 97 98 <?php 99 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 98 100 echo do_blocks( <<<BLOCKS 99 101 <!-- wp:query {"tagName":"div","className":"plugin-cards"} --> -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/src/blocks/plugin-card/render.php
r15153 r15190 12 12 <div class="entry"> 13 13 <div class="entry-thumbnail"> 14 <?php echo Template::get_plugin_icon( get_post(), 'html' ); ?>14 <?php echo Template::get_plugin_icon( get_post(), 'html' ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() output and Template::get_plugin_icon() markup; escaping would print the markup. ?> 15 15 </div> 16 16 -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/src/blocks/search-page/render.php
r13691 r15190 2 2 namespace WordPressdotorg\Theme\Plugins_2024\SearchPage; 3 3 4 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 4 5 echo do_blocks( <<<BLOCKS 5 6 <!-- wp:template-part {"slug":"grid-controls"} /--> -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/template-parts/plugin-single.php
r14932 r15190 34 34 <div class="entry-thumbnail"> 35 35 <?php 36 // phpcs:ignore WordPress. XSS.EscapeOutput.OutputNotEscaped36 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Template::get_plugin_icon() returns the icon markup. 37 37 echo Template::get_plugin_icon( $post, 'html' ); 38 38 ?> -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/template-parts/section-blocks.php
r12319 r15190 75 75 <li class="<?php echo esc_attr( $block_classes ); ?>"> 76 76 <?php if ( false !== strpos( $block_icon, '<svg' ) ) : ?> 77 <span class="block-icon" <?php echo $block_style; ?>>77 <span class="block-icon" <?php echo $block_style; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Style attribute built above from sanitize_hex_color() values. ?>> 78 78 <?php echo wp_kses( str_replace( '<svg ', '<svg role="img" aria-hidden="true" focusable="false" ', $block_icon ), $allowed_svg ); ?> 79 79 </span> 80 80 <?php elseif ( $block_icon ) : ?> 81 <span class="block-icon dashicons dashicons-<?php echo esc_attr( $block_icon ); ?>" <?php echo $block_style; ?>></span>81 <span class="block-icon dashicons dashicons-<?php echo esc_attr( $block_icon ); ?>" <?php echo $block_style; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Style attribute built above from sanitize_hex_color() values. ?>></span> 82 82 <?php else : ?> 83 83 <span class="block-icon dashicons dashicons-block-default"></span> -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-plugins-2024/template-parts/section.php
r12319 r15190 18 18 <div id="<?php echo esc_attr( $prefix . $section_slug ); ?>" class="<?php echo esc_attr( $classes ); ?>"> 19 19 <h2 id="<?php echo esc_attr( $section_slug . '-header' ); ?>"><?php echo esc_html( $section_title ); ?></h2> 20 <?php echo $section_content; ?>20 <?php echo $section_content; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Rendered readme section markup. ?> 21 21 </div> -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-showcase/404.php
r15179 r15190 61 61 </div>\n"; 62 62 63 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Markup assembled in this file from literal strings. 63 64 echo $output; 64 65 } -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-showcase/comments.php
r15179 r15190 14 14 <li id="comment-<?php comment_ID() ?>" <?php if ($i % 2) echo "class='altc'"; ?>> 15 15 <?php comment_text() ?> 16 <p><cite><?php printf( 17 /* translators: 1: comment type, 2: comment author link, 3: comment date */ 18 esc_html__( '%1$s from %2$s on %3$s', 'wporg-showcase' ), 19 comment_type( __( 'Comment', 'wporg-showcase' ), __( 'Trackback', 'wporg-showcase' ), __( 'Pingback', 'wporg-showcase' ) ), 20 comment_author_link(), 21 comment_date() 22 ); ?></cite> <?php edit_comment_link( __( 'Edit This', 'wporg-showcase' ), ' |' ); ?></p> 16 <p><cite> 17 <?php 18 $comment_type_labels = array( 19 'comment' => __( 'Comment', 'wporg-showcase' ), 20 'trackback' => __( 'Trackback', 'wporg-showcase' ), 21 'pingback' => __( 'Pingback', 'wporg-showcase' ), 22 ); 23 $comment_type_key = get_comment_type(); 24 printf( 25 /* translators: 1: Comment type, 2: Comment author link, 3: Comment date. */ 26 esc_html__( '%1$s from %2$s on %3$s', 'wporg-showcase' ), 27 esc_html( $comment_type_labels[ $comment_type_key ] ?? $comment_type_labels['comment'] ), 28 wp_kses_post( get_comment_author_link() ), 29 esc_html( get_comment_date() ) 30 ); 31 ?> 32 </cite> <?php edit_comment_link( __( 'Edit This', 'wporg-showcase' ), ' |' ); ?></p> 23 33 </li> 24 34 -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-showcase/feed-extras.php
