PluginProbe
Elementor Website Builder – more than just a page builder / 3.26.4
Elementor Website Builder – more than just a page builder v3.26.4
4.3.0-beta2 4.3.0-beta1 4.2.4 4.2.3 4.2.2 4.2.1 4.2.0 4.1.5 4.2.0-beta2 4.2.0-dev2 4.2.0-beta1 4.1.4 4.1.3 4.1.2 4.1.1 4.1.0 4.1.0-beta3 4.1.0-dev3 4.0.9 4.1.0-beta2 4.1.0-dev2 4.0.8 4.1.0-beta1 4.1.0-dev1 4.0.7 All 451 releases
← All changes | includes/utils.php +44 -202 4.3.0-beta23.26.4 View file →
@@ -1,8 +1,7 @@
1 1 <?php
2 2 namespace Elementor;
3 3
4 -use Elementor\Core\Files\Fonts\Google_Font;
5 4 use Elementor\Core\Utils\Collection;
6 5
7 6 if ( ! defined( 'ABSPATH' ) ) {
8 7 exit; // Exit if accessed directly.
@@ -29,9 +28,8 @@
29 28 'a',
30 29 'article',
31 30 'aside',
32 31 'button',
33 - 'form',
34 32 'div',
35 33 'footer',
36 34 'h1',
37 35 'h2',
@@ -46,29 +44,8 @@
46 44 'section',
47 45 'span',
48 46 ];
49 47
50 - /**
51 - * Tags that must never be usable as an HTML wrapper tag, regardless of what
52 - * `elementor/allowed_html_wrapper_tags` filters return. These are the classic
53 - * script-execution / markup-injection vectors (XSS), so they're enforced as a
54 - * hard denylist rather than left to filter authors to avoid re-adding them.
55 - */
56 - const FORBIDDEN_HTML_WRAPPER_TAGS = [
57 - 'script',
58 - 'iframe',
59 - 'object',
60 - 'embed',
61 - 'style',
62 - 'link',
63 - 'meta',
64 - 'base',
65 - 'noscript',
66 - 'template',
67 - 'svg',
68 - 'math',
69 - ];
70 -
71 48 const EXTENDED_ALLOWED_HTML_TAGS = [
72 49 'iframe' => [
73 50 'iframe' => [
74 51 'allow' => true,
@@ -127,13 +104,10 @@
127 104
128 105 const IMAGE_CAROUSEL = 'image_carousel';
129 106
130 107 /**
131 - * Whether WordPress CLI mode is enabled or not.
108 + * Is WP CLI.
132 109 *
133 - * @access public
134 - * @static
135 - *
136 110 * @return bool
137 111 */
138 112 public static function is_wp_cli() {
139 113 return defined( 'WP_CLI' ) && WP_CLI;
@@ -139,8 +113,10 @@
139 113 return defined( 'WP_CLI' ) && WP_CLI;
140 114 }
141 115
142 116 /**
117 + * Is script debug.
118 + *
143 119 * Whether script debug is enabled or not.
144 120 *
145 121 * @since 1.0.0
146 122 * @access public
@@ -145,32 +121,21 @@
145 121 * @since 1.0.0
146 122 * @access public
147 123 * @static
148 124 *
149 - * @return bool
125 + * @return bool True if it's a script debug is active, false otherwise.
150 126 */
151 127 public static function is_script_debug() {
152 128 return defined( 'SCRIPT_DEBUG' ) && SCRIPT_DEBUG;
153 129 }
154 130
155 - /**
156 - * Whether Elementor debug is enabled or not.
157 - *
158 - * @access public
159 - * @static
160 - *
161 - * @return bool
162 - */
163 131 public static function is_elementor_debug() {
164 132 return defined( 'ELEMENTOR_DEBUG' ) && ELEMENTOR_DEBUG;
165 133 }
166 134
167 135 /**
168 - * Whether Elementor test mode is enabled or not.
136 + * Whether elementor test mode is enabled or not.
