PluginProbe
BetterDocs – AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ & Chatbot / 4.9.3
BetterDocs – AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ & Chatbot v4.9.3
4.9.3 4.9.2 4.9.1 4.9.0 4.8.2 4.8.1 4.8.0 4.7.0 4.6.2 4.6.1 4.6.0 4.5.6 4.5.5 4.5.4 4.5.3 4.5.2 4.5.1 4.5.0 4.4.1 4.4.0 3.3.4 3.4.0 3.4.1 3.4.2 3.5.0 All 201 releases
← All changes | includes/Core/Admin.php +580 -58 4.5.4 → 4.9.3 View file →
@@ -1,8 +1,12 @@
1 1 <?php
2 +namespace WPDeveloper\BetterDocs\Core;
2 3
3 -namespace WPDeveloper\BetterDocs\Core;
4 +if ( ! defined( 'ABSPATH' ) ) {
5 + exit;
6 +}
4 7
8 +
5 9 use Exception;
6 10 use PriyoMukul\WPNotice\Notices;
7 11 use WPDeveloper\BetterDocs\Admin\NoticePointers;
8 12 use WPDeveloper\BetterDocs\Utils\Base;
@@ -8,9 +12,9 @@
8 12 use WPDeveloper\BetterDocs\Utils\Base;
9 13 use PriyoMukul\WPNotice\Utils\CacheBank;
10 14 use WPDeveloper\BetterDocs\Utils\Helper;
11 15 use WPDeveloper\BetterDocs\Utils\Enqueue;
12 -use WPDeveloper\BetterDocs\Utils\Insights;
16 +use WPDeveloper\BetterDocs\Insights\Insights;
13 17 use PriyoMukul\WPNotice\Utils\NoticeRemover;
14 18 use WPDeveloper\BetterDocs\Core\PluginInstaller;
15 19 use WPDeveloper\BetterDocs\Dependencies\DI\Container;
16 20
@@ -15,8 +19,42 @@
15 19 use WPDeveloper\BetterDocs\Dependencies\DI\Container;
16 20
17 21 class Admin extends Base {
18 22 /**
23 + * Per-user flag recording that this administrator has opened the Content IQ
24 + * screen — the discovery badge (ADR-063) now flags Content Intelligence, the
25 + * headline feature, rather than MCP.
26 + *
27 + * Stores the timestamp of the first visit, but only its **presence** is read:
28 + * absent means "this user has not seen Content IQ yet", which is what puts the
29 + * one-time discovery badge on the menu. Per user on purpose — two administrators
30 + * each get their own first look, and neither clears the other's. A deliberately
31 + * fresh meta key (not the old `betterdocs_mcp_seen`) so a user who already
32 + * dismissed the MCP badge still gets this one for the new feature.
33 + *
34 + * The private `*_mcp_*` helper names below are kept as-is to hold the diff to
35 + * the target slug + this key; they now paint the Content IQ item.
36 + *
37 + * @var string
38 + * @since 4.9.0
39 + */
40 + const MCP_SEEN_META = 'betterdocs_content_iq_seen';
41 +
42 + /**
43 + * Whether this request painted the MCP discovery badge onto the menu.
44 + *
45 + * Decided once in `menus()` (on `admin_menu`) and read again in
46 + * `mcp_badge_styles()` (on `admin_head`), rather than re-deciding, because the
47 + * two must agree: on the request that opens the MCP screen the badge is still
48 + * painted while the meta is already written, and re-deciding at `admin_head`
49 + * would leave that one painted pill unstyled.
50 + *
51 + * @var bool
52 + * @since 4.9.0
53 + */
54 + private $mcp_badge = false;
55 +
56 + /**
19 57 * @var CacheBank
20 58 */
21 59 private static $cache_bank;
22 60 /**
@@ -68,9 +106,8 @@
68 106 *
69 107 * @var FAQBuilder
70 108 */
71 109 private $faq_builder;
72 - private $glossaries;
73 110
74 111 public function __construct( Container $container, PostType $type, Enqueue $assets, Settings $settings, KBMigration $kbmigration ) {
75 112 $this->container = $container;
76 113 $this->assets = $assets;
@@ -84,10 +121,19 @@
84 121 $type->init();
85 122 $type->admin_init();
86 123
87 124 $this->faq_builder = $this->container->get( FAQBuilder::class );
88 - $this->glossaries = $this->container->get( Glossaries::class );
89 125
126 + /**
127 + * Register usage tracking (including the daily `put_do_weekly_action` cron
128 + * handler) on every request — WP-Cron runs with is_admin() === false, so
129 + * this MUST sit above the admin guard or the cron send never fires. The
130 + * admin-only UI hooks inside Insights::init() (deactivation form, footer
131 + * scripts, plugin_action_links) are context-specific and simply never run
132 + * outside wp-admin.
133 + */
134 + $this->plugin_insights();
135 +
90 136 if ( ! is_admin() ) {
91 137 return;
92 138 }
93 139
@@ -92,16 +138,32 @@
92 138 }
93 139
94 140 $this->installer = new PluginInstaller();
95 141
96 - $this->plugin_insights();
97 142 add_action( 'admin_notices', array( $this, 'compatibility_notices' ) );
143 + // The WPNotice CacheBank wipes all admin_notices at priority 10 on BetterDocs
144 + // screens, so the hook above never renders inside the BetterDocs panels.
145 + // Re-add the compatibility notice after that wipe (in_admin_header, priority
146 + // 999) so it shows on the panels like the review / license notices.
147 + add_action( 'in_admin_header', function () {
148 + $screen = function_exists( 'get_current_screen' ) ? get_current_screen() : null;
149 + if ( $screen && betterdocs()->is_betterdocs_screen( $screen->id ) ) {
150 + add_action( 'admin_notices', array( $this, 'compatibility_notices' ) );
151 + }
152 + }, 999 );
98 153 // add_action( 'admin_init', [$this, 'notices'], 9 );
99 154 add_filter( 'admin_init', array( $this, 'save_admin_page' ), 99 );
100 155
101 156 add_action( 'admin_menu', array( $this, 'menus' ) );
157 + // The badge's clear runs on `admin_init` — a hook that fires for every
158 + // admin request — and identifies the screen by its page slug, rather
159 + // than on `load-{$hook_suffix}` (ADR-065). `admin_init` fires *after*
160 + // `admin_menu`, measured on the rig, so the badge is still painted on
161 + // the request that opens the screen exactly as before.