r15170 r15190 12 12 13 13 ?> 14 <?php echo '<?xml version="1.0" encoding="' .get_option('blog_charset').'"?'.'>';?>14 <?php echo '<?xml version="1.0" encoding="' . get_option( 'blog_charset' ) . '"?' . '>'; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- RSS feed body: the XML declaration and core feed values, not HTML. ?> 15 15 16 16 <rss version="2.0" … … 29 29 <link><?php bloginfo_rss('url') ?></link> 30 30 <description><?php bloginfo_rss("description") ?></description> 31 <pubDate><?php echo mysql2date( 'D, d M Y H:i:s +0000', get_lastpostmodified('GMT'), false);?></pubDate>31 <pubDate><?php echo mysql2date( 'D, d M Y H:i:s +0000', get_lastpostmodified( 'GMT' ), false ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- RSS feed body: the XML declaration and core feed values, not HTML. ?></pubDate> 32 32 <?php the_generator( 'rss2' ); ?> 33 <language><?php echo get_option( 'rss_language');?></language>34 <sy:updatePeriod><?php echo apply_filters( 'rss_update_period', 'hourly' ); ?></sy:updatePeriod>35 <sy:updateFrequency><?php echo apply_filters( 'rss_update_frequency', '1' ); ?></sy:updateFrequency>33 <language><?php echo get_option( 'rss_language' ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- RSS feed body: the XML declaration and core feed values, not HTML. ?></language> 34 <sy:updatePeriod><?php echo apply_filters( 'rss_update_period', 'hourly' ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- RSS feed body: the XML declaration and core feed values, not HTML. ?></sy:updatePeriod> 35 <sy:updateFrequency><?php echo apply_filters( 'rss_update_frequency', '1' ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- RSS feed body: the XML declaration and core feed values, not HTML. ?></sy:updateFrequency> 36 36 <?php do_action('rss2_head'); ?> 37 37 <?php while( have_posts()) : the_post(); ?> … … 40 40 <link><?php the_permalink_rss() ?></link> 41 41 <comments><?php comments_link(); ?></comments> 42 <pubDate><?php echo mysql2date( 'D, d M Y H:i:s +0000', get_post_time('Y-m-d H:i:s', true), false);?></pubDate>42 <pubDate><?php echo mysql2date( 'D, d M Y H:i:s +0000', get_post_time( 'Y-m-d H:i:s', true ), false ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- RSS feed body: the XML declaration and core feed values, not HTML. ?></pubDate> 43 43 <dc:creator><?php the_author() ?></dc:creator> 44 44 <?php the_category_rss() ?> -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-showcase/footer.php
r11496 r15190 1 1 <?php 2 2 3 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 3 4 echo do_blocks( '<!-- wp:wporg/global-footer /-->' ); -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-showcase/functions.php
r15179 r15190 152 152 153 153 if ( ! empty( $_GET['p'] ) && strlen( $_GET['p'] ) > 0 ) { 154 echo "<p>" . $content . "</p>";154 echo '<p>' . esc_html( $content ) . '</p>'; 155 155 } else if ( ( strlen( $content ) > $max_char ) && ( $espacio = strpos( $content, " ", $max_char ) ) ) { 156 156 $content = substr( $content, 0, $espacio ); 157 echo "<p>" . $content . "..." . "</p>";158 } else { 159 echo "<p>" . $content . "</p>";157 echo '<p>' . esc_html( $content ) . '...</p>'; 158 } else { 159 echo '<p>' . esc_html( $content ) . '</p>'; 160 160 } 161 161 } … … 179 179 180 180 $out .= '</ul>'; 181 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Markup assembled in this file from already-escaped parts. 181 182 echo $out; 182 183 } -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-showcase/header.php
r15170 r15190 3 3 \WordPressdotorg\skip_to( '#pagebody' ); 4 4 5 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 5 6 echo do_blocks( '<!-- wp:wporg/global-header /-->' ); 6 7 -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-showcase/page-submit.php
r15179 r15190 75 75 76 76 <form action="/showcase/submit-a-wordpress-site/#return" method="post" id="submitform"> 77 <input type="hidden" name="comment_post_ID" value="<?php echo $post->ID; ?>" />77 <input type="hidden" name="comment_post_ID" value="<?php echo (int) $post->ID; ?>" /> 78 78 79 79 <p><label for="submitname"><?php esc_html_e( 'Your Name', 'wporg-showcase' ); ?></label><br /> -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-showcase/single.php
r15117 r15190 54 54 </div>\n"; 55 55 56 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Markup assembled in this file from literal strings. 56 57 echo $output; 57 58 } -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-support-2024/archive-forum.php
r15179 r15190 28 28 </main> 29 29 30 <?php echo do_blocks( 30 <?php 31 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 32 echo do_blocks( 31 33 sprintf( 32 34 '<!-- wp:group {"align":"full","style":{"spacing":{"padding":{"right":"var:preset|spacing|edge-space","left":"var:preset|spacing|edge-space","top":"var:preset|spacing|40","bottom":"var:preset|spacing|40"}},"border":{"bottom":{"color":"var:preset|color|white-opacity-15","style":"solid","width":"1px"}},"elements":{"link":{"color":{"text":"var:preset|color|white"}}}},"backgroundColor":"charcoal-2","textColor":"white","className":"forums-homepage-footer","layout":{"type":"constrained"}} --> -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-support-2024/archive.php
