PluginProbe
Elementor Website Builder – more than just a page builder / 3.16.2
Elementor Website Builder – more than just a page builder v3.16.2
4.3.0-beta2 4.3.0-beta1 4.2.4 4.2.3 4.2.2 4.2.1 4.2.0 4.1.5 4.2.0-beta2 4.2.0-dev2 4.2.0-beta1 4.1.4 4.1.3 4.1.2 4.1.1 4.1.0 4.1.0-beta3 4.1.0-dev3 4.0.9 4.1.0-beta2 4.1.0-dev2 4.0.8 4.1.0-beta1 4.1.0-dev1 4.0.7 All 451 releases
← All changes | includes/utils.php +46 -284 4.3.0-beta23.16.2 View file →
@@ -1,8 +1,7 @@
1 1 <?php
2 2 namespace Elementor;
3 3
4 -use Elementor\Core\Files\Fonts\Google_Font;
5 4 use Elementor\Core\Utils\Collection;
6 5
7 6 if ( ! defined( 'ABSPATH' ) ) {
8 7 exit; // Exit if accessed directly.
@@ -22,9 +21,9 @@
22 21
23 22 const EDITOR_BREAK_LINES_OPTION_KEY = 'elementor_editor_break_lines';
24 23
25 24 /**
26 - * A list of safe tags for `validate_html_tag` method.
25 + * A list of safe tage for `validate_html_tag` method.
27 26 */
28 27 const ALLOWED_HTML_WRAPPER_TAGS = [
29 28 'a',
30 29 'article',
@@ -29,9 +28,8 @@
29 28 'a',
30 29 'article',
31 30 'aside',
32 31 'button',
33 - 'form',
34 32 'div',
35 33 'footer',
36 34 'h1',
37 35 'h2',
@@ -46,29 +44,8 @@
46 44 'section',
47 45 'span',
48 46 ];
49 47
50 - /**
51 - * Tags that must never be usable as an HTML wrapper tag, regardless of what
52 - * `elementor/allowed_html_wrapper_tags` filters return. These are the classic
53 - * script-execution / markup-injection vectors (XSS), so they're enforced as a
54 - * hard denylist rather than left to filter authors to avoid re-adding them.
55 - */
56 - const FORBIDDEN_HTML_WRAPPER_TAGS = [
57 - 'script',
58 - 'iframe',
59 - 'object',
60 - 'embed',
61 - 'style',
62 - 'link',
63 - 'meta',
64 - 'base',
65 - 'noscript',
66 - 'template',
67 - 'svg',
68 - 'math',
69 - ];
70 -
71 48 const EXTENDED_ALLOWED_HTML_TAGS = [
72 49 'iframe' => [
73 50 'iframe' => [
74 51 'allow' => true,
@@ -113,27 +90,10 @@
113 90 ],
114 91 ];
115 92
116 93 /**
117 - * Variables for free to pro upsale modal promotions
118 - */
119 -
120 - const ANIMATED_HEADLINE = 'animated_headline';
121 -
122 - const CTA = 'cta';
123 -
124 - const VIDEO_PLAYLIST = 'video_playlist';
125 -
126 - const TESTIMONIAL_WIDGET = 'testimonial_widget';
127 -
128 - const IMAGE_CAROUSEL = 'image_carousel';
129 -
130 - /**
131 - * Whether WordPress CLI mode is enabled or not.
94 + * Is WP CLI.
132 95 *
133 - * @access public
134 - * @static
135 - *
136 96 * @return bool
137 97 */
138 98 public static function is_wp_cli() {
139 99 return defined( 'WP_CLI' ) && WP_CLI;
@@ -139,8 +99,10 @@
139 99 return defined( 'WP_CLI' ) && WP_CLI;
140 100 }
141 101
142 102 /**
103 + * Is script debug.
104 + *
143 105 * Whether script debug is enabled or not.
144 106 *
145 107 * @since 1.0.0
146 108 * @access public
@@ -145,9 +107,9 @@
145 107 * @since 1.0.0
146 108 * @access public
147 109 * @static
148 110 *
149 - * @return bool
111 + * @return bool True if it's a script debug is active, false otherwise.
150 112 */
151 113 public static function is_script_debug() {
152 114 return defined( 'SCRIPT_DEBUG' ) && SCRIPT_DEBUG;
153 115 }
@@ -152,27 +114,12 @@
152 114 return defined( 'SCRIPT_DEBUG' ) && SCRIPT_DEBUG;
153 115 }
154 116
155 117 /**
156 - * Whether Elementor debug is enabled or not.
118 + * Whether elementor test mode is enabled or not.