162 + add_action( 'admin_init', array( $this, 'mark_mcp_seen' ) );
102 163 add_action( 'admin_menu', array( $this, 'reset_submenu' ) );
103 164 add_action( 'admin_head', array( $this, 'add_custom_classes_to_menu_items' ) );
165 + add_action( 'admin_head', array( $this, 'mcp_badge_styles' ) );
104 166 add_filter( 'plugin_action_links_' . BETTERDOCS_PLUGIN_BASENAME, array( $this, 'insert_plugin_links' ) );
105 167
106 168 // $this->container->get( SetupWizard::class )->init();
107 169
@@ -113,8 +175,10 @@
113 175 add_filter( 'admin_body_class', array( $this, 'body_classes' ) );
114 176 add_filter( 'parent_file', array( $type, 'highlight_admin_menu' ) );
115 177 add_filter( 'submenu_file', array( $type, 'highlight_admin_submenu' ), 10, 2 );
116 178 add_filter( 'betterdocs_admin_menu', array( $this, 'quick_setup_menu' ), 10, 1 );
179 + // Runs last so it also orders items Pro/add-ons append through this filter.
180 + add_filter( 'betterdocs_admin_menu', array( $this, 'order_admin_menu' ), 999, 1 );
117 181
118 182 /**
119 183 * Remove Comments Column from List Table.
120 184 */
@@ -236,9 +300,11 @@
236 300 if ( betterdocs()->is_pro_active() ) {
237 301 $plugins = Helper::get_plugins();
238 302 $plugin_data = $plugins['betterdocs-pro/betterdocs-pro.php'];
239 303
240 - if ( isset( $plugin_data['Version'] ) && version_compare( $plugin_data['Version'], '2.5.0', '>=' ) ) {
304 + // Require the paired Pro release: the Analytics UI is version-coupled to
305 + // Pro's advanced modules, so an older Pro renders a broken/partial panel.
306 + if ( isset( $plugin_data['Version'] ) && version_compare( $plugin_data['Version'], '4.0.0', '>=' ) ) {
241 307 return;
242 308 }
243 309
244 310 betterdocs()->views->get( 'admin/notices/compatibility', array( 'version' => $plugin_data['Version'] ) );
@@ -467,8 +533,11 @@
467 533 'betterdocs_page_betterdocs-faq',
468 534 'betterdocs_page_betterdocs-analytics',
469 535 'betterdocs_page_betterdocs-glossaries',
470 536 'betterdocs_page_betterdocs-ai-chatbot',
537 + 'betterdocs_page_betterdocs-api-docs',
538 + 'betterdocs_page_betterdocs-doc-categories',
539 + 'betterdocs_page_betterdocs-doc-tags',
471 540 'edit-doc_category',
472 541 'edit-doc_tag',
473 542 ),
474 543 $notices,
@@ -476,31 +545,93 @@
476 545 );
477 546 }
478 547 }
479 548
549 + /**
550 + * Resolve the admin dark-mode preference.
551 + *
552 + * The mode switcher stores the choice in a client cookie (no DB write, shared
553 + * across every admin screen). Fall back to the legacy
554 + * `betterdocs_settings['dark_mode']` value for installs that set it before this
555 + * change and haven't toggled since.
556 + *
557 + * @return bool
558 + */
559 + public function is_dark_mode() {
560 + if ( isset( $_COOKIE['betterdocs_admin_dark_mode'] ) ) {
561 + return '1' === $_COOKIE['betterdocs_admin_dark_mode']; // phpcs:ignore WordPress.Security.NonceVerification.Recommended
562 + }
563 +
564 + $saved = get_option( 'betterdocs_settings', array() );
565 + return ! empty( $saved['dark_mode'] );
566 + }
567 +
568 + /**
569 + * Whether the knowledge base is genuinely empty (no doc categories and no
570 + * non-trash docs). Localized to the admin so the All Docs panel can render a
571 + * skeleton shaped like the "No Category Found" empty card on first paint —
572 + * instead of a category/docs skeleton it would immediately replace — without
573 + * waiting for the REST fetch to reveal the count.
574 + *
575 + * @return bool
576 + */
577 + public function kb_is_empty() {
578 + $cats = wp_count_terms( array( 'taxonomy' => 'doc_category', 'hide_empty' => false ) );
579 + $cats = is_wp_error( $cats ) ? 0 : (int) $cats;
580 + if ( $cats > 0 ) {
581 + return false;
582 + }
583 +
584 + $counts = (array) wp_count_posts( 'docs' );
585 + $total = 0;
586 + foreach ( array( 'publish', 'future', 'draft', 'pending', 'private' ) as $status ) {
587 + $total += isset( $counts[ $status ] ) ? (int) $counts[ $status ] : 0;
588 + }
589 +
590 + return 0 === $total;
591 + }
592 +
480 593 public function body_classes( $classes ) {
481 - $saved_settings = get_option( 'betterdocs_settings', false );
482 - $dark_mode = isset( $saved_settings['dark_mode'] ) ? $saved_settings['dark_mode'] : false;
483 - $dark_mode = ! empty( $dark_mode ) ? boolval( $dark_mode ) : false;
594 + $dark_mode = $this->is_dark_mode();
484 595 $current_screen_id = get_current_screen() != null ? str_replace( 'betterdocs_page_', '', str_replace( 'toplevel_page_', '', str_replace( 'admin_page_', '', get_current_screen()->id ) ) ) : '';
485 - $registered_screens = array(
596 + /**
597 + * Filter the list of (prefix-stripped) screen ids that receive the
598 + * `betterdocs-admin` body class (and dark-mode class). Pro/add-ons can
599 + * register their own React admin pages, e.g. the Knowledge Base page.
600 + *
601 + * @param string[] $registered_screens Screen ids with the page prefix removed.
