| @@ -1,7 +1,12 @@ | ||
| 1 | 1 | <?php |
| 2 | +// phpcs:disable WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedVariableFound -- view template receives variables via extract(); prefixing is impractical. | |
| 2 | 3 | |
| 3 | - // Get the author's ID | |
| 4 | + | |
| 5 | +if ( ! defined( 'ABSPATH' ) ) { | |
| 6 | + exit; | |
| 7 | +} | |
| 8 | +// Get the author's ID | |
| 4 | 9 | $author_id = get_post_field( 'post_author', get_the_ID() ); |
| 5 | 10 | |
| 6 | 11 | // Get the author's avatar with a specified size |
| 7 | 12 | $avatar_size = 40; |
| @@ -9,13 +14,13 @@ | ||
| 9 | 14 | $authors_url = site_url() . '/' . betterdocs()->settings->get( 'docs_slug' ) . '/authors/' . $author_id . '/page/1'; |
| 10 | 15 | |
| 11 | 16 | ?> |
| 12 | 17 | |
| 13 | -<a class="betterdocs-author-date" href="<?php echo $authors_url; ?>"> | |
| 18 | +<a class="betterdocs-author-date" href="<?php echo esc_url( $authors_url ); ?>"> | |
| 14 | 19 | <div class="betterdocs-author"> |
| 15 | 20 | <?php |
| 16 | - echo '<div class="author-avatar">' . $author_avatar . '</div>'; | |
| 17 | - echo '<span>' . get_the_author_meta( 'display_name', $author_id ) . '</span>'; | |
| 21 | + echo '<div class="author-avatar">' . wp_kses_post( $author_avatar ) . '</div>'; | |
| 22 | + echo '<span>' . esc_html( get_the_author_meta( 'display_name', $author_id ) ) . '</span>'; | |
| 18 | 23 | ?> |
| 19 | 24 | </div> |
| 20 | 25 | <?php betterdocs()->views->get( 'template-parts/update-date' );?> |
| 21 | 26 | </a> |