PluginProbe
CryptX / 4.0.1
CryptX v4.0.1
4.2.1 4.2.0 4.1.1 trunk 1.0 1.1 1.2 1.3 1.4 1.5 1.6 1.7 1.9 2.0 2.1 2.2 2.3 2.3.1 2.3.2 2.3.3 2.4.0 2.4.1 2.4.2 2.4.3 2.4.4 All 93 releases
← All changes | cryptx.php +64 -281 4.2.14.0.1 View file →
@@ -2,11 +2,11 @@
2 2 /**
3 3 * Plugin Name: CryptX
4 4 * Plugin URI: https://wordpress.org/plugins/cryptx/
5 5 * Description: CryptX encrypts email addresses in your posts, pages, comments, and text widgets to protect them from spam bots while keeping them readable for your visitors.
6 - * Version: 4.2.1
6 + * Version: 4.0.1
7 7 * Requires at least: 6.7
8 - * Tested up to: 7.1
8 + * Tested up to: 6.8
9 9 * Requires PHP: 8.1
10 10 * Author: Ralf Weber
11 11 * Author URI: https://weber-nrw.de/
12 12 * License: GPL v2 or later
@@ -11,8 +11,11 @@
11 11 * Author URI: https://weber-nrw.de/
12 12 * License: GPL v2 or later
13 13 * License URI: https://www.gnu.org/licenses/gpl-2.0.html
14 14 * Text Domain: cryptx
15 + * Domain Path: /languages
16 + * Network: false
17 + * Update URI: https://wordpress.org/plugins/cryptx/
15 18 *
16 19 * CryptX is free software: you can redistribute it and/or modify
17 20 * it under the terms of the GNU General Public License as published by
18 21 * the Free Software Foundation, either version 2 of the License, or
@@ -35,9 +38,9 @@
35 38 exit;
36 39 }
37 40
38 41 // Plugin constants
39 -define('CRYPTX_VERSION', '4.2.1');
42 +define('CRYPTX_VERSION', '4.0.1');
40 43 define('CRYPTX_PLUGIN_FILE', __FILE__);
41 44 define('CRYPTX_PLUGIN_BASENAME', plugin_basename(__FILE__));
42 45 define('CRYPTX_BASENAME', plugin_basename(__FILE__)); // Add this missing constant
43 46 define('CRYPTX_DIR_PATH', plugin_dir_path(__FILE__));
@@ -43,64 +46,36 @@
43 46 define('CRYPTX_DIR_PATH', plugin_dir_path(__FILE__));
44 47 define('CRYPTX_DIR_URL', plugin_dir_url(__FILE__));
45 48 define('CRYPTX_BASEFOLDER', dirname(CRYPTX_PLUGIN_BASENAME));
46 49
47 -// Minimum requirements. Keep these in sync with the plugin header above and
48 -// with "Requires at least" / "Requires PHP" in readme.txt. They are defined
49 -// once and used both for the check and for the notice, so the number shown to
50 -// the user cannot drift away from the number actually enforced.
51 -define('CRYPTX_MIN_PHP', '8.1');
52 -define('CRYPTX_MIN_WP', '6.7');
53 -
54 -/**
55 - * Shows an admin notice to whoever is in a position to act on it.
56 - *
57 - * Registered on both admin_notices and network_admin_notices. Without the
58 - * second, a network administrator working in the network backend -- the only
59 - * person who can deactivate a network-activated plugin -- never saw that the
60 - * server runs too old a PHP, or that a class file is missing. The capability
61 - * differs per screen: on a site it is activate_plugins, in the network backend
62 - * manage_network_plugins, which a mere site administrator does not hold.
63 - *
64 - * @param string $message The message, already translated and unescaped.