602 + */
603 + $registered_screens = apply_filters( 'betterdocs_admin_screen_slugs', array(
486 604 'betterdocs-settings',
487 605 'betterdocs-admin',
488 606 'betterdocs-dashboard',
489 607 'betterdocs-analytics',
608 + 'betterdocs-content-iq',
490 609 'betterdocs-glossaries',
491 610 'betterdocs-faq',
611 + 'betterdocs-doc-categories',
612 + 'betterdocs-doc-tags',
492 613 'edit-doc_category',
493 614 'edit-doc_tag',
494 615 'edit-knowledge_base',
495 616 'betterdocs-ai-chatbot',
496 - );
617 + 'betterdocs-api-docs',
618 + // Without this the MCP screen never receives `betterdocs-admin`, and
619 + // the design tokens' dark-mode overrides — which are declared on
620 + // `.betterdocs-admin.betterdocs-dark-mode` — can never apply there:
621 + // the switcher in the header flips the cookie and the page stays
622 + // light. @since 4.9.0
623 + 'betterdocs-mcp',
624 + ) );
497 625
498 626 if ( in_array( $current_screen_id, $registered_screens ) ) {
499 627 $classes .= ' betterdocs-admin ';
500 628 }
501 629
502 - if ( true === $dark_mode && in_array( $current_screen_id, $registered_screens ) ) {
630 + // Dark mode also applies on the Quick Setup wizard, whose self-scoped chrome
631 + // keys off `.betterdocs_page_betterdocs-setup.betterdocs-dark-mode`.
632 + $dark_screens = array_merge( $registered_screens, array( 'betterdocs-setup' ) );
633 + if ( $dark_mode && in_array( $current_screen_id, $dark_screens, true ) ) {
503 634 $classes .= ' betterdocs-dark-mode ';
504 635 }
505 636
506 637 return $classes;
@@ -531,9 +662,9 @@
531 662 public function manage_custom_columns( $column, $post_id ) {
532 663 global $wpdb;
533 664 switch ( $column ) {
534 665 case 'betterdocs_word_count':
535 - $content_without_html_tags = trim( strip_tags( get_post_field( 'post_content', $post_id ) ) );
666 + $content_without_html_tags = trim( wp_strip_all_tags( get_post_field( 'post_content', $post_id ) ) );
536 667 preg_match_all( '/<[^>]*>|[\p{L}\p{M}]+/u', $content_without_html_tags, $matches );
537 668 $total_words = ! empty( $matches[0] ) ? count( $matches[0] ) : count( array() );
538 669 $word_count = $total_words;
539 670 echo '<span>' . esc_html( intval( $word_count ) ) . '</span>';
@@ -538,19 +669,22 @@
538 669 $word_count = $total_words;
539 670 echo '<span>' . esc_html( intval( $word_count ) ) . '</span>';
540 671 break;
541 672 case 'betterdocs_reaction':
542 - $where = "WHERE post_id='" . esc_sql( $post_id ) . "'";
673 + // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery,WordPress.DB.DirectDatabaseQuery.NoCaching -- per-post analytics aggregation rendered in admin list table; cache would mask live reactions.
543 674 $analytics = $wpdb->get_results(
544 - "SELECT
545 - sum(impressions) as totalViews,
546 - sum(unique_visit) as totalUniqueViews,
547 - sum(happy + sad + normal) as totalReactions,
548 - sum(happy) as totalHappy,
549 - sum(normal) as totalNormal,
550 - sum(sad) as totalSad
551 - FROM {$wpdb->prefix}betterdocs_analytics
552 - $where"
675 + $wpdb->prepare(
676 + "SELECT
677 + sum(impressions) as totalViews,
678 + sum(unique_visit) as totalUniqueViews,
679 + sum(happy + sad + normal) as totalReactions,
680 + sum(happy) as totalHappy,
681 + sum(normal) as totalNormal,
682 + sum(sad) as totalSad
683 + FROM {$wpdb->prefix}betterdocs_analytics
684 + WHERE post_id = %d",
685 + $post_id
686 + )
553 687 );
554 688
555 689 echo '<ul class="reactions-count">
556 690 <li>
@@ -632,9 +766,48 @@
632 766 * @return void
633 767 * @since 1.0.0
634 768 */
635 769 public function scripts( $hook ) {
636 - if ( ( 'edit.php' === $hook ) && get_post_type() == 'docs' ) {
770 + // Classic-UI screens that should offer a "Switch to BetterDocs UI"
771 + // button: All Docs, FAQ list, FAQ groups, Product FAQ groups,
772 + // Doc Categories, Doc Tags. Maps each to the React admin page to
773 + // return to; $switch_args carries extra query args (e.g. the FAQ
774 + // Builder tab) appended to the React page URL.
775 + $switch_page = '';
776 + $switch_args = array();
777 + if ( 'edit.php' === $hook && 'docs' === get_post_type() ) {
778 + $switch_page = 'betterdocs-admin';
779 + } elseif ( 'edit.php' === $hook && 'betterdocs_faq' === get_post_type() ) {
780 + $switch_page = 'betterdocs-faq';
781 + } elseif ( 'edit-tags.php' === $hook ) {
782 + $screen = function_exists( 'get_current_screen' ) ? get_current_screen() : null;
783 + $taxonomy = $screen && ! empty( $screen->taxonomy )
784 + ? $screen->taxonomy
785 + : ( isset( $_GET['taxonomy'] ) ? sanitize_key( wp_unslash( $_GET['taxonomy'] ) ) : '' ); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
786 + if ( 'betterdocs_faq_category' === $taxonomy ) {
787 + $switch_page = 'betterdocs-faq';
788 + } elseif ( 'betterdocs_product_faq_category' === $taxonomy ) {
789 + // Product FAQ groups live on the FAQ Builder's WooCommerce tab.
790 + $switch_page = 'betterdocs-faq';
791 + $switch_args = array( 'faq_tab' => 'woocommerce' );
792 + } elseif ( 'doc_category' === $taxonomy ) {
793 + $switch_page = 'betterdocs-doc-categories';
794 + } elseif ( 'doc_tag' === $taxonomy ) {
795 + $switch_page = 'betterdocs-doc-tags';
796 + }
797 + }
798 +
799 + /**
800 + * Allow Pro/add-ons to map their own classic-UI taxonomy screens to a
801 + * React admin page for the "Switch to BetterDocs UI" button — e.g. the
802 + * Knowledge Base taxonomy, which only exists when Pro is active.
803 + *
804 + * @param string $switch_page React page slug, or '' for no switcher.
805 + * @param string $hook Current admin page hook.