169 137 *
170 - * @access public
171 - * @static
172 - *
173 138 * @return bool
174 139 */
175 140 public static function is_elementor_tests() {
176 141 return defined( 'ELEMENTOR_TESTS' ) && ELEMENTOR_TESTS;
@@ -216,13 +181,13 @@
216 181 * @since 2.1.0
217 182 * @static
218 183 * @access public
219 184 *
220 - * @param string $from
221 - * @param string $to
185 + * @param $from
186 + * @param $to
222 187 *
223 188 * @return string
224 - * @throws \Exception If URLs are missing or invalid URLs provided.
189 + * @throws \Exception
225 190 */
226 191 public static function replace_urls( $from, $to ) {
227 192 $from = trim( $from );
228 193 $to = trim( $to );
@@ -268,9 +233,8 @@
268 233 // Allow externals to replace-urls, when they have to.
269 234 $rows_affected += (int) apply_filters( 'elementor/tools/replace-urls', 0, $from, $to );
270 235
271 236 Plugin::$instance->files_manager->clear_cache();
272 - Google_Font::clear_cache();
273 237
274 238 return sprintf(
275 239 /* translators: %d: Number of rows. */
276 240 _n( '%d database row affected.', '%d database rows affected.', $rows_affected, 'elementor' ),
@@ -465,9 +429,9 @@
465 429 * @access public
466 430 * @deprecated 3.3.0 Use `Plugin::$instance->documents->get_create_new_post_url()` instead.
467 431 * @static
468 432 *
469 - * @param string $post_type Optional. Post type slug. Default is 'page'.
433 + * @param string $post_type Optional. Post type slug. Default is 'page'.
470 434 * @param string|null $template_type Optional. Query arg 'template_type'. Default is null.
471 435 *
472 436 * @return string A URL for creating new post using Elementor.
473 437 */
@@ -534,14 +498,14 @@
534 498 * @since 2.1.2
535 499 * @access public
536 500 * @static
537 501 */
538 - public static function array_inject( $base_array, $key, $insert ) {
539 - $length = array_search( $key, array_keys( $base_array ), true ) + 1;
502 + public static function array_inject( $array, $key, $insert ) {
503 + $length = array_search( $key, array_keys( $array ), true ) + 1;
540 504
541 - return array_slice( $base_array, 0, $length, true ) +
505 + return array_slice( $array, 0, $length, true ) +
542 506 $insert +
543 - array_slice( $base_array, $length, null, true );
507 + array_slice( $array, $length, null, true );
544 508 }
545 509
546 510 /**
547 511 * Render html attributes
@@ -602,12 +566,11 @@
602 566 /**
603 567 * Add Elementor Config js vars to the relevant script handle,
604 568 * WP will wrap it with <script> tag.
605 569 * To make sure this script runs thru the `script_loader_tag` hook, use a known handle value.
606 - *
607 570 * @param string $handle
608 571 * @param string $js_var
609 - * @param mixed $config
572 + * @param mixed $config
610 573 */
611 574 public static function print_js_config( $handle, $js_var, $config ) {
612 575 $config = wp_json_encode( $config );
613 576
@@ -637,9 +600,9 @@
637 600
638 601 /**
639 602 * Checks a control value for being empty, including a string of '0' not covered by PHP's empty().