65 - *
66 - * @return void
67 - */
68 -function cryptx_admin_notice(string $message): void
69 -{
70 - $render = static function () use ($message): void {
71 - $capability = is_network_admin() ? 'manage_network_plugins' : 'activate_plugins';
72 -
73 - if (!current_user_can($capability)) {
74 - return;
75 - }
76 -
77 - printf('<div class="notice notice-error"><p>%s</p></div>', esc_html($message));
78 - };
79 -
80 - add_action('admin_notices', $render);
81 - add_action('network_admin_notices', $render);
82 -}
83 -
84 -if (version_compare(PHP_VERSION, CRYPTX_MIN_PHP, '<')) {
85 - cryptx_admin_notice(sprintf(
86 - /* translators: %1$s: Required PHP version, %2$s: Current PHP version */
87 - __('CryptX requires PHP version %1$s or higher. You are running version %2$s. Please update PHP.', 'cryptx'),
88 - CRYPTX_MIN_PHP,
89 - PHP_VERSION
90 - ));
50 +// Minimum requirements check
51 +if (version_compare(PHP_VERSION, '8.1.0', '<')) {
52 + add_action('admin_notices', function() {
53 + echo '<div class="notice notice-error"><p>';
54 + printf(
55 + /* translators: %1$s: Required PHP version, %2$s: Current PHP version */
56 + __('CryptX requires PHP version %1$s or higher. You are running version %2$s. Please update PHP.', 'cryptx'),
57 + '8.1.0',
58 + PHP_VERSION
59 + );
60 + echo '</p></div>';
61 + });
91 62 return;
92 63 }
93 64
94 65 // WordPress version check
95 66 global $wp_version;
96 -if (version_compare($wp_version, CRYPTX_MIN_WP, '<')) {
97 - cryptx_admin_notice(sprintf(
98 - /* translators: %1$s: Required WordPress version, %2$s: Current WordPress version */
99 - __('CryptX requires WordPress version %1$s or higher. You are running version %2$s. Please update WordPress.', 'cryptx'),
100 - CRYPTX_MIN_WP,
101 - $GLOBALS['wp_version']
102 - ));
67 +if (version_compare($wp_version, '6.7', '<')) {
68 + add_action('admin_notices', function() {
69 + echo '<div class="notice notice-error"><p>';
70 + printf(
71 + /* translators: %1$s: Required WordPress version, %2$s: Current WordPress version */
72 + __('CryptX requires WordPress version %1$s or higher. You are running version %2$s. Please update WordPress.', 'cryptx'),
73 + '5.0',
74 + $GLOBALS['wp_version']
75 + );
76 + echo '</p></div>';
77 + });
103 78 return;
104 79 }
105 80
106 81 // Autoloader for plugin classes
@@ -124,15 +99,8 @@
124 99 require_once $file;
125 100 }
126 101 });
127 102
128 -// The settings screen posts nothing: it talks to the REST routes in
129 -// CryptX\Admin\RestController, which carry their own capability check and are
130 -// covered by WordPress' REST nonce. The global cryptx_nonce_check() that used
131 -// to sit here guarded $_POST['cryptX_var'], a key nothing has sent since the
132 -// old settings form was removed in 4.1.0 -- a dead guard next to a live one is
133 -// a trap for whoever wires up the next form.