r13604 r15190 19 19 20 20 <div> 21 <?php echo do_blocks( 21 <?php 22 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 23 echo do_blocks( 22 24 sprintf( 23 25 '<!-- wp:group {"style":{"spacing":{"blockGap":"var:preset|spacing|10"}},"className":"is-style-cards-grid","layout":{"type":"grid","minimumColumnWidth":"32.3%%"},"fontSize":"small"} --> -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-support-2024/bbpress/form-topic.php
r15188 r15190 37 37 bbp_is_single_view() && 'reviews' === bbp_get_view_id() 38 38 ) { 39 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 39 40 echo do_blocks( 40 41 sprintf( -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-support-2024/bbpress/loop-forums-homepage.php
r15179 r15190 5 5 <h2 class="has-heading-5-font-size"><?php esc_html_e( 'Forums', 'wporg-forums' ); ?></h2> 6 6 7 <?php echo do_blocks( 7 <?php 8 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 9 echo do_blocks( 8 10 sprintf( 9 11 '<!-- wp:group {"style":{"spacing":{"blockGap":"var:preset|spacing|10"}},"className":"bbp-forums is-style-cards-grid","layout":{"type":"grid","minimumColumnWidth":"32.3%%"},"fontSize":"small"} --> … … 20 22 <h2 class="has-heading-5-font-size"><?php esc_html_e( 'Topics', 'wporg-forums' ); ?></h2> 21 23 22 <?php echo do_blocks( 24 <?php 25 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 26 echo do_blocks( 23 27 sprintf( 24 28 '<!-- wp:group {"style":{"spacing":{"blockGap":"var:preset|spacing|10"}},"className":"is-style-cards-grid","layout":{"type":"grid","minimumColumnWidth":"32.3%%"},"fontSize":"small"} --> -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-support-2024/bbpress/loop-single-forum-homepage.php
r14598 r15190 1 1 <?php 2 2 3 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 3 4 echo do_blocks( 4 5 sprintf( ' -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-support-2024/footer.php
r11496 r15190 12 12 <?php 13 13 14 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 14 15 echo do_blocks( '<!-- wp:wporg/global-footer /-->' ); -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-support-2024/front-page.php
r13604 r15190 18 18 19 19 <section class="helphub-front-page"> 20 <?php echo do_blocks( 20 <?php 21 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 22 echo do_blocks( 21 23 sprintf( 22 24 '<!-- wp:heading --> … … 46 48 <section id="forum-welcome"> 47 49 48 <?php echo do_blocks( '<!-- wp:pattern {"slug":"wporg-support/welcome-cards"} /-->' ); ?>50 <?php echo do_blocks( '<!-- wp:pattern {"slug":"wporg-support/welcome-cards"} /-->' ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. ?> 49 51 50 52 </section> -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-support-2024/functions.php
r15188 r15190 527 527 $columns_to_fill = 3 - ( $forums_count % 3 ); 528 528 529 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 529 530 echo do_blocks( 530 531 sprintf( -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-support-2024/header.php
r14965 r15190 14 14 \WordPressdotorg\skip_to( '#content' ); 15 15 16 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 16 17 echo do_blocks( '<!-- wp:wporg/global-header {"style":{"border":{"bottom":{"color":"var:preset|color|white-opacity-15","style":"solid","width":"1px"}}}} /-->' ); 17 18 … … 42 43 } 43 44 45 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 44 46 echo do_blocks( $is_forums_home || is_front_page() || $is_homepage 45 47 ? '<!-- wp:pattern {"slug":"wporg-support/local-nav-home"} /-->' … … 56 58 <?php if ( is_front_page() || $is_homepage ) : 57 59 60 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 58 61 echo do_blocks( 59 62 sprintf( … … 97 100 elseif ( $is_forums_home ) : 98 101 102 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 99 103 echo do_blocks( 100 104 sprintf( … … 138 142 139 143 if ( ! $is_user_profile && ! is_404() ) { 144 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 140 145 echo do_blocks( 141 146 sprintf( … … 159 164 160 165 if ( ! ( $is_user_profile || $is_reviews || $is_plugin || $is_theme || $is_single_forum ) ) { 166 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 161 167 echo do_blocks( 162 168 '<!-- wp:group {"style":{"spacing":{padding":{"left":"var:preset|spacing|edge-space","right":"var:preset|spacing|edge-space"}}}} --> -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-support-2024/page-homepage.php
r15179 r15190 25 25 26 26 <section id="forum-welcome"> 27 <?php echo do_blocks( '<!-- wp:pattern {"slug":"wporg-support/welcome-cards"} /-->' ); ?>27 <?php echo do_blocks( '<!-- wp:pattern {"slug":"wporg-support/welcome-cards"} /-->' ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. ?> 28 28 </section> 29 29 … … 35 35 <h2 class="has-heading-5-font-size"><?php esc_html_e( 'Topics', 'wporg-forums' ); ?></h2> 36 36 37 <?php echo do_blocks( '<!-- wp:pattern {"slug":"wporg-support/forums-views"} /-->' ); ?>37 <?php echo do_blocks( '<!-- wp:pattern {"slug":"wporg-support/forums-views"} /-->' ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. ?> 38 38 </section> 39 39 -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-support-2024/sidebar.php