806 + */
807 + $switch_page = apply_filters( 'betterdocs_classic_switch_page', $switch_page, $hook );
808 +
809 + if ( $switch_page ) {
637 810 $this->assets->enqueue(
638 811 'betterdocs-switcher',
639 812 'admin/js/switcher.js',
640 813 array(
@@ -646,8 +819,13 @@
646 819 'betterdocs-switcher',
647 820 'betterdocsSwitcher',
648 821 array(
649 822 'menu_title' => __( 'Switch to BetterDocs UI', 'betterdocs' ),
823 + 'page' => $switch_page,
824 + 'url' => add_query_arg(
825 + array_merge( array( 'page' => $switch_page ), $switch_args ),
826 + admin_url( 'admin.php' )
827 + ),
650 828 'site_address' => get_bloginfo( 'url' ),
651 829 'betterdocs_pro_plugin' => betterdocs()->is_pro_active(),
652 830 'betterdocs_pro_version' => betterdocs()->pro_version(),
653 831 )
@@ -665,10 +843,9 @@
665 843 wp_enqueue_media(); // load early to fix problems with media upload issues on settings for WordPress 6.0.9
666 844 $this->assets->register( 'betterdocs-admin', 'admin/js/dashboard.js' );
667 845
668 846 $saved_settings = get_option( 'betterdocs_settings', false );
669 - $dark_mode = $saved_settings['dark_mode'] ?? false;
670 - $dark_mode = ! empty( $dark_mode ) && boolval( $dark_mode );
847 + $dark_mode = $this->is_dark_mode();
671 848 $this->assets->localize(
672 849 'betterdocs-admin',
673 850 'betterdocs_admin',
674 851 array(
@@ -674,12 +851,13 @@
674 851 array(
675 852 'ajaxurl' => admin_url( 'admin-ajax.php' ),
676 853 'doc_cat_order_nonce' => wp_create_nonce( 'doc_cat_order_nonce' ),
677 854 'knowledge_base_order_nonce' => wp_create_nonce( 'knowledge_base_order_nonce' ),
678 - 'paged' => isset( $_GET['paged'] ) ? absint( wp_unslash( $_GET['paged'] ) ) : 0, // phpcs:ignore WordPress.Security.NonceVerification.Missing
855 + 'paged' => isset( $_GET['paged'] ) ? absint( wp_unslash( $_GET['paged'] ) ) : 0, // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- pagination read from URL.
679 856 'per_page_id' => 'edit_doc_category_per_page',
680 857 'menu_title' => __( 'Switch to BetterDocs UI', 'betterdocs' ),
681 858 'dark_mode' => $dark_mode,
859 + 'kb_is_empty' => $this->kb_is_empty(),
682 860 'text' => __( 'Copied!', 'betterdocs' ),
683 861 'test_report' => __( 'Test Report!', 'betterdocs' ),
684 862 'sending' => __( 'Sending...', 'betterdocs' ),
685 863 'dir_url' => BETTERDOCS_ABSURL,
@@ -685,12 +863,17 @@
685 863 'dir_url' => BETTERDOCS_ABSURL,
686 864 'rest_url' => esc_url_raw( rest_url() ),
687 865 'free_version' => betterdocs()->version,
688 866 'generate_data_url' => get_rest_url( null, '/betterdocs/v1/create-sample-docs' ),
867 + 'ai_sample_docs' => array(
868 + 'enabled' => (bool) betterdocs()->settings->get( 'enable_ai_sample_docs', true ),
869 + 'rest_base' => esc_url_raw( get_rest_url( null, '/betterdocs/v1/sample-docs' ) ),
870 + ),
689 871 'nonce' => wp_create_nonce( 'wp_rest' ),
690 872 'sync_nonce' => wp_create_nonce( 'ai_chatbot_embed' ),
691 873 'count_all_docs' => array_sum( (array) wp_count_posts( 'docs' ) ),
692 874 'count_all_faq' => array_sum( (array) wp_count_posts( 'betterdocs_faq' ) ),
875 + 'faq_order' => get_option( 'betterdocs_faq_order', 'default' ),
693 876 'count_new_docs' => $this->get_not_synced_docs_count(),
694 877 'admin_url' => admin_url(),
695 878 'ia_preview' => betterdocs()->settings->get( 'ia_enable_preview', false ),
696 879 'multiple_kb' => betterdocs()->settings->get( 'multiple_kb' ),
@@ -698,13 +881,34 @@
698 881 'dashboard_mode' => get_option( 'dashboard_mode' ),
699 882 'betterdocs_pro_plugin' => betterdocs()->is_pro_active(),
700 883 'betterdocs_pro_version' => betterdocs()->pro_version(),
701 884 'analytics_older' => version_compare( betterdocs()->pro_version(), '3.3.4', '<=' ),
702 - 'disabled_embed_model_option' => get_option( 'disabled_embed_model_option' ),
703 885 'betterdocs_ChatBot_plugin' => is_plugin_active( 'betterdocs-ai-chatbot/betterdocs-ai-chatbot.php' ),
886 + 'api_docs_teaser' => betterdocs()->show_api_docs_teaser(),
887 + 'glossaries_teaser' => betterdocs()->show_glossary_teaser(),
888 + 'glossaries_needs_pro_update' => betterdocs()->glossaries_needs_pro_update(),
889 + 'glossaries_min_pro_version' => betterdocs()->glossaries_min_pro_version(),
890 + 'glossaries_pro_update_url' => self_admin_url( 'plugins.php' ),
891 + 'content_intelligence_teaser' => betterdocs()->show_content_intelligence_teaser(),
892 + 'is_woocommerce_active' => class_exists( 'WooCommerce' ),
704 893 'total_doc_category_terms' => wp_count_terms( 'doc_category' ),
705 894 'current_admin_language' => Helper::get_current_admin_language(),
706 895 'is_multilingual' => Helper::is_multilingual_active(),
896 + 'languages' => Helper::get_admin_languages(),
897 + /**
898 + * MCP page bootstrap. `abilities_api_available` decides whether the
899 + * page offers a connection at all: without the Abilities API there
900 + * is no tool catalog, so an AI client would connect and find
901 + * nothing. `enabled` is only the initial paint — the toggle owns
902 + * the value from then on.
903 + *
904 + * @since 4.9.0
905 + */
906 + 'mcp' => array(
907 + 'abilities_api_available' => function_exists( 'wp_register_ability' ),
908 + 'enabled' => (bool) betterdocs()->settings->get( 'enable_mcp', false ),
909 + 'rest' => 'betterdocs/v1',
910 + ),
707 911 )
708 912 );
709 913
710 914 // If wp-date (which includes moment.js) is not registered, enqueue your custom moment.js
@@ -720,8 +924,16 @@
720 924 // FAQ Builder Related Localization
721 925 betterdocs()->assets->enqueue( 'betterdocs-admin-faq', 'admin/css/faq.css' );
722 926 betterdocs()->assets->enqueue( 'betterdocs-admin-faq', 'admin/js/faq.js' );
723 927
928 + // Load the classic editor (TinyMCE + QuickTags) so the FAQ rich-text editor can mount via wp.editor.initialize().