134 -
135 103 // Initialize the plugin
136 104 add_action('plugins_loaded', function() {
137 105 // Check if all required classes can be loaded
138 106 $requiredClasses = [
@@ -137,17 +105,14 @@
137 105 // Check if all required classes can be loaded
138 106 $requiredClasses = [
139 107 'CryptX\\CryptX',
140 108 'CryptX\\Config',
109 + 'CryptX\\CryptXSettingsTabs',
141 110 'CryptX\\SecureEncryption',
142 - 'CryptX\\Exposure',
143 - 'CryptX\\Block',
144 - 'CryptX\\ImageToken',
145 - 'CryptX\\Admin\\NetworkDefaults',
146 - 'CryptX\\Admin\\SettingsPage',
147 - 'CryptX\\Admin\\SettingsSchema',
148 - 'CryptX\\Admin\\RestController',
149 - 'CryptX\\Admin\\SiteHealth',
111 + 'CryptX\\Admin\\ChangelogSettingsTab',
112 + 'CryptX\\Admin\\GeneralSettingsTab',
113 + 'CryptX\\Admin\\PresentationSettingsTab',
114 + 'CryptX\\Util\\DataSanitizer',
150 115 ];
151 116
152 117 $missingClasses = [];
153 118 foreach ($requiredClasses as $class) {
@@ -156,11 +121,13 @@
156 121 }
157 122 }
158 123
159 124 if (!empty($missingClasses)) {
160 - cryptx_admin_notice(
161 - __('CryptX: Missing required classes: ', 'cryptx') . implode(', ', $missingClasses)
162 - );
125 + add_action('admin_notices', function() use ($missingClasses) {
126 + echo '<div class="notice notice-error"><p>';
127 + echo esc_html__('CryptX: Missing required classes: ', 'cryptx') . implode(', ', $missingClasses);
128 + echo '</p></div>';
129 + });
163 130 return;
164 131 }
165 132
166 133 // Initialize the main plugin class
@@ -166,194 +133,39 @@
166 133 // Initialize the main plugin class
167 134 try {
168 135 $cryptx_instance = CryptX\CryptX::get_instance();
169 136 $cryptx_instance->startCryptX();
170 - cryptx_register_action_links();
171 -
172 - // Guarded here as well as inside register(), and deliberately not
173 - // listed in $requiredClasses above. Both of those would load the file
174 - // on every single front-end and admin request -- class_exists() runs
175 - // the autoloader, and so does a static call -- to register commands
176 - // that only exist under WP-CLI.
177 - //
178 - // class_exists() is still asked so that a package missing the file
179 - // cannot raise a fatal Error, which catch (Exception) below would not
180 - // have caught. It buys no notice: the commands are then simply absent.
181 - // That is the right silence -- nothing a visitor or an administrator
182 - // sees depends on them.
183 - if (defined('WP_CLI') && WP_CLI && class_exists('CryptX\Cli')) {
184 - CryptX\Cli::register();
185 - }
186 137 } catch (Exception $e) {
187 - cryptx_admin_notice(
188 - __('CryptX initialization failed: ', 'cryptx') . $e->getMessage()
189 - );
138 + add_action('admin_notices', function() use ($e) {
139 + echo '<div class="notice notice-error"><p>';
140 + echo esc_html__('CryptX initialization failed: ', 'cryptx') . esc_html($e->getMessage());
141 + echo '</p></div>';
142 + });
190 143 }
191 144 });
192 145
193 -/**
194 - * Runs a callback once for every site of the network, in batches.
195 - *
196 - * get_sites() without a limit pulls the whole network into memory, and a
197 - * network can have thousands of sites. Same construction as uninstall.php,
198 - * deliberately: the two do the same job at opposite ends of the plugin's life,
199 - * and one of them being cleverer than the other only makes both harder to
200 - * trust.
201 - *
202 - * On a single site the callback simply runs once.
203 - *
204 - * @param callable $callback Receives nothing; runs with the site switched in.
205 - *
206 - * @return void
207 - */
208 -function cryptx_for_each_site(callable $callback): void
209 -{
210 - if (!is_multisite()) {
211 - $callback();
146 +// Remove the strict activation requirements - let the plugin handle fallbacks
147 +register_activation_hook(__FILE__, function() {
148 + // Just flush rewrite rules
149 + flush_rewrite_rules();
150 +});
212 151
213 - return;
214 - }
215 -
216 - $batch_size = 100;
217 - $offset = 0;
218 -
219 - do {
220 - $site_ids = get_sites([
221 - 'fields' => 'ids',
222 - 'number' => $batch_size,
223 - 'offset' => $offset,
224 - 'orderby' => 'id',
225 - 'update_site_meta_cache' => false,
226 - ]);
227 -
228 - foreach ($site_ids as $site_id) {
229 - switch_to_blog($site_id);
230 -
231 - // finally, so a failing callback does not leave the blog stack
232 - // switched for whatever runs next. It does not keep the loop
233 - // going: an exception still travels upwards and the remaining
234 - // sites are skipped. Catching it here would hide a broken site
235 - // instead, and that is a trade to make deliberately, not in
236 - // passing.