r15188 r15190 90 90 <h2><?php esc_html_e( 'Topics', 'wporg-forums' ); ?></h2> 91 91 92 <?php echo do_blocks( 92 <?php 93 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 94 echo do_blocks( 93 95 sprintf( 94 96 '<!-- wp:group {"style":{"spacing":{"blockGap":"var:preset|spacing|10"}},"className":"topic-views is-style-cards-grid","layout":{"type":"grid"},"fontSize":"small"} --> -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg-support-2024/template-parts/content-page.php
r13567 r15190 19 19 <div class="container"> 20 20 <?php 21 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 21 22 echo do_blocks( '<!-- wp:wporg/table-of-contents /-->' ); 22 23 -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg/bin/build.php
r6555 r15190 14 14 } 15 15 16 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI build progress written to the console, not HTML. 16 17 echo "Building $theme..."; 17 18 -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg/comments.php
r15188 r15190 35 35 printf( 36 36 /* translators: 1: title. */ 37 esc_html_ e( 'One thought on “%1$s”', 'wporg' ),38 '<span>' . get_the_title() . '</span>'37 esc_html__( 'One thought on “%1$s”', 'wporg' ), 38 '<span>' . esc_html( get_the_title() ) . '</span>' 39 39 ); 40 40 } else { 41 printf( // WPCS: XSS OK.41 printf( 42 42 /* translators: 1: comment count number, 2: title. */ 43 43 esc_html( _nx( '%1$s thought on “%2$s”', '%1$s thoughts on “%2$s”', $comment_count, 'comments title', 'wporg' ) ), 44 44 esc_html( number_format_i18n( $comment_count ) ), 45 '<span>' . get_the_title() . '</span>'45 '<span>' . esc_html( get_the_title() ) . '</span>' 46 46 ); 47 47 } -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg/footer-wporg.php
r11496 r15190 12 12 namespace WordPressdotorg\Theme; 13 13 14 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 14 15 echo do_blocks( '<!-- wp:wporg/global-footer /-->' ); -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg/footer.php
r11496 r15190 19 19 <?php 20 20 21 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 21 22 echo do_blocks( '<!-- wp:wporg/global-footer /-->' ); 22 23 -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg/header-wporg.php
r11496 r15190 12 12 namespace WordPressdotorg\Theme; 13 13 14 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- do_blocks() renders the block markup defined here; escaping it would print the markup. 14 15 echo do_blocks( '<!-- wp:wporg/global-header /-->' ); -
sites/trunk/wordpress.org/public_html/wp-content/themes/pub/wporg/inc/template-tags.php
r15179 r15190 28 28 ); 29 29 30 // phpcs:disable WordPress. XSS.EscapeOutput.OutputNotEscaped30 // phpcs:disable WordPress.Security.EscapeOutput.OutputNotEscaped 31 31 printf( 32 32 /* translators: 1: post date 2: post author */ … … 35 35 $author_string 36 36 ); 37 // phpcs:enable WordPress. XSS.EscapeOutput.OutputNotEscaped37 // phpcs:enable WordPress.Security.EscapeOutput.OutputNotEscaped 38 38 } 39 39 … … 98 98 esc_html_x( 'Posted on', 'Used before publish date.', 'wporg' ), 99 99 esc_url( get_permalink() ), 100 get_entry_date() // phpcs:ignore WordPress. XSS.EscapeOutput.OutputNotEscaped100 get_entry_date() // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped 101 101 ); 102 102 } … … 115 115 '<span class="cat-links"><span class="screen-reader-text">%1$s </span>%2$s</span>', 116 116 esc_html_x( 'Categories', 'Used before category names.', 'wporg' ), 117 $categories_list // phpcs:ignore WordPress. XSS.EscapeOutput.OutputNotEscaped117 $categories_list // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped 118 118 ); 119 119 } … … 124 124 '<span class="tags-links"><span class="screen-reader-text">%1$s </span>%2$s</span>', 125 125 esc_html_x( 'Tags', 'Used before tag names.', 'wporg' ), 126 $tags_list // phpcs:ignore WordPress. XSS.EscapeOutput.OutputNotEscaped126 $tags_list // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped 127 127 ); 128 128 } -
sites/trunk/wordpress.tv/public_html/wp-content/themes/wptv2/anon-upload-template.php
r15170 r15190 252 252 if ( post_password_required() ) { 253 253 echo '<div class="pass-form">'; 254 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- get_the_password_form() returns core's form markup. 254 255 echo get_the_password_form(); 255 256 echo '</div></div></div>'; … … 257 258 return; 258 259 } else { 259 echo $message;260 echo wp_kses_post( $message ); 260 261 } 261 262 … … 335 336 printf( 336 337 '<li id="category-%1$d"><label class="selectit"><input value="%1$d" type="checkbox" name="post_category[]" id="in-category-%1$d" %2$s> %3$s</label></li>', 337 $term->term_id,338 (int) $term->term_id, 338 339 isset( $selected_cats[ $term->term_id ] ) ? 'checked="checked" ' : '', 339 $term->name,340 esc_html( $term->name ), 340 341 ); 341 342 } … … 358 359 printf( 359 360 '<li id="category-%1$d"><label class="selectit"><input value="%1$d" type="checkbox" name="post_category[]" id="in-category-%1$d" %2$s> %3$s</label></li>', 360 $term->term_id,361 (int) $term->term_id, 361 362 isset( $selected_cats[ $term->term_id ] ) ? 'checked="checked" ' : '', 362 $term->name,363 esc_html( $term->name ), 363 364 ); 364 365 } -