929 + if ( function_exists( 'wp_enqueue_editor' ) ) {
930 + wp_enqueue_editor();
931 + }
932 + if ( function_exists( 'wp_enqueue_media' ) ) {
933 + wp_enqueue_media();
934 + }
935 +
724 936 // removing emoji support
725 937 remove_action( 'wp_head', 'print_emoji_detection_script', 7 );
726 938 remove_action( 'admin_print_scripts', 'print_emoji_detection_script' );
727 939
@@ -727,10 +939,11 @@
727 939
728 940 // Get settings and remove unnecessary keys
729 941 $betterdocs_settings = get_option( 'betterdocs_settings', false );
730 942 if ( is_array( $betterdocs_settings ) && ! current_user_can( 'edit_docs_settings' ) ) {
731 - unset( $betterdocs_settings['ai_autowrite_api_key'] );
732 - unset( $betterdocs_settings['ai_chatbot_api_key'] );
943 + foreach ( Settings::sensitive_api_key_fields() as $sensitive_key ) {
944 + unset( $betterdocs_settings[ $sensitive_key ] );
945 + }
733 946 }
734 947
735 948 betterdocs()->assets->localize(
736 949 'betterdocs-admin-faq',
@@ -743,24 +956,10 @@
743 956 'betterdocs_settings' => $betterdocs_settings,
744 957 )
745 958 );
746 959
747 - // Glossaries Related Localization
748 - betterdocs()->assets->enqueue( 'betterdocs-admin-glossaries', 'admin/css/faq.css' );
749 -
750 - betterdocs()->assets->enqueue( 'betterdocs-admin-glossaries', 'admin/js/glossaries.js' );
751 -
752 - betterdocs()->assets->localize(
753 - 'betterdocs-admin-glossaries',
754 - 'betterdocsGlossary',
755 - array(
756 - 'dir_url' => BETTERDOCS_ABSURL,
757 - 'rest_url' => esc_url_raw( rest_url() ),
758 - 'free_version' => betterdocs()->version,
759 - 'nonce' => wp_create_nonce( 'wp_rest' ),
760 - 'betterdocs_settings' => $betterdocs_settings,
761 - )
762 - );
960 + // Glossaries is Pro — Pro's Core\Glossaries::enqueue() owns that bundle
961 + // and both of its localized objects (`betterdocs`, `betterdocsGlossary`).
763 962 }
764 963
765 964 /**
766 965 * All admin pages header
@@ -817,8 +1016,13 @@
817 1016
818 1017 // Always register both UI endpoints
819 1018 $this->register_modern_ui_fallback();
820 1019
1020 + // The one-time MCP discovery badge (ADR-063). Decided once, here, and
1021 + // remembered for `mcp_badge_styles()`: the pill's markup and the pill's
1022 + // stylesheet have to be printed on the same requests as each other.
1023 + $this->mcp_badge = self::should_flag_mcp();
1024 +
821 1025 foreach ( $this->menu_list() as $key => $value ) {
822 1026 if ( 'betterdocs' === $key ) {
823 1027 $callable = 'add_menu_page';
824 1028 $value = wp_parse_args( $value, $default_args );
@@ -847,10 +1051,203 @@
847 1051 }
848 1052 ++$_menu_position;
849 1053 }
850 1054 }
1055 +
1056 + $this->paint_mcp_badge();
851 1057 }
852 1058
1059 + /**
1060 + * Append the discovery badge to the registered menu titles.
1061 + *
1062 + * **After** registration, editing `$menu` / `$submenu` in place — the same
1063 + * shape `add_custom_classes_to_menu_items()` uses — and never by passing a
1064 + * decorated title to `add_menu_page()`. That distinction is not cosmetic:
1065 + * core stores `sanitize_title( $menu_title )` as `$admin_page_hooks[ $slug ]`
1066 + * (`wp-admin/includes/plugin.php:1397`) and builds every child page's hook
1067 + * suffix from it (`get_plugin_page_hookname()`), so markup in the parent's
1068 + * title renames `betterdocs_page_betterdocs-mcp` — and the MCP screen, whose
1069 + * asset enqueue is keyed on that exact suffix, silently loads no React
1070 + * bundle at all. Measured: the first visit came back 102,513 bytes with no
1071 + * `dashboard.js`, against 489,272 bytes once the badge had cleared.
1072 + *
1073 + * Titles are only ever appended to, never rebuilt: the menu list is filtered
1074 + * (`betterdocs_admin_menu`), so whatever a filter put in a title survives.
1075 + *
1076 + * @return void
1077 + * @since 4.9.0
1078 + */
1079 + private function paint_mcp_badge() {
1080 + if ( ! $this->mcp_badge ) {
1081 + return;
1082 + }
1083 +
1084 + global $menu, $submenu;
1085 +
1086 + if ( is_array( $menu ) ) {
1087 + foreach ( $menu as &$item ) {
1088 + if ( isset( $item[2] ) && $this->slug === $item[2] ) {
1089 + $item[0] .= self::mcp_parent_bubble();
1090 + break;
1091 + }
1092 + }
1093 + unset( $item );
1094 + }
1095 +
1096 + if ( isset( $submenu[ $this->slug ] ) && is_array( $submenu[ $this->slug ] ) ) {
1097 + foreach ( $submenu[ $this->slug ] as &$sub_item ) {
1098 + if ( isset( $sub_item[2] ) && 'betterdocs-content-iq' === $sub_item[2] ) {
1099 + $sub_item[0] .= self::mcp_submenu_pill();
1100 + break;
1101 + }
1102 + }
1103 + unset( $sub_item );
1104 + }
1105 + }
1106 +
1107 + /**
1108 + * Whether the current user should see the one-time MCP discovery badge.
1109 + *
1110 + * True only for a user who can actually reach the screen and has never
1111 + * opened it. The capability is the one the MCP menu item is already
1112 + * registered with (`manage_options`) rather than a second, re-derived rule —
1113 + * so the badge can never advertise a page its reader cannot open.