237 - try {
238 - $callback();
239 - } finally {
240 - restore_current_blog();
241 - }
242 - }
243 -
244 - $offset += $batch_size;
245 - } while (count($site_ids) === $batch_size);
246 -}
247 -
248 -/**
249 - * Removes the plugin's transients from the site that is currently switched in.
250 - *
251 - * @return void
252 - */
253 -function cryptx_delete_transients(): void
254 -{
152 +// Plugin deactivation hook
153 +register_deactivation_hook(__FILE__, function() {
154 + // Clean up any transients or cached data
255 155 global $wpdb;
256 -
257 - // The LIKE patterns run through $wpdb->esc_like() and $wpdb->prepare().
258 - // No user input is involved here, so this is not a hole, but "_" is a
259 - // single-character wildcard in LIKE: unescaped, '_transient_cryptx_%' also
260 - // matches names like 'Xtransient1cryptxZ...' belonging to other plugins.
261 - // esc_like() turns those underscores into literal ones. The table name is
262 - // an identifier, not a value, and therefore must stay outside prepare().
263 - $transientLike = $wpdb->esc_like('_transient_cryptx_') . '%';
264 - $transientTimeoutLike = $wpdb->esc_like('_transient_timeout_cryptx_') . '%';
265 -
266 - // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
267 - $wpdb->query($wpdb->prepare("DELETE FROM {$wpdb->options} WHERE option_name LIKE %s", $transientLike));
268 - // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
269 - $wpdb->query($wpdb->prepare("DELETE FROM {$wpdb->options} WHERE option_name LIKE %s", $transientTimeoutLike));
270 -}
271 -
272 -/**
273 - * Sets up the plugin's options for the site that is currently switched in.
274 - *
275 - * @return void
276 - */
277 -function cryptx_install_site(): void
278 -{
279 - if (!class_exists('CryptX\\CryptX')) {
280 - return;
281 - }
282 -
283 - CryptX\CryptX::get_instance()->installCryptX();
284 -}
285 -
286 -// Activation.
287 -//
288 -// $network_wide is true when someone ticks "Network Activate". WordPress then
289 -// fires this hook exactly once, not once per site -- so without the loop, every
290 -// site but the current one is left without its stored options and, more to the
291 -// point, without the one-time migration of the pre-4.0 "cryptxoff" post meta.
292 -// The plugin still works there, because the defaults fill in, but a site that
293 -// carried excluded posts from an old version would silently lose them.
294 -register_activation_hook(__FILE__, function ($network_wide = false) {
295 - if ($network_wide) {
296 - cryptx_for_each_site('cryptx_install_site');
297 - } else {
298 - cryptx_install_site();
299 - }
300 -
301 - flush_rewrite_rules();
156 + $wpdb->query("DELETE FROM {$wpdb->options} WHERE option_name LIKE '_transient_cryptx_%'");
157 + $wpdb->query("DELETE FROM {$wpdb->options} WHERE option_name LIKE '_transient_timeout_cryptx_%'");
302 158 });
303 159
304 -// Deactivation. Same reason, other direction: the transients of every site but
305 -// the current one used to survive a network deactivation.
306 -register_deactivation_hook(__FILE__, function ($network_wide = false) {
307 - if ($network_wide) {
308 - cryptx_for_each_site('cryptx_delete_transients');
309 - } else {
310 - cryptx_delete_transients();
311 - }
160 +// Add plugin action links - updated to match the settings page slug
161 +add_filter('plugin_action_links_' . plugin_basename(__FILE__), function($links) {
162 + $settings_link = '<a href="' . admin_url('options-general.php?page=cryptx') . '">' .
163 + esc_html__('Settings', 'cryptx') . '</a>';
164 + array_unshift($links, $settings_link);
165 + return $links;
312 166 });
313 167
314 -// A site created while the plugin is network-active gets the same treatment as
315 -// one that existed at activation time. Without this the new site works -- the
316 -// defaults see to that -- but nothing is ever written until someone saves, and
317 -// the behaviour differs from every other site in the network for no reason
318 -// anybody could see.