sites/trunk/wordpress.tv/public_html/wp-content/themes/wptv2/archive.php
r15179 r15190 44 44 $tax = get_taxonomy( $wp_query->query_vars['taxonomy'] ); 45 45 $terms = get_term_by( 'slug', $wp_query->query_vars['term'], $wp_query->query_vars['taxonomy'] ); 46 print ( "$tax->label: $terms->name");46 printf( '%s: %s', esc_html( $tax->label ), esc_html( $terms->name ) ); 47 47 48 48 elseif ( is_search() ) : … … 84 84 $excerpt .= ' — ' . get_the_excerpt(); 85 85 } 86 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- the_excerpt filter output is already the rendered excerpt. 86 87 echo apply_filters( 'the_excerpt', $excerpt ); 87 88 ?> -
sites/trunk/wordpress.tv/public_html/wp-content/themes/wptv2/footer.php
r8230 r15190 11 11 <div class="container"> 12 12 <?php wp_nav_menu( array( 'theme_location' => 'footer', 'depth' => 1 ) ); ?> 13 <p class="automattic">An <a href="https://automattic.com/"><img src="data:image/svg+xml;base64,PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz4NCjwhLS0gR2VuZXJhdG9yOiBBZG9iZSBJbGx1c3RyYXRvciAxNy4xLjAsIFNWRyBFeHBvcnQgUGx1Zy1JbiAuIFNWRyBWZXJzaW9uOiA2LjAwIEJ1aWxkIDApICAtLT4NCjwhRE9DVFlQRSBzdmcgUFVCTElDICItLy9XM0MvL0RURCBTVkcgMS4xLy9FTiIgImh0dHA6Ly93d3cudzMub3JnL0dyYXBoaWNzL1NWRy8xLjEvRFREL3N2ZzExLmR0ZCI+DQo8c3ZnIHZlcnNpb249IjEuMSIgaWQ9IkxvZ28iIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgeG1sbnM6eGxpbms9Imh0dHA6Ly93d3cudzMub3JnLzE5OTkveGxpbmsiIHg9IjBweCIgeT0iMHB4Ig0KCSB2aWV3Qm94PSIwIDAgNDk0LjQgMzguMiIgZW5hYmxlLWJhY2tncm91bmQ9Im5ldyAwIDAgNDk0LjQgMzguMiIgeG1sOnNwYWNlPSJwcmVzZXJ2ZSI+DQo8cGF0aCBmaWxsPSIjODg4ODg4IiBkPSJNMTc5LjMsMzguMmMtMTIuNiwwLTIwLjctOS4xLTIwLjctMTguNXYtMS4yYzAtOS42LDguMi0xOC41LDIwLjctMTguNWMxMi42LDAsMjAuOCw4LjksMjAuOCwxOC41djEuMg0KCUMyMDAuMSwyOS4xLDE5MS45LDM4LjIsMTc5LjMsMzguMnogTTE5My4zLDE4LjZjMC02LjktNS0xMy0xNC4xLTEzYy05LjEsMC0xNCw2LjEtMTQsMTN2MC45YzAsNi45LDUsMTMuMSwxNCwxMy4xDQoJYzkuMSwwLDE0LjEtNi4yLDE0LjEtMTMuMVYxOC42eiIvPg0KPHBhdGggZmlsbD0iIzg4ODg4OCIgZD0iTTM3LjEsMzYuOEwzMi40LDI4SDExLjZMNywzNi44SDBMMTkuMiwxLjNoNS41bDE5LjUsMzUuNUgzNy4xeiBNMjEuOCw4LjJsLTcuNywxNC45aDE1LjdMMjEuOCw4LjJ6Ii8+DQo8cGF0aCBmaWxsPSIjODg4ODg4IiBkPSJNNzQuNiwzOC4yYy0xMi43LDAtMTguNy02LjktMTguNy0xNi4yVjEuM2g2LjZ2MjAuOWMwLDYuNiw0LjMsMTAuNSwxMi41LDEwLjVjOC40LDAsMTEuOS0zLjksMTEuOS0xMC41VjEuMw0KCWg2LjdWMjJDOTMuNiwzMC44LDg3LjksMzguMiw3NC42LDM4LjJ6Ii8+DQo8cGF0aCBmaWxsPSIjODg4ODg4IiBkPSJNMTMwLjcsNi44djMwaC02Ljd2LTMwaC0xNS41VjEuM2gzNy43djUuNUgxMzAuN3oiLz4NCjxwYXRoIGZpbGw9IiM4ODg4ODgiIGQ9Ik0yNTkuNSwzNi44VjguN2wtMS44LDMuMWwtMTQuOSwyNWgtMy4zbC0xNC43LTI1bC0xLjgtMy4xdjI4LjFoLTYuNVYxLjNoOS4ybDE0LDI0LjRsMS43LDNsMS43LTNMMjU3LDEuMw0KCWg5LjF2MzUuNUgyNTkuNXoiLz4NCjxwYXRoIGZpbGw9IiM4ODg4ODgiIGQ9Ik0zMTYuNSwzNi44bC00LjctOC44SDI5MWwtNC41LDguOGgtN2wxOS4yLTM1LjVoNS41bDE5LjUsMzUuNUgzMTYuNXogTTMwMS4yLDguMmwtNy43LDE0LjloMTUuN0wzMDEuMiw4LjJ6DQoJIi8+DQo8cGF0aCBmaWxsPSIjODg4ODg4IiBkPSJNMzUwLjYsNi44djMwaC02Ljd2LTMwaC0xNS41VjEuM2gzNy43djUuNUgzNTAuNnoiLz4NCjxwYXRoIGZpbGw9IiM4ODg4ODgiIGQ9Ik0zOTkuNSw2Ljh2MzBoLTYuN3YtMzBoLTE1LjVWMS4zSDQxNXY1LjVIMzk5LjV6Ii8+DQo8cGF0aCBmaWxsPSIjODg4ODg4IiBkPSJNNDMxLjQsMzYuOFY0LjZjMi43LDAsMy43LTEuNCwzLjctMy40aDIuOHYzNS41SDQzMS40eiIvPg0KPHBhdGggZmlsbD0iIzg4ODg4OCIgZD0iTTQ5MC4yLDExLjNjLTMuMi0yLjktNy45LTUuNy0xNC4yLTUuN2MtOS41LDAtMTQuOCw2LjUtMTQuOCwxMy4zdjAuN2MwLDYuNyw1LjQsMTMsMTUuMywxMw0KCWM1LjksMCwxMC44LTIuOCwxMy45LTUuN2w0LDQuMmMtMy45LDMuOC0xMC41LDcuMS0xOC4zLDcuMWMtMTMuNCwwLTIxLjYtOC43LTIxLjYtMTguM3YtMS4yYzAtOS42LDguOS0xOC43LDIxLjktMTguNw0KCWM3LjUsMCwxNC4zLDMuMSwxOCw3LjFMNDkwLjIsMTEuM3oiLz4NCjxwYXRoIGZpbGw9IiM4ODg4ODgiIGQ9Ik0xODMuNiwxMi40YzEuMiwwLjgsMS41LDIuNCwwLjgsMy42bC02LjEsOS40Yy0wLjgsMS4yLTIuNCwxLjYtMy42LDAuOGwwLDBjLTEuMi0wLjgtMS41LTIuNC0wLjgtMy42DQoJbDYuMS05LjRDMTgwLjgsMTEuOSwxODIuNCwxMS42LDE4My42LDEyLjRMMTgzLjYsMTIuNHoiLz4NCjwvc3ZnPg0K" alt="Automattic" width="165" height="14" /></a> <?php $words = array( 'Production', 'Joint', 'Medley', 'Experiment', 'Ruckus', 'Invention', 'Creation', 'Thingamajig', 'Opus', 'Brainchild', 'Contraption' ); echo $words[ mt_rand( 0, count( $words) -1 ) ]; ?