PluginProbe
WPBot – AI ChatBot for Live Support, Lead Generation, WordPress Automation, AI Services / 5.2.2
WPBot – AI ChatBot for Live Support, Lead Generation, WordPress Automation, AI Services v5.2.2
8.7.8 8.7.7 8.7.6 8.7.5 8.7.4 8.7.3 8.7.2 8.7.1 8.7.0 8.6.9 8.6.8 8.6.7 8.6.6 8.6.5 8.6.4 8.6.2 8.6.1 8.6.0 8.5.9 8.5.8 8.5.7 8.5.6 8.5.5 8.5.4 8.5.3 All 534 releases
← All changes | includes/class-response-list.php +33 -49 8.6.95.2.2 View file →
@@ -1,6 +1,5 @@
1 1 <?php
2 -if (!defined('ABSPATH')) exit; // Exit if accessed directly
3 2 if ( ! class_exists( 'WP_List_Table' ) ) {
4 3 require_once( ABSPATH . 'wp-admin/includes/class-wp-list-table.php' );
5 4 }
6 5
@@ -11,10 +10,10 @@
11 10 /** Class constructor */
12 11 public function __construct() {
13 12
14 13 parent::__construct( [
15 - 'singular' => __( 'Response', 'chatbot' ), //singular name of the listed records
16 - 'plural' => __( 'Responses', 'chatbot' ), //plural name of the listed records
14 + 'singular' => __( 'Response', 'wpchatbot' ), //singular name of the listed records
15 + 'plural' => __( 'Responses', 'wpchatbot' ), //plural name of the listed records
17 16 'ajax' => false //does this table support ajax?
18 17 ] );
19 18
20 19 $this->chatbot_admin_page = admin_url('admin.php?page=simple-text-response');
@@ -30,41 +29,27 @@
30 29 *
31 30 * @return mixed
32 31 */
33 32 public static function get_responses( $per_page = 5, $page_number = 1 ) {
33 +
34 +
34 35 global $wpdb;
35 36
36 - // Default order by and order
37 - $orderby = 'id';
38 - $order = 'DESC';
37 + $sql = "SELECT * FROM {$wpdb->prefix}wpbot_response";
39 38
40 - // Allow sorting by column and order if provided and valid
41 39 if ( ! empty( $_REQUEST['orderby'] ) ) {
42 - // Whitelist allowed columns to prevent SQL injection
43 - $allowed = array( 'id', 'intent', 'response', 'type' );
44 - $orderby_request = esc_sql( wp_unslash($_REQUEST['orderby']) );
45 - if ( in_array( $orderby_request, $allowed ) ) {
46 - $orderby = $orderby_request;
47 - }
40 + $sql .= sanitize_sql_orderby(' ORDER BY ' . esc_sql( $_REQUEST['orderby'] ));
41 + $sql .= ! empty( $_REQUEST['order'] ) ? ' ' . sanitize_sql_orderby(esc_sql( $_REQUEST['order'] )) : ' ASC';
48 42 }
49 - if ( ! empty( $_REQUEST['order'] ) ) {
50 - $order_request = strtoupper( esc_sql( wp_unslash($_REQUEST['order']) ) );
51 - if ( in_array( $order_request, array( 'ASC', 'DESC' ) ) ) {
52 - $order = $order_request;
53 - }
54 - }
55 43
56 - $offset = ( $page_number - 1 ) * $per_page;
44 + $sql .= " LIMIT $per_page";
45 + $sql .= ' OFFSET ' . ( $page_number - 1 ) * $per_page;
57 46
58 - // Build the SQL query with validated orderby and order
59 - $sql = $wpdb->prepare(
60 - "SELECT * FROM {$wpdb->prefix}wpbot_response ORDER BY $orderby $order LIMIT %d OFFSET %d",
61 - $per_page,
62 - $offset
63 - );
64 47
65 - $result = $wpdb->get_results( $sql, 'ARRAY_A' ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter
48 + $result = $wpdb->get_results( $sql, 'ARRAY_A' );
66 49
50 +
51 +
67 52 return $result;
68 53 }
69 54
70 55
@@ -75,14 +60,13 @@
75 60 */
76 61 public static function delete_response( $id ) {
77 62 global $wpdb;
78 63
79 - $wpdb->delete( // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
64 + $wpdb->delete(
80 65 "{$wpdb->prefix}wpbot_response",
81 66 [ 'id' => $id ],
82 67 [ '%d' ]
83 68 );
84 -
85 69 }
86 70
87 71
88 72 /**
@@ -94,15 +78,15 @@
94 78 global $wpdb;
95 79
96 80 $sql = "SELECT COUNT(*) FROM {$wpdb->prefix}wpbot_response";
97 81
98 - return $wpdb->get_var( $sql ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared
82 + return $wpdb->get_var( $sql );
99 83 }
100 84
101 85
102 86 /** Text displayed when no customer data is available */
103 87 public function no_items() {
104 - esc_html_e( 'No responses avaliable.', 'chatbot' );
88 + esc_html_e( 'No responses avaliable.', 'wpchatbot' );
105 89 }
106 90
107 91
108 92 /**
@@ -173,12 +157,12 @@
173 157 $delete_nonce = wp_create_nonce( 'wp_delete_query' );
