astra_addon_sanitize_unexecuted_snippet( string $code )
Sanitize a code-editor snippet that is NOT going to be executed.
Description
PHP blocks are removed before sanitizing: wp_kses_post() only discards <?php ... ?> when the block body contains no >, so a snippet containing >, => or -> would otherwise have its opening tag consumed as a malformed HTML tag and the remaining source code — potentially including credentials — printed to visitors.
Script bodies are left visible on purpose: wp_kses_post() drops the <script> tag but keeps its text, and that visible JavaScript is the signal that a snippet has stopped running.
Parameters
- $code
-
(string) (Required) Stored snippet.
Return
(string) Safe markup, with any PHP source removed.
Source
File: classes/astra-addon-extended-functionality.php
function astra_addon_sanitize_unexecuted_snippet( $code ) {
if ( ! is_string( $code ) || '' === $code ) {
return '';
}
// Remove PHP blocks entirely; __return_empty_string() replaces each match with ''.
$html_only = preg_replace_callback( '/<\?(?:php|=)?.*?(?:\?>|$)/s', '__return_empty_string', $code );
return wp_kses_post( (string) $html_only );
}
Expand full source code Collapse full source code View on Trac
Changelog
| Version | Description |
|---|---|
| 4.13.7 | Introduced. |