PluginProbe
Advanced Access Manager – Access Governance for WordPress / 7.1.2
Advanced Access Manager – Access Governance for WordPress v7.1.2
7.1.4 7.1.2 7.1.3 6.8.4 6.8.5 6.9.0 6.9.1 6.9.10 6.9.11 6.9.12 6.9.13 6.9.14 6.9.15 6.9.16 6.9.17 6.9.18 6.9.19 6.9.2 6.9.20 6.9.21 6.9.22 6.9.23 6.9.24 6.9.25 6.9.26 All 210 releases
advanced-access-manager / application / Audit / XmlRpcEndpointCheck.php
XmlRpcEndpointCheck.php
125 lines 2.8 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 /**
4 * ======================================================================
5 * LICENSE: This file is subject to the terms and conditions defined in *
6 * file 'license.txt', which is part of this source code package. *
7 * ======================================================================
8 */
9
10 /**
11 * Check if XML-RPC endpoint is enabled
12 *
13 * @package AAM
14 * @version 7.0.0
15 */
16 class AAM_Audit_XmlRpcEndpointCheck
17 {
18
19 use AAM_Audit_AuditCheckTrait;
20
21 /**
22 * Step ID
23 *
24 * @version 7.0.0
25 */
26 const ID = 'xml_rpc_endpoint';
27
28 /**
29 * Run the check
30 *
31 * @return array
32 *
33 * @access public
34 * @static
35 *
36 * @version 7.0.0
37 */
38 public static function run()
39 {
40 $issues = [];
41 $response = [ 'is_completed' => true ];
42
43 try {
44 array_push($issues, ...self::_check_endpoint_accessability());
45 } catch (Exception $e) {
46 array_push($issues, self::_format_issue(
47 'APPLICATION_ERROR',
48 [
49 'message' => $e->getMessage()
50 ],
51 'error'
52 ));
53 }
54
55 if (count($issues) > 0) {
56 $response['issues'] = $issues;
57 }
58
59 // Determine final status for the check
60 self::_determine_check_status($response);
61
62 return $response;
63 }
64
65 /**
66 * Get a collection of error messages for current step
67 *
68 * @return array
69 * @access private
70 * @static
71 *
72 * @version 7.0.0
73 */
74 private static function _get_message_templates()
75 {
76 return [
77 'OPEN_XMLRPC_ENDPOINT' => __(
78 'Detected open to anonymous users XML-RPC endpoint',
79 'advanced-access-manager'
80 ),
81 'ENABLED_XMLRPC' => __(
82 'The XML-RPC API is enabled',
83 'advanced-access-manager'
84 )
85 ];
86 }
87
88 /**
89 * Detect empty roles
90 *
91 * @return array
92 *
93 * @access private
94 * @static
95 *
96 * @version 7.0.0
97 */
98 private static function _check_endpoint_accessability()
99 {
100 $response = [];
101
102 $visitor = AAM::api()->visitor();
103
104 // Check if API route "/xmlrpc.php" is enabled
105 $api_url_enabled = !$visitor->urls()->is_denied('/xmlrpc.php');
106
107 if ($api_url_enabled) {
108 array_push($response, self::_format_issue('OPEN_XMLRPC_ENDPOINT'));
109 }
110
111 // Check if XML-PRC API is enabled
112 $api_enabled = apply_filters('xmlrpc_enabled', true);
113
114 if ($api_enabled) {
115 array_push($response, self::_format_issue(
116 'ENABLED_XMLRPC',
117 [],
118 'warning'
119 ));
120 }
121
122 return $response;
123 }
124
125 }