157 119 *
158 - * @access public
159 - * @static
160 - *
161 120 * @return bool
162 121 */
163 - public static function is_elementor_debug() {
164 - return defined( 'ELEMENTOR_DEBUG' ) && ELEMENTOR_DEBUG;
165 - }
166 -
167 - /**
168 - * Whether Elementor test mode is enabled or not.
169 - *
170 - * @access public
171 - * @static
172 - *
173 - * @return bool
174 - */
175 122 public static function is_elementor_tests() {
176 123 return defined( 'ELEMENTOR_TESTS' ) && ELEMENTOR_TESTS;
177 124 }
178 125
@@ -216,13 +163,13 @@
216 163 * @since 2.1.0
217 164 * @static
218 165 * @access public
219 166 *
220 - * @param string $from
221 - * @param string $to
167 + * @param $from
168 + * @param $to
222 169 *
223 170 * @return string
224 - * @throws \Exception If URLs are missing or invalid URLs provided.
171 + * @throws \Exception
225 172 */
226 173 public static function replace_urls( $from, $to ) {
227 174 $from = trim( $from );
228 175 $to = trim( $to );
@@ -268,9 +215,8 @@
268 215 // Allow externals to replace-urls, when they have to.
269 216 $rows_affected += (int) apply_filters( 'elementor/tools/replace-urls', 0, $from, $to );
270 217
271 218 Plugin::$instance->files_manager->clear_cache();
272 - Google_Font::clear_cache();
273 219
274 220 return sprintf(
275 221 /* translators: %d: Number of rows. */
276 222 _n( '%d database row affected.', '%d database rows affected.', $rows_affected, 'elementor' ),
@@ -465,9 +411,9 @@
465 411 * @access public
466 412 * @deprecated 3.3.0 Use `Plugin::$instance->documents->get_create_new_post_url()` instead.
467 413 * @static
468 414 *
469 - * @param string $post_type Optional. Post type slug. Default is 'page'.
415 + * @param string $post_type Optional. Post type slug. Default is 'page'.
470 416 * @param string|null $template_type Optional. Query arg 'template_type'. Default is null.
471 417 *
472 418 * @return string A URL for creating new post using Elementor.
473 419 */
@@ -534,14 +480,14 @@
534 480 * @since 2.1.2
535 481 * @access public
536 482 * @static
537 483 */
538 - public static function array_inject( $base_array, $key, $insert ) {
539 - $length = array_search( $key, array_keys( $base_array ), true ) + 1;
484 + public static function array_inject( $array, $key, $insert ) {
485 + $length = array_search( $key, array_keys( $array ), true ) + 1;
540 486
541 - return array_slice( $base_array, 0, $length, true ) +
487 + return array_slice( $array, 0, $length, true ) +
542 488 $insert +
543 - array_slice( $base_array, $length, null, true );
489 + array_slice( $array, $length, null, true );
544 490 }
545 491
546 492 /**
547 493 * Render html attributes
@@ -585,9 +531,9 @@
585 531 * Viewport meta tag.
586 532 *
587 533 * Filters the meta tag containing the viewport information.
588 534 *
589 - * This hook can be used to change the initial viewport meta tag set by Elementor
535 + * This hook can be used to change the intial viewport meta tag set by Elementor
590 536 * and replace it with a different viewport tag.
591 537 *
592 538 * @since 2.5.0
593 539 *
@@ -602,12 +548,11 @@
602 548 /**
603 549 * Add Elementor Config js vars to the relevant script handle,
604 550 * WP will wrap it with <script> tag.
605 551 * To make sure this script runs thru the `script_loader_tag` hook, use a known handle value.
606 - *
607 552 * @param string $handle
608 553 * @param string $js_var
609 - * @param mixed $config
554 + * @param mixed $config
610 555 */
611 556 public static function print_js_config( $handle, $js_var, $config ) {
612 557 $config = wp_json_encode( $config );
613 558
@@ -637,9 +582,9 @@
637 582
638 583 /**
639 584 * Checks a control value for being empty, including a string of '0' not covered by PHP's empty().