640 603 *
641 - * @param mixed $source
604 + * @param mixed $source
642 605 * @param bool|string $key
643 606 *
644 607 * @return bool
645 608 */
@@ -658,34 +621,15 @@
658 621 public static function has_pro() {
659 622 return defined( 'ELEMENTOR_PRO_VERSION' );
660 623 }
661 624
662 - public static function is_license_active(): bool {
663 - return class_exists( '\ElementorPro\License\API' ) && \ElementorPro\License\API::is_license_active();
664 - }
665 -
666 - public static function is_pro_installed_and_not_active(): bool {
667 - if ( ! function_exists( 'get_plugins' ) ) {
668 - require_once ABSPATH . 'wp-admin/includes/plugin.php';
669 - }
670 -
671 - $file_path = self::get_elementor_pro_file_path();
672 - $installed_plugins = get_plugins();
673 -
674 - return isset( $installed_plugins[ $file_path ] );
675 - }
676 -
677 - private static function get_elementor_pro_file_path(): string {
678 - return 'elementor-pro/elementor-pro.php';
679 - }
680 -
681 625 /**
682 626 * Convert HTMLEntities to UTF-8 characters
683 627 *
684 - * @param string $html_string
628 + * @param $string
685 629 * @return string
686 630 */
687 - public static function urlencode_html_entities( $html_string ) {
631 + public static function urlencode_html_entities( $string ) {
688 632 $entities_dictionary = [
689 633 '&#145;' => "'", // Opening single quote
690 634 '&#146;' => "'", // Closing single quote
691 635 '&#147;' => '"', // Closing double quote
@@ -698,11 +642,11 @@
698 642 '&#8222;' => '"', // Double low quote
699 643 ];
700 644
701 645 // Decode decimal entities
702 - $html_string = str_replace( array_keys( $entities_dictionary ), array_values( $entities_dictionary ), $html_string );
646 + $string = str_replace( array_keys( $entities_dictionary ), array_values( $entities_dictionary ), $string );
703 647
704 - return rawurlencode( html_entity_decode( $html_string, ENT_QUOTES | ENT_HTML5, 'UTF-8' ) );
648 + return rawurlencode( html_entity_decode( $string, ENT_QUOTES | ENT_HTML5, 'UTF-8' ) );
705 649 }
706 650
707 651 /**
708 652 * Parse attributes that come as a string of comma-delimited key|value pairs.
@@ -754,19 +698,13 @@
754 698 if ( $id === $element['id'] ) {
755 699 return $element;
756 700 }
757 701
758 - $inner_elements = apply_filters(
759 - 'elementor/utils/find_element_recursive/inner_elements',
760 - $element['elements'] ?? [],
761 - $element
762 - );
702 + if ( ! empty( $element['elements'] ) ) {
703 + $element = self::find_element_recursive( $element['elements'], $id );
763 704
764 - if ( ! empty( $inner_elements ) ) {
765 - $found = self::find_element_recursive( $inner_elements, $id );
766 -
767 - if ( $found ) {
768 - return $found;
705 + if ( $element ) {
706 + return $element;
769 707 }
770 708 }
771 709 }
772 710
@@ -781,10 +719,10 @@
781 719 * Fired by `admin_menu` action.
782 720 *
783 721 * @since 3.1.0
784 722 *
785 - * @param string $menu_slug
786 - * @param string $new_label
723 + * @param $menu_slug
724 + * @param $new_label
787 725 * @access public
788 726 */
789 727 public static function change_submenu_first_item_label( $menu_slug, $new_label ) {
790 728 global $submenu;
@@ -796,45 +734,8 @@
796 734 }
797 735 }
798 736
799 737 /**
800 - * @var string[]|null
801 - */
802 - private static $resolved_allowed_html_wrapper_tags;
803 -
804 - /**
805 - * Get allowed HTML wrapper tags.
806 - *
807 - * @since 4.4.0
808 - *
809 - * @return string[]
810 - */
811 - public static function get_allowed_html_wrapper_tags(): array {
812 - if ( null !== self::$resolved_allowed_html_wrapper_tags ) {
813 - return self::$resolved_allowed_html_wrapper_tags;
814 - }
815 -
816 - /**
817 - * Allowed HTML wrapper tags.
818 - *
819 - * Filters the list of allowed HTML tag names used by `validate_html_tag()`.
820 - *
821 - * Note: tags in `Utils::FORBIDDEN_HTML_WRAPPER_TAGS` (e.g. `script`, `iframe`,
822 - * `object`) are always stripped after this filter runs and cannot be re-added,
823 - * to prevent XSS via a wrapper tag that executes script or embeds external content.
824 - *
825 - * @since 4.4.0
826 - *
827 - * @param string[] $tags A list of lowercase HTML tag name strings.
828 - */
829 - $tags = apply_filters( 'elementor/allowed_html_wrapper_tags', self::ALLOWED_HTML_WRAPPER_TAGS );
830 -
831 - self::$resolved_allowed_html_wrapper_tags = self::normalize_allowed_html_wrapper_tags( $tags );
832 -
833 - return self::$resolved_allowed_html_wrapper_tags;
834 - }
835 -
836 - /**
837 738 * Validate an HTML tag against a safe allowed list.