></p> 13 <p class="automattic">An <a href="https://automattic.com/"><img src="data:image/svg+xml;base64,PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz4NCjwhLS0gR2VuZXJhdG9yOiBBZG9iZSBJbGx1c3RyYXRvciAxNy4xLjAsIFNWRyBFeHBvcnQgUGx1Zy1JbiAuIFNWRyBWZXJzaW9uOiA2LjAwIEJ1aWxkIDApICAtLT4NCjwhRE9DVFlQRSBzdmcgUFVCTElDICItLy9XM0MvL0RURCBTVkcgMS4xLy9FTiIgImh0dHA6Ly93d3cudzMub3JnL0dyYXBoaWNzL1NWRy8xLjEvRFREL3N2ZzExLmR0ZCI+DQo8c3ZnIHZlcnNpb249IjEuMSIgaWQ9IkxvZ28iIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgeG1sbnM6eGxpbms9Imh0dHA6Ly93d3cudzMub3JnLzE5OTkveGxpbmsiIHg9IjBweCIgeT0iMHB4Ig0KCSB2aWV3Qm94PSIwIDAgNDk0LjQgMzguMiIgZW5hYmxlLWJhY2tncm91bmQ9Im5ldyAwIDAgNDk0LjQgMzguMiIgeG1sOnNwYWNlPSJwcmVzZXJ2ZSI+DQo8cGF0aCBmaWxsPSIjODg4ODg4IiBkPSJNMTc5LjMsMzguMmMtMTIuNiwwLTIwLjctOS4xLTIwLjctMTguNXYtMS4yYzAtOS42LDguMi0xOC41LDIwLjctMTguNWMxMi42LDAsMjAuOCw4LjksMjAuOCwxOC41djEuMg0KCUMyMDAuMSwyOS4xLDE5MS45LDM4LjIsMTc5LjMsMzguMnogTTE5My4zLDE4LjZjMC02LjktNS0xMy0xNC4xLTEzYy05LjEsMC0xNCw2LjEtMTQsMTN2MC45YzAsNi45LDUsMTMuMSwxNCwxMy4xDQoJYzkuMSwwLDE0LjEtNi4yLDE0LjEtMTMuMVYxOC42eiIvPg0KPHBhdGggZmlsbD0iIzg4ODg4OCIgZD0iTTM3LjEsMzYuOEwzMi40LDI4SDExLjZMNywzNi44SDBMMTkuMiwxLjNoNS41bDE5LjUsMzUuNUgzNy4xeiBNMjEuOCw4LjJsLTcuNywxNC45aDE1LjdMMjEuOCw4LjJ6Ii8+DQo8cGF0aCBmaWxsPSIjODg4ODg4IiBkPSJNNzQuNiwzOC4yYy0xMi43LDAtMTguNy02LjktMTguNy0xNi4yVjEuM2g2LjZ2MjAuOWMwLDYuNiw0LjMsMTAuNSwxMi41LDEwLjVjOC40LDAsMTEuOS0zLjksMTEuOS0xMC41VjEuMw0KCWg2LjdWMjJDOTMuNiwzMC44LDg3LjksMzguMiw3NC42LDM4LjJ6Ii8+DQo8cGF0aCBmaWxsPSIjODg4ODg4IiBkPSJNMTMwLjcsNi44djMwaC02Ljd2LTMwaC0xNS41VjEuM2gzNy43djUuNUgxMzAuN3oiLz4NCjxwYXRoIGZpbGw9IiM4ODg4ODgiIGQ9Ik0yNTkuNSwzNi44VjguN2wtMS44LDMuMWwtMTQuOSwyNWgtMy4zbC0xNC43LTI1bC0xLjgtMy4xdjI4LjFoLTYuNVYxLjNoOS4ybDE0LDI0LjRsMS43LDNsMS43LTNMMjU3LDEuMw0KCWg5LjF2MzUuNUgyNTkuNXoiLz4NCjxwYXRoIGZpbGw9IiM4ODg4ODgiIGQ9Ik0zMTYuNSwzNi44bC00LjctOC44SDI5MWwtNC41LDguOGgtN2wxOS4yLTM1LjVoNS41bDE5LjUsMzUuNUgzMTYuNXogTTMwMS4yLDguMmwtNy43LDE0LjloMTUuN0wzMDEuMiw4LjJ6DQoJIi8+DQo8cGF0aCBmaWxsPSIjODg4ODg4IiBkPSJNMzUwLjYsNi44djMwaC02Ljd2LTMwaC0xNS41VjEuM2gzNy43djUuNUgzNTAuNnoiLz4NCjxwYXRoIGZpbGw9IiM4ODg4ODgiIGQ9Ik0zOTkuNSw2Ljh2MzBoLTYuN3YtMzBoLTE1LjVWMS4zSDQxNXY1LjVIMzk5LjV6Ii8+DQo8cGF0aCBmaWxsPSIjODg4ODg4IiBkPSJNNDMxLjQsMzYuOFY0LjZjMi43LDAsMy43LTEuNCwzLjctMy40aDIuOHYzNS41SDQzMS40eiIvPg0KPHBhdGggZmlsbD0iIzg4ODg4OCIgZD0iTTQ5MC4yLDExLjNjLTMuMi0yLjktNy45LTUuNy0xNC4yLTUuN2MtOS41LDAtMTQuOCw2LjUtMTQuOCwxMy4zdjAuN2MwLDYuNyw1LjQsMTMsMTUuMywxMw0KCWM1LjksMCwxMC44LTIuOCwxMy45LTUuN2w0LDQuMmMtMy45LDMuOC0xMC41LDcuMS0xOC4zLDcuMWMtMTMuNCwwLTIxLjYtOC43LTIxLjYtMTguM3YtMS4yYzAtOS42LDguOS0xOC43LDIxLjktMTguNw0KCWM3LjUsMCwxNC4zLDMuMSwxOCw3LjFMNDkwLjIsMTEuM3oiLz4NCjxwYXRoIGZpbGw9IiM4ODg4ODgiIGQ9Ik0xODMuNiwxMi40YzEuMiwwLjgsMS41LDIuNCwwLjgsMy42bC02LjEsOS40Yy0wLjgsMS4yLTIuNCwxLjYtMy42LDAuOGwwLDBjLTEuMi0wLjgtMS41LTIuNC0wLjgtMy42DQoJbDYuMS05LjRDMTgwLjgsMTEuOSwxODIuNCwxMS42LDE4My42LDEyLjRMMTgzLjYsMTIuNHoiLz4NCjwvc3ZnPg0K" alt="Automattic" width="165" height="14" /></a> 14 <?php 15 $words = array( 'Production', 'Joint', 'Medley', 'Experiment', 'Ruckus', 'Invention', 'Creation', 'Thingamajig', 'Opus', 'Brainchild', 'Contraption' ); 16 echo esc_html( $words[ mt_rand( 0, count( $words ) - 1 ) ] ); 17 ?> 18 </p> 14 19 </div> 15 20 </div><!-- #footer --> -
sites/trunk/wordpress.tv/public_html/wp-content/themes/wptv2/functions.php
r15179 r15190 482 482 <?php 483 483 edit_comment_link( __( 'edit', 'wptv' ), ' ', '' ); 484 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Rendered markup: core link helpers, the_content/the_title filter output, and widget before/after wrappers. 484 485 echo comment_reply_link( array( 485 486 'depth' => $depth, … … 534 535 } 535 536 537 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Rendered markup: core link helpers, the_content/the_title filter output, and widget before/after wrappers. 536 538 echo $video; 537 539 … … 558 560 $ret = '<img src="' . $ret . '" alt="' . esc_attr( $post->post_title ) . '" />'; 559 561 } 562 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Rendered markup: core link helpers, the_content/the_title filter output, and widget before/after wrappers. 560 563 echo $ret; 561 564 } … … 695 698 if ( in_category( $category ) ) { 696 699 $link = get_category_link( $category ); 700 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Rendered markup: core link helpers, the_content/the_title filter output, and widget before/after wrappers. 697 701 echo $before . ' <a href="' . esc_url( $link ) . '">' . esc_html( $category->name ) . '</a>'; 698 702 break; // only one category is printed … … 715 719 foreach ( $terms as $term ) { 716 720 $link = get_term_link( $term, 'event' ); 721 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Rendered markup: core link helpers, the_content/the_title filter output, and widget before/after wrappers. 717 722 echo $before . '<a href="' . esc_url( $link ) . '">' . esc_html( $term->name ) . '</a>' . $after; 718 723 break; // only the first one event is printed … … 903 908 <div> 904 909 <h3> 905 <?php echo apply_filters( 'the_title', $item->title ); ?>910 <?php echo apply_filters( 'the_title', $item->title ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Rendered markup: core link helpers, the_content/the_title filter output, and widget before/after wrappers. ?> 906 911 <a href="<?php echo esc_url( $item->url ); ?>" class="view-more"><?php esc_html_e( 'More →' ); ?></a> 907 912 </h3> -