640 585 *
641 - * @param mixed $source
586 + * @param mixed $source
642 587 * @param bool|string $key
643 588 *
644 589 * @return bool
645 590 */
@@ -658,34 +603,15 @@
658 603 public static function has_pro() {
659 604 return defined( 'ELEMENTOR_PRO_VERSION' );
660 605 }
661 606
662 - public static function is_license_active(): bool {
663 - return class_exists( '\ElementorPro\License\API' ) && \ElementorPro\License\API::is_license_active();
664 - }
665 -
666 - public static function is_pro_installed_and_not_active(): bool {
667 - if ( ! function_exists( 'get_plugins' ) ) {
668 - require_once ABSPATH . 'wp-admin/includes/plugin.php';
669 - }
670 -
671 - $file_path = self::get_elementor_pro_file_path();
672 - $installed_plugins = get_plugins();
673 -
674 - return isset( $installed_plugins[ $file_path ] );
675 - }
676 -
677 - private static function get_elementor_pro_file_path(): string {
678 - return 'elementor-pro/elementor-pro.php';
679 - }
680 -
681 607 /**
682 608 * Convert HTMLEntities to UTF-8 characters
683 609 *
684 - * @param string $html_string
610 + * @param $string
685 611 * @return string
686 612 */
687 - public static function urlencode_html_entities( $html_string ) {
613 + public static function urlencode_html_entities( $string ) {
688 614 $entities_dictionary = [
689 615 '&#145;' => "'", // Opening single quote
690 616 '&#146;' => "'", // Closing single quote
691 617 '&#147;' => '"', // Closing double quote
@@ -698,11 +624,11 @@
698 624 '&#8222;' => '"', // Double low quote
699 625 ];
700 626
701 627 // Decode decimal entities
702 - $html_string = str_replace( array_keys( $entities_dictionary ), array_values( $entities_dictionary ), $html_string );
628 + $string = str_replace( array_keys( $entities_dictionary ), array_values( $entities_dictionary ), $string );
703 629
704 - return rawurlencode( html_entity_decode( $html_string, ENT_QUOTES | ENT_HTML5, 'UTF-8' ) );
630 + return rawurlencode( html_entity_decode( $string, ENT_QUOTES | ENT_HTML5, 'UTF-8' ) );
705 631 }
706 632
707 633 /**
708 634 * Parse attributes that come as a string of comma-delimited key|value pairs.
@@ -754,19 +680,13 @@
754 680 if ( $id === $element['id'] ) {
755 681 return $element;
756 682 }
757 683
758 - $inner_elements = apply_filters(
759 - 'elementor/utils/find_element_recursive/inner_elements',
760 - $element['elements'] ?? [],
761 - $element
762 - );
684 + if ( ! empty( $element['elements'] ) ) {
685 + $element = self::find_element_recursive( $element['elements'], $id );
763 686
764 - if ( ! empty( $inner_elements ) ) {
765 - $found = self::find_element_recursive( $inner_elements, $id );
766 -
767 - if ( $found ) {
768 - return $found;
687 + if ( $element ) {
688 + return $element;
769 689 }
770 690 }
771 691 }
772 692
@@ -781,10 +701,10 @@
781 701 * Fired by `admin_menu` action.
782 702 *
783 703 * @since 3.1.0
784 704 *
785 - * @param string $menu_slug
786 - * @param string $new_label
705 + * @param $menu_slug
706 + * @param $new_label
787 707 * @access public
788 708 */
789 709 public static function change_submenu_first_item_label( $menu_slug, $new_label ) {
790 710 global $submenu;
@@ -796,45 +716,8 @@
796 716 }
797 717 }
798 718
799 719 /**
800 - * @var string[]|null
801 - */
802 - private static $resolved_allowed_html_wrapper_tags;
803 -
804 - /**
805 - * Get allowed HTML wrapper tags.
806 - *
807 - * @since 4.4.0
808 - *
809 - * @return string[]
810 - */
811 - public static function get_allowed_html_wrapper_tags(): array {
812 - if ( null !== self::$resolved_allowed_html_wrapper_tags ) {
813 - return self::$resolved_allowed_html_wrapper_tags;
814 - }
815 -
816 - /**
817 - * Allowed HTML wrapper tags.
818 - *
819 - * Filters the list of allowed HTML tag names used by `validate_html_tag()`.
820 - *
821 - * Note: tags in `Utils::FORBIDDEN_HTML_WRAPPER_TAGS` (e.g. `script`, `iframe`,
822 - * `object`) are always stripped after this filter runs and cannot be re-added,
823 - * to prevent XSS via a wrapper tag that executes script or embeds external content.
824 - *
825 - * @since 4.4.0
826 - *
827 - * @param string[] $tags A list of lowercase HTML tag name strings.
828 - */
829 - $tags = apply_filters( 'elementor/allowed_html_wrapper_tags', self::ALLOWED_HTML_WRAPPER_TAGS );
830 -
831 - self::$resolved_allowed_html_wrapper_tags = self::normalize_allowed_html_wrapper_tags( $tags );
832 -
833 - return self::$resolved_allowed_html_wrapper_tags;
834 - }
835 -
836 - /**
837 720 * Validate an HTML tag against a safe allowed list.