838 739 *
839 740 * @param string $tag
840 741 *
@@ -840,37 +741,12 @@
840 741 *
841 742 * @return string
842 743 */
843 744 public static function validate_html_tag( $tag ) {
844 - return $tag && in_array( strtolower( $tag ), self::get_allowed_html_wrapper_tags(), true ) ? $tag : 'div';
745 + return $tag && in_array( strtolower( $tag ), self::ALLOWED_HTML_WRAPPER_TAGS ) ? $tag : 'div';
845 746 }
846 747
847 748 /**
848 - * @param array $tags
849 - *
850 - * @return string[]
851 - */
852 - private static function normalize_allowed_html_wrapper_tags( array $tags ): array {
853 - $normalized_tags = [];
854 -
855 - foreach ( $tags as $tag ) {
856 - if ( ! is_string( $tag ) ) {
857 - continue;
858 - }
859 -
860 - $tag = strtolower( $tag );
861 -
862 - if ( in_array( $tag, self::FORBIDDEN_HTML_WRAPPER_TAGS, true ) ) {
863 - continue;
864 - }
865 -
866 - $normalized_tags[] = $tag;
867 - }
868 -
869 - return array_values( array_unique( $normalized_tags ) );
870 - }
871 -
872 - /**
873 749 * Safe print a validated HTML tag.
874 750 *
875 751 * @param string $tag
876 752 */
@@ -881,10 +757,10 @@
881 757
882 758 /**
883 759 * Print internal content (not user input) without escaping.
884 760 */
885 - public static function print_unescaped_internal_string( $internal_string ) {
886 - echo $internal_string; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
761 + public static function print_unescaped_internal_string( $string ) {
762 + echo $string; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
887 763 }
888 764
889 765 /**
890 766 * Get recently edited posts query.
@@ -909,9 +785,9 @@
909 785
910 786 return new \WP_Query( $args );
911 787 }
912 788
913 - public static function print_wp_kses_extended( $text, array $tags ) {
789 + public static function print_wp_kses_extended( $string, array $tags ) {
914 790 $allowed_html = wp_kses_allowed_html( 'post' );
915 791
916 792 foreach ( $tags as $tag ) {
917 793 if ( isset( self::EXTENDED_ALLOWED_HTML_TAGS[ $tag ] ) ) {
@@ -919,17 +795,11 @@
919 795 $allowed_html = array_replace_recursive( $allowed_html, $extended_tags );
920 796 }
921 797 }
922 798
923 - echo wp_kses( $text, $allowed_html );
799 + echo wp_kses( $string, $allowed_html );
924 800 }
925 801
926 - public static function kses_post_deep( $data ) {
927 - return map_deep( $data, function ( $value ) {
928 - return is_string( $value ) ? wp_kses_post( $value ) : $value;
929 - } );
930 - }
931 -
932 802 public static function is_elementor_path( $path ) {
933 803 $path = wp_normalize_path( $path );
934 804
935 805 /**
@@ -951,10 +821,10 @@
951 821 } );
952 822 }
953 823
954 824 /**
955 - * @param string $file
956 - * @param mixed ...$args
825 + * @param $file
826 + * @param mixed ...$args
957 827 * @return false|string
958 828 */
959 829 public static function file_get_contents( $file, ...$args ) {
960 830 if ( ! is_file( $file ) || ! is_readable( $file ) ) {
@@ -959,8 +829,9 @@
959 829 public static function file_get_contents( $file, ...$args ) {
960 830 if ( ! is_file( $file ) || ! is_readable( $file ) ) {
961 831 return false;
962 832 }
833 +
963 834 return file_get_contents( $file, ...$args );
964 835 }
965 836
966 837 public static function get_super_global_value( $super_global, $key ) {
@@ -967,9 +838,9 @@
967 838 if ( ! isset( $super_global[ $key ] ) ) {
968 839 return null;
969 840 }
970 841
971 - if ( $_FILES === $super_global ) { // phpcs:ignore WordPress.Security.NonceVerification.Missing
842 + if ( $_FILES === $super_global ) {
972 843 return isset( $super_global[ $key ]['name'] ) ?