sites/trunk/wordpress.tv/public_html/wp-content/themes/wptv2/plugins/wordpresstv-anon-upload/anon-upload.php
r14472 r15190 78 78 // For an XHR request, just send the redirect location, don't redirect to it. 79 79 if ( isset( $_GET['xhr'] ) ) { 80 die( $redir ); 80 die( $redir ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- URL response with encoded query values, including description newlines. 81 81 } 82 82 … … 450 450 <div id="anon-data-wrap" class="inside"> 451 451 452 <p>To change the default thumbnail image, <a href="https://wordpress.com/media/wordpress.tv/<?php echo $attachment_post->ID; ?>">go here and select Edit Thumbnail</a>.</p>452 <p>To change the default thumbnail image, <a href="https://wordpress.com/media/wordpress.tv/<?php echo (int) $attachment_post->ID; ?>">go here and select Edit Thumbnail</a>.</p> 453 453 454 454 <div class="wp_attachment_holder wp-clearfix"> 455 455 <?php 456 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- wp_video_shortcode() returns the rendered video player markup. 456 457 echo wp_video_shortcode( array( 'src' => wp_get_attachment_url( $attachment_post->ID ) ) ) 457 458 ?> … … 505 506 $cat = get_term_by( 'name', substr( $meta['recorded'], 0, 4 ), 'category' ); 506 507 if ( $cat ) { 507 echo '<a href="#in-category-' . $cat->term_id. '" class="button-secondary anon-approve anon-cat-link" title="Click to approve">Approve</a>';508 echo '<a href="#in-category-' . esc_attr( $cat->term_id ) . '" class="button-secondary anon-approve anon-cat-link" title="Click to approve">Approve</a>'; 508 509 } 509 510 ?> … … 521 522 foreach ( $cats as $cat ) { 522 523 if ( intval( $cat ) ) { 523 echo '<a href="#in-category-' . $cat. '-2" class="anon-cat-link" title="Click to approve">Unknown?</a>, ';524 echo '<a href="#in-category-' . esc_attr( $cat ) . '-2" class="anon-cat-link" title="Click to approve">Unknown?</a>, '; 524 525 } 525 526 } -
sites/trunk/wordpress.tv/public_html/wp-content/themes/wptv2/plugins/wordpresstv-oembed/wordpresstv-oembed.php
r8230 r15190 135 135 echo "<oembed>\n"; 136 136 foreach ( $data as $tag => $value ) { 137 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- XML response element; the value is htmlspecialchars()'d and the tag name is an internal key. 137 138 echo " <{$tag}>" . htmlspecialchars( $value ) . "</{$tag}>\n"; 138 139 } -
sites/trunk/wordpress.tv/public_html/wp-content/themes/wptv2/plugins/wordpresstv-rest/wordpresstv-rest.php
r12045 r15190 265 265 function error( $message, $http_code = 404 ) { 266 266 status_header( $http_code ); 267 exit( $message);267 exit( esc_html( $message ) ); 268 268 } 269 269 } -
sites/trunk/wordpress.tv/public_html/wp-content/themes/wptv2/plugins/wordpresstv-unisubs/wordpresstv-unisubs.php
r8230 r15190 166 166 echo "<item>\n"; 167 167 foreach ( $data as $tag => $value ) { 168 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- XML response element; the value is htmlspecialchars()'d and the tag name is an internal key. 168 169 echo " <{$tag}>" . htmlspecialchars( $value ) . "</{$tag}>\n"; 169 170 } -
sites/trunk/wordpress.tv/public_html/wp-content/themes/wptv2/plugins/wordpresstv-upload-subtitles/wordpresstv-upload-subtitles.php
r12041 r15190 380 380 <strong>Content of the subtitles file</strong><br> 381 381 382 <div id="subs-content"><?php echo $file_content; ?></div>382 <div id="subs-content"><?php echo $file_content; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- File contents are escaped above before inserting line breaks. ?></div> 383 383 384 384 <div class="subs-info"> … … 456 456 if ( $pending_subs ) { 457 457 echo '<div class="updated"><p><a href="upload.php?post_mime_type=' . urlencode( 'application/ttml+xml' ) . 458 '&detached=1">Subtitles awaiting moderation (' .$pending_subs . ')</a></p></div>';458 '&detached=1">Subtitles awaiting moderation (' . (int) $pending_subs . ')</a></p></div>'; 459 459 } 460 460 } -
sites/trunk/wordpress.tv/public_html/wp-content/themes/wptv2/upload-subtitles-template.php
r15179 r15190 170 170 <p><?php printf( wp_kses_post( __( 'Hey there! If you’re interested in subtitling or captioning videos for WordPress.tv, please fill out the <a href="%s">contact form</a>, and we’ll be in touch.', 'wptv' ) ), 'https://wordpress.tv/contact/' ); ?></p> 171 171 <div class="pass-form"> 172 <?php echo get_the_password_form(); ?>172 <?php echo get_the_password_form(); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Core template markup and the_title-filtered value; escaping would print the markup. ?> 173 173 </div> 174 174 </div> … … 244 244 <div class="container"> 245 245 <div class="video-upload"> 246 <?php echo $message; ?>247 248 <p>Subtitling: <a href="<?php echo esc_url( get_permalink( $parent->ID ) ); ?>"><?php echo apply_filters( 'the_title', $parent->post_title ); ?></a></p>246 <?php echo wp_kses_post( $message ); ?> 247 248 <p>Subtitling: <a href="<?php echo esc_url( get_permalink( $parent->ID ) ); ?>"><?php echo apply_filters( 'the_title', $parent->post_title ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Core template markup and the_title-filtered value; escaping would print the markup. ?></a></p> 249 249 250 250 <form method="post" action="<?php echo esc_url( admin_url( 'admin-post.php' ) ); ?>" id="video-upload-form" enctype="multipart/form-data"> -
