astra_addon_sanitize_unexecuted_snippet( string $code )

Sanitize a code-editor snippet that is NOT going to be executed.


Description

PHP blocks are removed before sanitizing: wp_kses_post() only discards <?php ... ?> when the block body contains no >, so a snippet containing >, => or -> would otherwise have its opening tag consumed as a malformed HTML tag and the remaining source code — potentially including credentials — printed to visitors.

Script bodies are left visible on purpose: wp_kses_post() drops the <script> tag but keeps its text, and that visible JavaScript is the signal that a snippet has stopped running.


Parameters

$code

(string) (Required) Stored snippet.


Return

(string) Safe markup, with any PHP source removed.


Source

File: classes/astra-addon-extended-functionality.php

function astra_addon_sanitize_unexecuted_snippet( $code ) {
	if ( ! is_string( $code ) || '' === $code ) {
		return '';
	}

	// Remove PHP blocks entirely; __return_empty_string() replaces each match with ''.
	$html_only = preg_replace_callback( '/<\?(?:php|=)?.*?(?:\?>|$)/s', '__return_empty_string', $code );
	return wp_kses_post( (string) $html_only );
}

Changelog

Changelog
Version Description
4.13.7 Introduced.


User Contributed Notes

You must log in before being able to contribute a note or feedback.