1114 + *
1115 + * @return bool
1116 + * @since 4.9.0
1117 + */
1118 + public static function should_flag_mcp() {
1119 + if ( ! current_user_can( 'manage_options' ) ) {
1120 + return false;
1121 + }
1122 +
1123 + $user_id = get_current_user_id();
1124 +
1125 + if ( ! $user_id ) {
1126 + return false;
1127 + }
1128 +
1129 + // `get_user_meta( …, true )` answers '' for a key that is not there, and
1130 + // the value written is always `time()` — so an empty string is the only
1131 + // shape "never opened" takes.
1132 + return '' === get_user_meta( $user_id, self::MCP_SEEN_META, true );
1133 + }
1134 +
1135 + /**
1136 + * WordPress' own update-count bubble, for the BetterDocs parent menu item.
1137 + *
1138 + * Core's markup on purpose: the red bubble, its position and its dark-mode
1139 + * colours are already in `wp-admin`'s stylesheet, so this needs no CSS of
1140 + * ours and cannot drift from the Plugins/Updates bubbles beside it.
1141 + *
1142 + * @return string
1143 + * @since 4.9.0
1144 + */
1145 + private static function mcp_parent_bubble() {
1146 + return ' <span class="update-plugins count-1"><span class="update-count">1</span></span>';
1147 + }
1148 +
1149 + /**
1150 + * The green "New" pill for the MCP submenu item.
1151 + *
1152 + * Core has no submenu-badge markup, so this one is ours — styled by
1153 + * `mcp_badge_styles()`.
1154 + *
1155 + * @return string
1156 + * @since 4.9.0
1157 + */
1158 + private static function mcp_submenu_pill() {
1159 + return ' <span class="bd-menu-pill">' . esc_html__( 'New', 'betterdocs' ) . '</span>';
1160 + }
1161 +
1162 + /**
1163 + * Whether this request is the MCP screen being opened by someone who can
1164 + * open it.
1165 + *
1166 + * The whole of the clearing decision, in one static so it can be pinned by
1167 + * a test. It reads the **page slug** rather than an admin hook suffix
1168 + * because the suffix is derived state: core builds it from
1169 + * `sanitize_title()` of the *parent* menu title (`get_plugin_page_hookname()`),
1170 + * that title is filtered (`betterdocs_admin_menu`), and the parent slug is
1171 + * spelled two ways in this class already. `?page=betterdocs-mcp` is the one
1172 + * thing that identifies this screen on every install (ADR-065).
1173 + *
1174 + * The capability is `manage_options`, the same one the MCP menu item is
1175 + * registered with and the same one {@see self::should_flag_mcp()} gates on:
1176 + * nothing may be written for a user who cannot reach the page.
1177 + *
1178 + * @return bool
1179 + * @since 4.9.0
1180 + */
1181 + public static function is_mcp_screen_request() {
1182 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- read-only screen detection; see mark_mcp_seen().
1183 + $page = isset( $_GET['page'] ) ? sanitize_key( wp_unslash( $_GET['page'] ) ) : '';
1184 +
1185 + if ( 'betterdocs-content-iq' !== $page ) {
1186 + return false;
1187 + }
1188 +
1189 + return current_user_can( 'manage_options' );
1190 + }
1191 +
1192 + /**
1193 + * Record that this user has now seen the MCP screen.
1194 + *
1195 + * Bound to `admin_init` — which fires for every admin request — and gated on
1196 + * the page slug, rather than to `load-{$hook_suffix}` for the one suffix
1197 + * `add_submenu_page()` happened to return. `admin_menu` has already run by
1198 + * the time `admin_init` fires (measured), so the badge is still painted on
1199 + * *this* request and is gone from the next admin page — that is expected and
1200 + * correct. Do not add JavaScript to strip it mid-request.
1201 + *
1202 + * **No nonce, on purpose.** A nonce protects a state change an attacker
1203 + * could make a logged-in administrator perform unknowingly. The only state
1204 + * here is "this administrator has now been shown the MCP screen once", it is
1205 + * written for the current user alone, it holds no attacker-chosen value, and
1206 + * the worst a forged request can achieve is hiding a discovery badge from
1207 + * the person it was drawn for. A nonce on a plain page view would also have
1208 + * to survive the menu link, which carries none.
1209 + *
1210 + * @return void
1211 + * @since 4.9.0
1212 + */
1213 + public function mark_mcp_seen() {
1214 + if ( ! self::is_mcp_screen_request() ) {
1215 + return;
1216 + }
1217 +
1218 + $user_id = get_current_user_id();
1219 +
1220 + if ( ! $user_id ) {
1221 + return;
1222 + }
1223 +
1224 + update_user_meta( $user_id, self::MCP_SEEN_META, time() );
1225 + }
1226 +
1227 + /**
1228 + * The handful of declarations the "New" pill needs, inline, and only while
1229 + * it is being shown.
1230 + *
1231 + * The menu is read from the WordPress Dashboard, and `styles()` above
1232 + * early-returns on non-BetterDocs screens — so `admin/css/dashboard.css` is
1233 + * not loaded where this pill is seen. Loading the whole BetterDocs admin
1234 + * stylesheet globally, or shipping a stylesheet file for nine declarations,
1235 + * both cost far more than printing them here. The accent is written out
1236 + * rather than taken from `--base-color-700`: that token lives in
1237 + * `dashboard.css`, which is exactly the file that is not loaded here.