838 721 *
839 722 * @param string $tag
840 723 *
@@ -840,37 +723,12 @@
840 723 *
841 724 * @return string
842 725 */
843 726 public static function validate_html_tag( $tag ) {
844 - return $tag && in_array( strtolower( $tag ), self::get_allowed_html_wrapper_tags(), true ) ? $tag : 'div';
727 + return in_array( strtolower( $tag ), self::ALLOWED_HTML_WRAPPER_TAGS ) ? $tag : 'div';
845 728 }
846 729
847 730 /**
848 - * @param array $tags
849 - *
850 - * @return string[]
851 - */
852 - private static function normalize_allowed_html_wrapper_tags( array $tags ): array {
853 - $normalized_tags = [];
854 -
855 - foreach ( $tags as $tag ) {
856 - if ( ! is_string( $tag ) ) {
857 - continue;
858 - }
859 -
860 - $tag = strtolower( $tag );
861 -
862 - if ( in_array( $tag, self::FORBIDDEN_HTML_WRAPPER_TAGS, true ) ) {
863 - continue;
864 - }
865 -
866 - $normalized_tags[] = $tag;
867 - }
868 -
869 - return array_values( array_unique( $normalized_tags ) );
870 - }
871 -
872 - /**
873 731 * Safe print a validated HTML tag.
874 732 *
875 733 * @param string $tag
876 734 */
@@ -881,10 +739,10 @@
881 739
882 740 /**
883 741 * Print internal content (not user input) without escaping.
884 742 */
885 - public static function print_unescaped_internal_string( $internal_string ) {
886 - echo $internal_string; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
743 + public static function print_unescaped_internal_string( $string ) {
744 + echo $string; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
887 745 }
888 746
889 747 /**
890 748 * Get recently edited posts query.
@@ -909,9 +767,9 @@
909 767
910 768 return new \WP_Query( $args );
911 769 }
912 770
913 - public static function print_wp_kses_extended( $text, array $tags ) {
771 + public static function print_wp_kses_extended( $string, array $tags ) {
914 772 $allowed_html = wp_kses_allowed_html( 'post' );
915 773
916 774 foreach ( $tags as $tag ) {
917 775 if ( isset( self::EXTENDED_ALLOWED_HTML_TAGS[ $tag ] ) ) {
@@ -919,17 +777,11 @@
919 777 $allowed_html = array_replace_recursive( $allowed_html, $extended_tags );
920 778 }
921 779 }
922 780
923 - echo wp_kses( $text, $allowed_html );
781 + echo wp_kses( $string, $allowed_html );
924 782 }
925 783
926 - public static function kses_post_deep( $data ) {
927 - return map_deep( $data, function ( $value ) {
928 - return is_string( $value ) ? wp_kses_post( $value ) : $value;
929 - } );
930 - }
931 -
932 784 public static function is_elementor_path( $path ) {
933 785 $path = wp_normalize_path( $path );
934 786
935 787 /**
@@ -951,10 +803,10 @@
951 803 } );
952 804 }
953 805
954 806 /**
955 - * @param string $file
956 - * @param mixed ...$args
807 + * @param $file
808 + * @param mixed ...$args
957 809 * @return false|string
958 810 */
959 811 public static function file_get_contents( $file, ...$args ) {
960 812 if ( ! is_file( $file ) || ! is_readable( $file ) ) {
@@ -959,8 +811,9 @@
959 811 public static function file_get_contents( $file, ...$args ) {
960 812 if ( ! is_file( $file ) || ! is_readable( $file ) ) {
961 813 return false;
962 814 }
815 +
963 816 return file_get_contents( $file, ...$args );
964 817 }
965 818
966 819 public static function get_super_global_value( $super_global, $key ) {
@@ -967,122 +820,31 @@
967 820 if ( ! isset( $super_global[ $key ] ) ) {
968 821 return null;
969 822 }
970 823
971 - if ( $_FILES === $super_global ) { // phpcs:ignore WordPress.Security.NonceVerification.Missing
972 - return isset( $super_global[ $key ]['name'] ) ?