sites/trunk/wp15.wordpress.net/public_html/content/mu-plugins/locales.php
r15179 r15190 57 57 58 58 if ( ! $po_content || ! $mo_content || false === strpos( $po_content, 'Project-Id-Version: Meta - wp15.wordpress.net' ) ) { 59 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Written to the error log by trigger_error(), not rendered. 59 60 trigger_error( "Invalid PO/MO content for {$set->wp_locale}." ); 60 61 continue; -
sites/trunk/wp15.wordpress.net/public_html/content/plugins/wp15-meetup-events/libraries/class-meetup-client.php
r9874 r15190 227 227 228 228 if ( 'cli' === php_sapi_name() ) { 229 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI import progress written to the console, not HTML. 229 230 echo "\nRequest failed $attempt_count times. Pausing for $wait seconds before retrying."; 230 231 } … … 236 237 if ( $attempt_count === $max_attempts && 'cli' === php_sapi_name() ) { 237 238 if ( 200 !== $response_code || is_wp_error( $response ) ) { 239 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI import progress written to the console, not HTML. 238 240 echo "\nRequest failed $attempt_count times. Giving up."; 239 241 } … … 317 319 318 320 if ( 'cli' === php_sapi_name() ) { 321 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CLI import progress written to the console, not HTML. 319 322 echo "\nPausing for $period seconds to avoid rate-limiting."; 320 323 } -
sites/trunk/wp15.wordpress.net/public_html/content/plugins/wp15-meetup-events/wp15-meetup-events.php
r7248 r15190 46 46 47 47 if ( is_wp_error( $potential_events ) ) { 48 // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Written to the error log by trigger_error(), not rendered. 48 49 trigger_error( $potential_events->get_error_message() ); 49 50 return; -
sites/trunk/wp15.wordpress.net/public_html/content/themes/twentyseventeen-wp15/functions.php
r7177 r15190 300 300 ?> 301 301 <meta property="og:type" content="website" /> 302 <meta property="og:title" content="<?php echo wp_get_document_title(); ?>" />303 <meta property="og:description" content="<?php echo internationalize_titles( 'WordPress turns 15 on May 27, 2018'); ?>" />302 <meta property="og:title" content="<?php echo esc_attr( wp_get_document_title() ); ?>" /> 303 <meta property="og:description" content="<?php echo esc_attr( internationalize_titles( 'WordPress turns 15 on May 27, 2018' ) ); ?>" /> 304 304 <meta property="og:url" content="https://wp15.wordpress.net/" /> 305 <meta property="og:site_name" content="<?php echo internationalize_titles( 'WP15'); ?>" />305 <meta property="og:site_name" content="<?php echo esc_attr( internationalize_titles( 'WP15' ) ); ?>" /> 306 306 <meta property="og:image" content="https://wp15.wordpress.net/content/uploads/2018/03/wp15-logo-square.png" /> 307 <meta property="og:locale" content="<?php echo get_locale(); ?>" />307 <meta property="og:locale" content="<?php echo esc_attr( get_locale() ); ?>" /> 308 308 <meta name="twitter:card" content="summary" /> 309 309 <meta name="twitter:url" content="https://wp15.wordpress.net/" /> 310 <meta name="twitter:title" content="<?php echo wp_get_document_title(); ?>" />311 <meta name="twitter:description" content="<?php echo internationalize_titles( 'WordPress turns 15 on May 27, 2018'); ?>" />310 <meta name="twitter:title" content="<?php echo esc_attr( wp_get_document_title() ); ?>" /> 311 <meta name="twitter:description" content="<?php echo esc_attr( internationalize_titles( 'WordPress turns 15 on May 27, 2018' ) ); ?>" /> 312 312 <meta name="twitter:image" content="https://wp15.wordpress.net/content/uploads/2018/03/wp15-logo-square.png" /> 313 313 <?php -
sites/trunk/wp15.wordpress.net/public_html/content/themes/twentyseventeen-wp15/page-swag.php
r7187 r15190 60 60 </p> 61 61 62 <?php echo wp_oembed_get( 'https://mercantile.wordpress.org/product/wordpress-15th-anniversary-mug/' ); ?>63 <?php echo wp_oembed_get( 'https://mercantile.wordpress.org/product/wordpress-15th-anniversary-tshirt/' ); ?>62 <?php echo wp_oembed_get( 'https://mercantile.wordpress.org/product/wordpress-15th-anniversary-mug/' ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- wp_oembed_get() returns the embed markup. ?> 63 <?php echo wp_oembed_get( 'https://mercantile.wordpress.org/product/wordpress-15th-anniversary-tshirt/' ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- wp_oembed_get() returns the embed markup. ?> 64 64 65 65 </div>
Note:
See TracChangeset
for help on using the changeset viewer.
![(please configure the [header_logo] section in trac.ini)](/chrome/site/your_project_logo.png)