319 -add_action('wp_initialize_site', function ($site) {
320 - // The network option directly, not is_plugin_active_for_network(): that
321 - // lives in wp-admin/includes/plugin.php, which is not loaded when a site is
322 - // created over the REST API or WP-CLI -- exactly the paths that create sites
323 - // in bulk.
324 - $network_active = get_site_option('active_sitewide_plugins', []);
325 -
326 - if (!isset($network_active[CRYPTX_PLUGIN_BASENAME])) {
327 - return;
328 - }
329 -
330 - $site_id = is_object($site) ? (int) $site->blog_id : (int) $site;
331 -
332 - switch_to_blog($site_id);
333 - cryptx_install_site();
334 - restore_current_blog();
335 -}, 20);
336 -
337 -// Add plugin action links.
338 -//
339 -// Registered inside the successful-initialisation path on purpose, not at the
340 -// top level of this file. It refers to a class constant, and the plugins screen
341 -// is exactly where someone goes to switch off a plugin whose class files are
342 -// missing -- a fatal error there would take away the only lever they have.
343 -// A plugin that did not initialise has no settings page to link to anyway.
344 -function cryptx_register_action_links(): void
345 -{
346 - add_filter('plugin_action_links_' . CRYPTX_PLUGIN_BASENAME, function ($links) {
347 - $settings_link = '<a href="' .
348 - esc_url(admin_url('options-general.php?page=' . CryptX\Admin\SettingsPage::MENU_SLUG)) .
349 - '">' . esc_html__('Settings', 'cryptx') . '</a>';
350 - array_unshift($links, $settings_link);
351 -
352 - return $links;
353 - });
354 -}
355 -
356 168 /**
357 169 * Encrypts the given content using the CryptX library and wraps it with a shortcode.
358 170 *
359 171 * @param string $content The content to be encrypted.
@@ -360,42 +172,13 @@
360 172 * @param array|null $args Optional arguments to customize the encryption process.
361 173 *
362 174 * @return string The encrypted content wrapped in the appropriate shortcode.
363 175 */
364 -if (!function_exists('cryptx_encrypt')) {
365 - function cryptx_encrypt(string $content, ?array $args = []): string
366 - {
176 +if (!function_exists('encryptx')) {
177 + function encryptx(string $content, ?array $args = []): string {
367 178 $cryptXInstance = Cryptx\CryptX::get_instance();
368 - // $attributesString contains the escaped (esc_attr()) shortcode attributes from $args
369 - // The signature allows null, convertArrayToArgumentString() does not.
370 - $attributesString = $cryptXInstance->convertArrayToArgumentString($args ?? []);
179 + $attributesString = $cryptXInstance->convertArrayToArgumentString($args);
180 + $shortcode = '[cryptx' . $attributesString . ']' . $content . '[/cryptx]';
371 181
372 - // wp_kses_post() and not esc_html(): the caller passes content, and
373 - // content in WordPress may carry markup. esc_html() turned a "<br>" in
374 - // a theme field into a visible "&lt;br&gt;" -- reported in the support
375 - // forum, and worked around there with html_entity_decode(), which
376 - // undoes the plugin's own protection in the Unicode and entity modes.
377 - // wp_kses_post keeps what a post may contain and drops the rest.
378 - $shortcode = '[cryptx' . $attributesString . ']' . wp_kses_post($content) . '[/cryptx]';
379 -
380 182 return do_shortcode($shortcode);
381 - }
382 -}
383 -
384 -/**
385 - * Encrypts the given content using the CryptX library and wraps it with a shortcode.
386 - *
387 - * @deprecated 4.0.5 Use cryptx_encrypt() instead.
388 - * @see cryptx_encrypt()
389 - */
390 -if (!function_exists('encryptx')) {
391 - function encryptx(string $content, ?array $args = []): string
392 - {
393 - _doing_it_wrong(
394 - 'encryptx',
395 - esc_html__('This function is deprecated. Use cryptx_encrypt() instead.', 'cryptx'),
396 - '4.0.5'
397 - );
398 -
399 - return cryptx_encrypt($content, $args);
400 183 }
401 184 }