| @@ -1,6 +1,11 @@ | ||
| 1 | 1 | <?php |
| 2 | - // Get the author's ID | |
| 2 | +// phpcs:disable WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedVariableFound -- view template receives variables via extract(); prefixing is impractical. | |
| 3 | + | |
| 4 | +if ( ! defined( 'ABSPATH' ) ) { | |
| 5 | + exit; | |
| 6 | +} | |
| 7 | +// Get the author's ID | |
| 3 | 8 | $author_id = get_post_field( 'post_author', get_the_ID() ); |
| 4 | 9 | |
| 5 | 10 | // Get the author's avatar with a specified size |
| 6 | 11 | $avatar_size = 40; |
| @@ -7,13 +12,13 @@ | ||
| 7 | 12 | $author_avatar = get_avatar( $author_id, $avatar_size ); |
| 8 | 13 | $authors_url = site_url() . '/'.betterdocs()->settings->get('docs_slug').'/authors/' . $author_id . '/page/1'; |
| 9 | 14 | ?> |
| 10 | 15 | |
| 11 | -<a class="betterdocs-author-date" href="<?php echo $authors_url; ?>"> | |
| 16 | +<a class="betterdocs-author-date" href="<?php echo esc_url( $authors_url ); ?>"> | |
| 12 | 17 | <div class="betterdocs-author"> |
| 13 | 18 | <?php |
| 14 | - echo '<div class="author-avatar">' . $author_avatar . '</div>'; | |
| 15 | - echo '<span>' . get_the_author_meta( 'display_name', $author_id ) . '</span>'; | |
| 19 | + echo '<div class="author-avatar">' . wp_kses_post( $author_avatar ) . '</div>'; | |
| 20 | + echo '<span>' . esc_html( get_the_author_meta( 'display_name', $author_id ) ) . '</span>'; | |
| 16 | 21 | ?> |
| 17 | 22 | </div> |
| 18 | 23 | <?php |
| 19 | 24 | if ( isset( $updated_date ) && $updated_date == true ) { |