174 158 $edit_nonce = wp_create_nonce( 'wp_edit_query' );
175 159
176 160 $title = '<strong>' . $item['query'] . '</strong>';
177 -// var_dump($title);
161 +
178 162 $actions = [
179 - 'edit' => sprintf( '<a href="?page=%s&action=%s&query=%s&_wpnonce=%s">Edit</a>', esc_attr(wp_unslash($_REQUEST['page'])), 'edit', absint( $item['id'] ), $edit_nonce ),
180 - 'delete' => sprintf( '<a href="?page=%s&action=%s&query=%s&_wpnonce=%s">Delete</a>', esc_attr(wp_unslash($_REQUEST['page'])), 'delete', absint( $item['id'] ), $delete_nonce )
163 + 'edit' => sprintf( '<a href="?page=%s&action=%s&query=%s&_wpnonce=%s">Edit</a>', esc_attr( $_REQUEST['page'] ), 'edit', absint( $item['id'] ), $edit_nonce ),
164 + 'delete' => sprintf( '<a href="?page=%s&action=%s&query=%s&_wpnonce=%s">Delete</a>', esc_attr( $_REQUEST['page'] ), 'delete', absint( $item['id'] ), $delete_nonce )
181 165 ];
182 166
183 167 return $title . $this->row_actions( $actions );
184 168 }
@@ -194,22 +178,22 @@
194 178
195 179 if(class_exists('Qcld_str_pro')){
196 180 $columns = [
197 181 'cb' => '<input type="checkbox" />',
198 - 'query' => __( 'Query', 'chatbot' ),
199 - 'keyword' => __( 'Keyword', 'chatbot' ),
200 - 'responses' => __( 'Response', 'chatbot' ),
201 - 'intent'=> __( 'Intent', 'chatbot' ),
202 - 'category'=> __( 'Category', 'chatbot' ),
182 + 'query' => __( 'Query', 'wpchatbot' ),
183 + 'keyword' => __( 'Keyword', 'wpchatbot' ),
184 + 'responses' => __( 'Response', 'wpchatbot' ),
185 + 'intent'=> __( 'Intent', 'wpchatbot' ),
186 + 'category'=> __( 'Category', 'wpchatbot' ),
203 187
204 188 ];
205 189 }else{
206 190 $columns = [
207 191 'cb' => '<input type="checkbox" />',
208 - 'query' => __( 'Query', 'chatbot' ),
209 - 'keyword' => __( 'Keyword', 'chatbot' ),
210 - 'responses' => __( 'Response', 'chatbot' ),
211 - 'intent'=> __( 'Intent', 'chatbot' ),
192 + 'query' => __( 'Query', 'wpchatbot' ),
193 + 'keyword' => __( 'Keyword', 'wpchatbot' ),
194 + 'responses' => __( 'Response', 'wpchatbot' ),
195 + 'intent'=> __( 'Intent', 'wpchatbot' ),
212 196
213 197 ];
214 198 }
215 199
@@ -277,15 +261,15 @@
277 261 //Detect when a bulk action is being triggered...
278 262 if ( 'delete' === $this->current_action() ) {
279 263
280 264 // In our file that handles the request, verify the nonce.
281 - $nonce = esc_attr(wp_unslash($_REQUEST['_wpnonce']));
265 + $nonce = esc_attr( $_REQUEST['_wpnonce'] );
282 266
283 267 if ( ! wp_verify_nonce( $nonce, 'wp_delete_query' ) ) {
284 268 die( 'Go get a life script kiddies' );
285 269 }
286 270 else {
287 - self::delete_response( absint( wp_unslash($_GET['query']) ) );
271 + self::delete_response( absint( $_GET['query'] ) );
288 272
289 273 // esc_url_raw() is used to prevent converting ampersand in url to "#038;"
290 274 // add_query_arg() return the current url
291 275 //wp_redirect( esc_url_raw($this->chatbot_admin_page) );
@@ -294,13 +278,13 @@
294 278
295 279 }
296 280
297 281 // If the delete bulk action is triggered
298 - if ( ( isset($_POST['action']) && wp_unslash($_POST['action']) == 'bulk-delete' )
299 - || ( isset($_POST['action2']) && wp_unslash($_POST['action2']) == 'bulk-delete' )
282 + if ( ( isset( $_POST['action'] ) && $_POST['action'] == 'bulk-delete' )
283 + || ( isset( $_POST['action2'] ) && $_POST['action2'] == 'bulk-delete' )
300 284 ) {
301 285
302 - $delete_ids = esc_sql( wp_unslash($_POST['bulk-delete']) );
286 + $delete_ids = esc_sql( $_POST['bulk-delete'] );
303 287
304 288
305 289 // loop over the array of record IDs and delete them
306 290 foreach ( $delete_ids as $id ) {
@@ -309,10 +293,10 @@
309 293 }
310 294
311 295 // esc_url_raw() is used to prevent converting ampersand in url to "#038;"
312 296 // add_query_arg() return the current url
313 - wp_safe_redirect( esc_url_raw($this->chatbot_admin_page) );
297 + wp_redirect( esc_url_raw($this->chatbot_admin_page) );
314 298 exit;
315 299 }
316 300 }
317 301
318 302 }