973 844 self::sanitize_file_name( $super_global[ $key ] ) :
974 845 self::sanitize_multi_upload( $super_global[ $key ] );
975 846 }
@@ -991,21 +862,21 @@
991 862
992 863 /**
993 864 * Return specific object property value if exist from array of keys.
994 865 *
995 - * @param array $base_array
996 - * @param array $keys
997 - * @return mixed|null
866 + * @param $array
867 + * @param $keys
868 + * @return key|false
998 869 */
999 - public static function get_array_value_by_keys( $base_array, $keys ) {
870 + public static function get_array_value_by_keys( $array, $keys ) {
1000 871 $keys = (array) $keys;
1001 872 foreach ( $keys as $key ) {
1002 - if ( ! isset( $base_array[ $key ] ) ) {
873 + if ( ! isset( $array[ $key ] ) ) {
1003 874 return null;
1004 875 }
1005 - $base_array = $base_array[ $key ];
876 + $array = $array[ $key ];
1006 877 }
1007 - return $base_array;
878 + return $array;
1008 879 }
1009 880
1010 881 public static function get_cached_callback( $callback, $cache_key, $cache_time = 24 * HOUR_IN_SECONDS ) {
1011 882 $cache = get_site_transient( $cache_key );
@@ -1021,10 +892,10 @@
1021 892 return $cache;
1022 893 }
1023 894
1024 895 public static function is_sale_time(): bool {
1025 - $sale_start_time = gmmktime( 10, 0, 0, 6, 15, 2026 );
1026 - $sale_end_time = gmmktime( 3, 59, 0, 6, 17, 2026 );
896 + $sale_start_time = gmmktime( 13, 0, 0, 11, 26, 2024 );
897 + $sale_end_time = gmmktime( 9, 59, 0, 12, 4, 2024 );
1027 898
1028 899 $now_time = gmdate( 'U' );
1029 900
1030 901 return $now_time >= $sale_start_time && $now_time <= $sale_end_time;
@@ -1034,9 +905,9 @@
1034 905 if ( ! static::is_elementor_debug() ) {
1035 906 return;
1036 907 }
1037 908
1038 - throw new \Exception( esc_html( $message ) );
909 + throw new \Exception( $message );
1039 910 }
1040 911
1041 912 public static function has_invalid_post_permissions( $post ): bool {
1042 913 $is_image_attachment = 'attachment' === $post->post_type && strpos( $post->post_mime_type, 'image/' ) === 0;
@@ -1054,35 +925,6 @@
1054 925 $password_required = post_password_required( $post->ID )
1055 926 && ! current_user_can( 'edit_post', $post->ID );
1056 927
1057 928 return $is_private || $not_allowed || $password_required;
1058 - }
1059 -
1060 - public static function is_custom_kit_applied() {
1061 - return (bool) Plugin::$instance->kits_manager->get_previous_id();
1062 - }
1063 -
1064 - public static function decode_string( string $encoded_string, ?string $fallback = '' ) {
1065 - try {
1066 - return base64_decode( $encoded_string, true ) ?? $fallback;
1067 - } catch ( \Exception $e ) {
1068 - return $fallback;
1069 - }
1070 - }
1071 -
1072 - public static function encode_string( string $decoded_string ): string {
1073 - return base64_encode( $decoded_string );
1074 - }
1075 -
1076 - public static function html_to_plain_text( string $html ): string {
1077 - if ( empty( $html ) ) {
1078 - return '';
1079 - }
1080 -
1081 - $text = preg_replace( '#<br\s*/?\s*>#i', ' ', $html );
1082 - $text = preg_replace( '#</?[a-z][^>]*>#i', ' ', $text );
1083 - $text = html_entity_decode( $text, ENT_QUOTES, 'UTF-8' );
1084 - $text = str_replace( "\xE2\x80\x8B", '', $text );
1085 -
1086 - return trim( preg_replace( '/\s+/', ' ', $text ) );
1087 929 }
1088 930 }