rules: require SDK verification before implementing any feature that … #66
ci.yml
on: push
Lint JS & CSS
37s
JavaScript Unit Tests
34s
Lint PHP
18s
PHPStan Static Analysis
49s
WordPress Plugin Check
1m 54s
Matrix: test-php
Annotations
3 warnings
|
PluginCheck.Security.DirectDB.UnescapedDBParameter:
includes/class-telex-cli.php#L617
Unescaped parameter $where_sql used in $wpdb->get_results($wpdb->prepare( "SELECT * FROM {$table} {$where_sql} ORDER BY id DESC LIMIT %d", ...$values ))\n$where_sql assigned unsafely at line 602:\n $where_sql = ! empty( $where_parts )\n\t\t\t? 'WHERE ' . implode( ' AND ', $where_parts )\n\t\t\t: ''\n$where_parts assigned unsafely at line 565:\n $where_parts[] = 'action = %s'
|
|
PluginCheck.Security.DirectDB.UnescapedDBParameter:
includes/class-telex-rest.php#L1438
Unescaped parameter $where_sql used in $wpdb->get_results($wpdb->prepare( "SELECT * FROM {$table} {$where_sql} ORDER BY id DESC LIMIT %d OFFSET %d", ...$limit_values ))\n$where_sql assigned unsafely at line 1417:\n $where_sql = 'WHERE ' . implode( ' AND ', $where_parts )\n$where_parts assigned unsafely at line 1388:\n $where_parts[] = '(public_id LIKE %s OR context LIKE %s)'\n$like assigned unsafely at line 1389:\n $like = '%' . $wpdb->esc_like( $search ) . '%'
|
|
PluginCheck.Security.DirectDB.UnescapedDBParameter:
includes/class-telex-rest.php#L1431
Unescaped parameter $where_sql used in $wpdb->get_var($wpdb->prepare( "SELECT COUNT(*) FROM {$table} {$where_sql}", ...$where_values ))\n$where_sql assigned unsafely at line 1417:\n $where_sql = 'WHERE ' . implode( ' AND ', $where_parts )\n$where_parts assigned unsafely at line 1388:\n $where_parts[] = '(public_id LIKE %s OR context LIKE %s)'\n$like assigned unsafely at line 1389:\n $like = '%' . $wpdb->esc_like( $search ) . '%'
|