973 - self::sanitize_file_name( $super_global[ $key ] ) :
974 - self::sanitize_multi_upload( $super_global[ $key ] );
824 + if ( $_FILES === $super_global ) {
825 + $super_global[ $key ]['name'] = sanitize_file_name( $super_global[ $key ]['name'] );
826 +
827 + return $super_global[ $key ];
975 828 }
976 829
977 830 return wp_kses_post_deep( wp_unslash( $super_global[ $key ] ) );
978 831 }
979 832
980 - private static function sanitize_multi_upload( $fields ) {
981 - return array_map( function( $field ) {
982 - return array_map( 'self::sanitize_file_name', $field );
983 - }, $fields );
984 - }
985 -
986 - private static function sanitize_file_name( $file ) {
987 - $file['name'] = sanitize_file_name( $file['name'] );
988 -
989 - return $file;
990 - }
991 -
992 833 /**
993 834 * Return specific object property value if exist from array of keys.
994 835 *
995 - * @param array $base_array
996 - * @param array $keys
997 - * @return mixed|null
836 + * @param $array
837 + * @param $keys
838 + * @return key|false
998 839 */
999 - public static function get_array_value_by_keys( $base_array, $keys ) {
840 + public static function get_array_value_by_keys( $array, $keys ) {
1000 841 $keys = (array) $keys;
1001 842 foreach ( $keys as $key ) {
1002 - if ( ! isset( $base_array[ $key ] ) ) {
843 + if ( ! isset( $array[ $key ] ) ) {
1003 844 return null;
1004 845 }
1005 - $base_array = $base_array[ $key ];
846 + $array = $array[ $key ];
1006 847 }
1007 - return $base_array;
1008 - }
1009 -
1010 - public static function get_cached_callback( $callback, $cache_key, $cache_time = 24 * HOUR_IN_SECONDS ) {
1011 - $cache = get_site_transient( $cache_key );
1012 -
1013 - if ( ! $cache ) {
1014 - $cache = call_user_func( $callback );
1015 -
1016 - if ( ! is_wp_error( $cache ) ) {
1017 - set_site_transient( $cache_key, $cache, $cache_time );
1018 - }
1019 - }
1020 -
1021 - return $cache;
1022 - }
1023 -
1024 - public static function is_sale_time(): bool {
1025 - $sale_start_time = gmmktime( 10, 0, 0, 6, 15, 2026 );
1026 - $sale_end_time = gmmktime( 3, 59, 0, 6, 17, 2026 );
1027 -
1028 - $now_time = gmdate( 'U' );
1029 -
1030 - return $now_time >= $sale_start_time && $now_time <= $sale_end_time;
1031 - }
1032 -
1033 - public static function safe_throw( string $message ) {
1034 - if ( ! static::is_elementor_debug() ) {
1035 - return;
1036 - }
1037 -
1038 - throw new \Exception( esc_html( $message ) );
1039 - }
1040 -
1041 - public static function has_invalid_post_permissions( $post ): bool {
1042 - $is_image_attachment = 'attachment' === $post->post_type && strpos( $post->post_mime_type, 'image/' ) === 0;
1043 -
1044 - if ( $is_image_attachment ) {
1045 - return false;
1046 - }
1047 -
1048 - $is_private = 'private' === $post->post_status
1049 - && ! current_user_can( 'read_private_posts', $post->ID );
1050 -
1051 - $not_allowed = 'publish' !== $post->post_status
1052 - && ! current_user_can( 'edit_post', $post->ID );
1053 -
1054 - $password_required = post_password_required( $post->ID )
1055 - && ! current_user_can( 'edit_post', $post->ID );
1056 -
1057 - return $is_private || $not_allowed || $password_required;
1058 - }
1059 -
1060 - public static function is_custom_kit_applied() {
1061 - return (bool) Plugin::$instance->kits_manager->get_previous_id();
1062 - }
1063 -
1064 - public static function decode_string( string $encoded_string, ?string $fallback = '' ) {
1065 - try {
1066 - return base64_decode( $encoded_string, true ) ?? $fallback;
1067 - } catch ( \Exception $e ) {
1068 - return $fallback;
1069 - }
1070 - }
1071 -
1072 - public static function encode_string( string $decoded_string ): string {
1073 - return base64_encode( $decoded_string );
1074 - }
1075 -
1076 - public static function html_to_plain_text( string $html ): string {
1077 - if ( empty( $html ) ) {
1078 - return '';
1079 - }
1080 -
1081 - $text = preg_replace( '#<br\s*/?\s*>#i', ' ', $html );
1082 - $text = preg_replace( '#</?[a-z][^>]*>#i', ' ', $text );
1083 - $text = html_entity_decode( $text, ENT_QUOTES, 'UTF-8' );
1084 - $text = str_replace( "\xE2\x80\x8B", '', $text );
1085 -
1086 - return trim( preg_replace( '/\s+/', ' ', $text ) );
848 + return $array;
1087 849 }
1088 850 }