1238 + *
1239 + * @return void
1240 + * @since 4.9.0
1241 + */
1242 + public function mcp_badge_styles() {
1243 + if ( ! $this->mcp_badge ) {
1244 + return;
1245 + }
1246 +
1247 + echo '<style id="betterdocs-menu-pill">#adminmenu .bd-menu-pill{display:inline-block;background:#00b884;color:#fff;font-size:10px;text-transform:uppercase;line-height:1.6;padding:1px 6px;margin-left:6px;border-radius:9px;}</style>' . "\n";
1248 + }
1249 +
853 1250 private function register_modern_ui_fallback() {
854 1251 // Add the submenu with valid parent slug
855 1252 add_submenu_page(
856 1253 'betterdocs', // Valid parent slug
@@ -949,15 +1346,19 @@
949 1346 'post-new.php?post_type=docs'
950 1347 ),
951 1348 'categories' => $this->normalize_menu(
952 1349 __( 'Categories', 'betterdocs' ),
953 - 'edit-tags.php?taxonomy=doc_category&post_type=docs',
954 - 'manage_doc_terms'
1350 + 'betterdocs-doc-categories',
1351 + 'manage_doc_terms',
1352 + array( $this, 'output' ),
1353 + $parent_slug
955 1354 ),
956 1355 'tags' => $this->normalize_menu(
957 1356 __( 'Tags', 'betterdocs' ),
958 - 'edit-tags.php?taxonomy=doc_tag&post_type=docs',
959 - 'manage_doc_terms'
1357 + 'betterdocs-doc-tags',
1358 + 'manage_doc_terms',
1359 + array( $this, 'output' ),
1360 + $parent_slug
960 1361 ),
961 1362 'settings' => $this->normalize_menu(
962 1363 __( 'Settings', 'betterdocs' ),
963 1364 'betterdocs-settings',
@@ -967,8 +1368,18 @@
967 1368 'output',
968 1369 ),
969 1370 $parent_slug
970 1371 ),
1372 + 'mcp' => $this->normalize_menu(
1373 + __( 'MCP', 'betterdocs' ),
1374 + 'betterdocs-mcp',
1375 + 'manage_options',
1376 + array(
1377 + $this,
1378 + 'output',
1379 + ),
1380 + $parent_slug
1381 + ),
971 1382 'analytics' => $this->normalize_menu(
972 1383 __( 'Analytics', 'betterdocs' ),
973 1384 'betterdocs-analytics',
974 1385 'read_docs_analytics',
@@ -977,8 +1388,18 @@
977 1388 'output',
978 1389 ),
979 1390 $parent_slug
980 1391 ),
1392 + 'content_intelligence' => $this->normalize_menu(
1393 + __( 'Content IQ', 'betterdocs' ),
1394 + 'betterdocs-content-iq',
1395 + 'read_docs_analytics',
1396 + array(
1397 + $this,
1398 + 'output',
1399 + ),
1400 + $parent_slug
1401 + ),
981 1402 'faq' => $this->normalize_menu(
982 1403 __( 'FAQ Builder', 'betterdocs' ),
983 1404 'betterdocs-faq',
984 1405 'read_faq_builder',
@@ -989,13 +1410,25 @@
989 1410 $parent_slug
990 1411 ),
991 1412 );
992 1413
993 - if ( betterdocs()->is_pro_active() && betterdocs()->settings->get( 'enable_glossaries' ) == true ) {
1414 + // Content Intelligence ships in Pro, which overwrites that same key in place.
1415 + // Unlike API Docs it has to sit directly after Analytics, and `menus()` walks
1416 + // this array in insertion order — so the slot is declared inside the literal
1417 + // above and only withdrawn here. Appending it after the fact, api_docs-style,
1418 + // would park it at the bottom of the menu.
1419 + if ( ! ( betterdocs()->show_content_intelligence_teaser() || betterdocs()->has_content_intelligence() ) ) {
1420 + unset( $betterdocs_admin_pages['content_intelligence'] );
1421 + }
1422 +
1423 + // Glossaries is Pro. Reserve this same 'glossaries' slot for Free's locked
1424 + // teaser so the item keeps this position; once Pro is active the real
1425 + // screen overwrites the key in place (same pattern as API Docs below).
1426 + if ( betterdocs()->show_glossary_teaser() || ( betterdocs()->is_pro_active() && betterdocs()->settings->get( 'enable_glossaries' ) == true ) ) {
994 1427 $betterdocs_admin_pages['glossaries'] = $this->normalize_menu(
995 1428 __( 'Glossaries', 'betterdocs' ),
996 1429 'betterdocs-glossaries',
997 - 'read_docs_analytics',
1430 + betterdocs()->show_glossary_teaser() ? 'manage_options' : 'read_docs_analytics',
998 1431 array(
999 1432 $this,
1000 1433 'output',
1001 1434 ),
@@ -1002,8 +1435,24 @@
1002 1435 $parent_slug
1003 1436 );
1004 1437 }
1005 1438
1439 + // API Docs ships in Pro, which overwrites this same key in place — declaring
1440 + // the slot here is what keeps the item in this position. Without Pro it
1441 + // holds Free's locked teaser instead.
1442 + if ( betterdocs()->show_api_docs_teaser() || betterdocs()->has_api_docs() ) {
1443 + $betterdocs_admin_pages['api_docs'] = $this->normalize_menu(
1444 + __( 'API Docs', 'betterdocs' ),
1445 + 'betterdocs-api-docs',
1446 + apply_filters( 'betterdocs_api_ref_capability', 'manage_options' ),
1447 + array(
1448 + $this,
1449 + 'output',
1450 + ),
1451 + $parent_slug
1452 + );
1453 + }
1454 +
1006 1455 if ( ! betterdocs()->is_chatbot_active() ) {
1007 1456 $betterdocs_admin_pages['ai_chatbot'] = $this->normalize_menu(
1008 1457 __( 'AI Chatbot', 'betterdocs' ),
1009 1458 'betterdocs-ai-chatbot',
@@ -1018,8 +1467,70 @@
1018 1467
1019 1468 return apply_filters( 'betterdocs_admin_menu', $betterdocs_admin_pages, array( $this, 'output' ), $parent_slug );
1020 1469 }
1021 1470
1471 + /**
1472 + * Put the BetterDocs submenu in a deliberate order.
1473 + *
1474 + * Order used to be an accident of *when* each item was added: Free declares
1475 + * most of them inline, and reserves in-place slots for `glossaries` /
1476 + * `api_docs` so Pro can overwrite the key without moving it. Anything added
1477 + * purely through this filter, though, could only land at the end — which is
1478 + * why Multiple KB (Pro, priority 100) and AI Chatbot Logs sat after
1479 + * everything else regardless of where they belong.
1480 + *
1481 + * Sorting here, at priority 999, fixes that for every source at once: Free's
1482 + * own entries, Pro's, and any add-on's. Knowledge Base now follows Tags (it
1483 + * is the third taxonomy-ish thing, so it belongs with Categories and Tags
1484 + * rather than past Analytics), and API Docs follows Knowledge Base.
1485 + *
1486 + * Keys not listed keep their relative order and are appended, so an add-on
1487 + * that registers something unknown to this list is never dropped.
1488 + *
1489 + * @param array $pages Menu pages keyed by slug id.
1490 + * @return array
1491 + */
1492 + public function order_admin_menu( $pages ) {
1493 + if ( ! is_array( $pages ) ) {
1494 + return $pages;
1495 + }
1496 +
1497 + $order = array(
1498 + 'betterdocs',
1499 + 'dashboard',
1500 + 'all_docs',
1501 + 'add_new',
1502 + 'categories',
1503 + 'tags',
1504 + 'multiple_kb',
1505 + 'api_docs',
1506 + 'settings',
1507 + 'mcp',
1508 + 'analytics',
1509 + // Content IQ reads as a second Analytics screen, so it has to stay
1510 + // pinned directly behind it. Without this entry it would fall into
1511 + // the unknown-key bucket below and be appended to the bottom of the
1512 + // menu — the exact placement the menu literal avoids by declaring
1513 + // the slot inline rather than filtering it in api_docs-style.
1514 + 'content_intelligence',
1515 + 'faq',
1516 + 'glossaries',
1517 + 'ai_chatbot',
1518 + 'ai_chatbot_logs',
1519 + );
1520 +
1521 + $ordered = array();
1522 + foreach ( $order as $key ) {
1523 + if ( array_key_exists( $key, $pages ) ) {
1524 + $ordered[ $key ] = $pages[ $key ];
1525 + unset( $pages[ $key ] );
1526 + }
1527 + }
1528 +
1529 + // `$pages` now holds only unknown keys, still in their original order.
1530 + return array_merge( $ordered, $pages );
1531 + }
1532 +
1022 1533 public function add_custom_classes_to_menu_items() {
1023 1534 global $menu, $submenu;
1024 1535
1025 1536 $menu_items = array(
@@ -1025,15 +1536,18 @@
1025 1536 $menu_items = array(
1026 1537 'betterdocs' => 'betterdocs',
1027 1538 'betterdocs_page_all_docs' => 'betterdocs-all-docs',
1028 1539 'betterdocs_page_add_new' => 'betterdocs-add-new',
1029 - 'edit-tags.php?taxonomy=doc_category&post_type=docs' => 'betterdocs-categories',
1030 - 'edit-tags.php?taxonomy=doc_tag&post_type=docs' => 'betterdocs-tags',
1540 + 'betterdocs-doc-categories' => 'betterdocs-categories',
1541 + 'betterdocs-doc-tags' => 'betterdocs-tags',
1031 1542 'betterdocs-settings' => 'betterdocs-settings',
1543 + 'betterdocs-mcp' => 'betterdocs-mcp',
1032 1544 'betterdocs-analytics' => 'betterdocs-analytics',
1545 + 'betterdocs-content-iq' => 'betterdocs-content-iq',
1033 1546 'betterdocs-faq' => 'betterdocs-faq',
1034 1547 'betterdocs-glossaries' => 'betterdocs-glossaries',
1035 1548 'betterdocs-ai-chatbot' => 'betterdocs-ai-chatbot',
1549 + 'betterdocs-api-docs' => 'betterdocs-api-docs',
1036 1550 'edit-tags.php?taxonomy=knowledge_base&post_type=docs' => 'betterdocs-multiplekb',
1037 1551 );
1038 1552
1039 1553 foreach ( $menu as &$item ) {
@@ -1146,11 +1660,18 @@
1146 1660 *
1147 1661 * @since 3.0.1
1148 1662 */
1149 1663 public function save_admin_page() {
1150 - if ( isset( $_GET['post_type'] ) && 'docs' === $_GET['post_type'] && isset( $_GET['bdocs_view'] ) && 'classic' === $_GET['bdocs_view'] ) { // phpcs:ignore WordPress.Security.NonceVerification.Missing
1664 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- read-only screen detection.
1665 + $post_type = isset( $_GET['post_type'] ) ? sanitize_text_field( wp_unslash( $_GET['post_type'] ) ) : '';
1666 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- read-only screen detection.
1667 + $bdocs_view = isset( $_GET['bdocs_view'] ) ? sanitize_text_field( wp_unslash( $_GET['bdocs_view'] ) ) : '';
1668 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- read-only screen detection.
1669 + $page = isset( $_GET['page'] ) ? sanitize_text_field( wp_unslash( $_GET['page'] ) ) : '';
1670 +
1671 + if ( 'docs' === $post_type && 'classic' === $bdocs_view ) {
1151 1672 update_user_meta( get_current_user_id(), 'last_visited_docs_admin_page', 'classic_ui' );
1152 - } elseif ( isset( $_GET['page'] ) && 'betterdocs-admin' === $_GET['page'] ) { // phpcs:ignore WordPress.Security.NonceVerification.Missing
1673 + } elseif ( 'betterdocs-admin' === $page ) {
1153 1674 update_user_meta( get_current_user_id(), 'last_visited_docs_admin_page', 'modern_ui' );
1154 1675 }
1155 1676 }
1156 1677
@@ -1217,9 +1738,10 @@
1217 1738 * @since 3.7.0
1218 1739 */
1219 1740 public function ajax_dismiss_black_friday_pointer() {
1220 1741 // Verify nonce
1221 - if ( ! isset( $_POST['nonce'] ) || ! wp_verify_nonce( $_POST['nonce'], 'betterdocs_dismiss_pointer' ) ) {
1742 + $nonce = isset( $_POST['nonce'] ) ? sanitize_text_field( wp_unslash( $_POST['nonce'] ) ) : '';
1743 + if ( ! wp_verify_nonce( $nonce, 'betterdocs_dismiss_pointer' ) ) {
1222 1744 wp_send_json_error( array( 'message' => __( 'Invalid nonce', 'betterdocs' ) ) );
1223 1745 }
1224 1746
1225 1747 // Check if user has permission
@@ -1227,9 +1749,9 @@
1227 1749 wp_send_json_error( array( 'message' => __( 'Permission denied', 'betterdocs' ) ) );
1228 1750 }
1229 1751
1230 1752 // Get the introduction key
1231 - $introduction_key = isset( $_POST['introduction_key'] ) ? sanitize_text_field( $_POST['introduction_key'] ) : '';
1753 + $introduction_key = isset( $_POST['introduction_key'] ) ? sanitize_text_field( wp_unslash( $_POST['introduction_key'] ) ) : '';
1232 1754
1233 1755 if ( empty( $introduction_key ) ) {
1234 1756 wp_send_json_error( array( 'message' => __( 'Invalid introduction key', 'betterdocs' ) ) );
1235 1757 }