PluginProbe
Elementor Website Builder – more than just a page builder / 3.28.0-dev2
Elementor Website Builder – more than just a page builder v3.28.0-dev2
4.3.1 4.3.0 4.3.0-beta3 4.3.0-beta2 4.3.0-beta1 4.2.4 4.2.3 4.2.2 4.2.1 4.2.0 4.1.5 4.2.0-beta2 4.2.0-dev2 4.2.0-beta1 4.1.4 4.1.3 4.1.2 4.1.1 4.1.0 4.1.0-beta3 4.1.0-dev3 4.0.9 4.1.0-beta2 4.1.0-dev2 4.0.8 All 454 releases
← All changes | includes/utils.php +25 -171 4.3.03.28.0-dev2 View file →
@@ -1,8 +1,7 @@
1 1 <?php
2 2 namespace Elementor;
3 3
4 -use Elementor\Core\Files\Fonts\Google_Font;
5 4 use Elementor\Core\Utils\Collection;
6 5
7 6 if ( ! defined( 'ABSPATH' ) ) {
8 7 exit; // Exit if accessed directly.
@@ -29,9 +28,8 @@
29 28 'a',
30 29 'article',
31 30 'aside',
32 31 'button',
33 - 'form',
34 32 'div',
35 33 'footer',
36 34 'h1',
37 35 'h2',
@@ -46,29 +44,8 @@
46 44 'section',
47 45 'span',
48 46 ];
49 47
50 - /**
51 - * Tags that must never be usable as an HTML wrapper tag, regardless of what
52 - * `elementor/allowed_html_wrapper_tags` filters return. These are the classic
53 - * script-execution / markup-injection vectors (XSS), so they're enforced as a
54 - * hard denylist rather than left to filter authors to avoid re-adding them.
55 - */
56 - const FORBIDDEN_HTML_WRAPPER_TAGS = [
57 - 'script',
58 - 'iframe',
59 - 'object',
60 - 'embed',
61 - 'style',
62 - 'link',
63 - 'meta',
64 - 'base',
65 - 'noscript',
66 - 'template',
67 - 'svg',
68 - 'math',
69 - ];
70 -
71 48 const EXTENDED_ALLOWED_HTML_TAGS = [
72 49 'iframe' => [
73 50 'iframe' => [
74 51 'allow' => true,
@@ -220,9 +197,9 @@
220 197 * @param string $from
221 198 * @param string $to
222 199 *
223 200 * @return string
224 - * @throws \Exception If URLs are missing or invalid URLs provided.
201 + * @throws \Exception Replace URL exception.
225 202 */
226 203 public static function replace_urls( $from, $to ) {
227 204 $from = trim( $from );
228 205 $to = trim( $to );
@@ -268,9 +245,8 @@
268 245 // Allow externals to replace-urls, when they have to.
269 246 $rows_affected += (int) apply_filters( 'elementor/tools/replace-urls', 0, $from, $to );
270 247
271 248 Plugin::$instance->files_manager->clear_cache();
272 - Google_Font::clear_cache();
273 249
274 250 return sprintf(
275 251 /* translators: %d: Number of rows. */
276 252 _n( '%d database row affected.', '%d database rows affected.', $rows_affected, 'elementor' ),
@@ -534,14 +510,14 @@
534 510 * @since 2.1.2
535 511 * @access public
536 512 * @static
537 513 */
538 - public static function array_inject( $base_array, $key, $insert ) {
539 - $length = array_search( $key, array_keys( $base_array ), true ) + 1;
514 + public static function array_inject( $array, $key, $insert ) {
515 + $length = array_search( $key, array_keys( $array ), true ) + 1;
540 516
541 - return array_slice( $base_array, 0, $length, true ) +
517 + return array_slice( $array, 0, $length, true ) +
542 518 $insert +
543 - array_slice( $base_array, $length, null, true );
519 + array_slice( $array, $length, null, true );
544 520 }
545 521
546 522 /**
547 523 * Render html attributes
@@ -658,34 +634,15 @@
658 634 public static function has_pro() {
659 635 return defined( 'ELEMENTOR_PRO_VERSION' );
660 636 }
661 637
662 - public static function is_license_active(): bool {
663 - return class_exists( '\ElementorPro\License\API' ) && \ElementorPro\License\API::is_license_active();
664 - }
665 -
666 - public static function is_pro_installed_and_not_active(): bool {
667 - if ( ! function_exists( 'get_plugins' ) ) {
668 - require_once ABSPATH . 'wp-admin/includes/plugin.php';
669 - }
670 -
671 - $file_path = self::get_elementor_pro_file_path();
672 - $installed_plugins = get_plugins();
673 -
674 - return isset( $installed_plugins[ $file_path ] );
675 - }
676 -
677 - private static function get_elementor_pro_file_path(): string {
678 - return 'elementor-pro/elementor-pro.php';
679 - }
680 -
681 638 /**
682 639 * Convert HTMLEntities to UTF-8 characters
683 640 *
684 - * @param string $html_string
641 + * @param string $string
685 642 * @return string
686 643 */
687 - public static function urlencode_html_entities( $html_string ) {
644 + public static function urlencode_html_entities( $string ) {
688 645 $entities_dictionary = [
689 646 '&#145;' => "'", // Opening single quote
690 647 '&#146;' => "'", // Closing single quote
691 648 '&#147;' => '"', // Closing double quote
@@ -698,11 +655,11 @@
698 655 '&#8222;' => '"', // Double low quote
699 656 ];
700 657
701 658 // Decode decimal entities
702 - $html_string = str_replace( array_keys( $entities_dictionary ), array_values( $entities_dictionary ), $html_string );
659 + $string = str_replace( array_keys( $entities_dictionary ), array_values( $entities_dictionary ), $string );
703 660
704 - return rawurlencode( html_entity_decode( $html_string, ENT_QUOTES | ENT_HTML5, 'UTF-8' ) );
661 + return rawurlencode( html_entity_decode( $string, ENT_QUOTES | ENT_HTML5, 'UTF-8' ) );
705 662 }
706 663
707 664 /**
708 665 * Parse attributes that come as a string of comma-delimited key|value pairs.
@@ -754,19 +711,13 @@
754 711 if ( $id === $element['id'] ) {
755 712 return $element;
756 713 }
757 714
758 - $inner_elements = apply_filters(
759 - 'elementor/utils/find_element_recursive/inner_elements',
760 - $element['elements'] ?? [],
761 - $element
762 - );
715 + if ( ! empty( $element['elements'] ) ) {
716 + $element = self::find_element_recursive( $element['elements'], $id );
763 717
764 - if ( ! empty( $inner_elements ) ) {
765 - $found = self::find_element_recursive( $inner_elements, $id );
766 -
767 - if ( $found ) {
768 - return $found;
718 + if ( $element ) {
719 + return $element;
769 720 }
770 721 }
771 722 }
772 723
@@ -796,45 +747,8 @@
796 747 }
797 748 }
798 749
799 750 /**
800 - * @var string[]|null
801 - */
802 - private static $resolved_allowed_html_wrapper_tags;
803 -
804 - /**
805 - * Get allowed HTML wrapper tags.
806 - *
807 - * @since 4.4.0
808 - *
809 - * @return string[]
810 - */
811 - public static function get_allowed_html_wrapper_tags(): array {
812 - if ( null !== self::$resolved_allowed_html_wrapper_tags ) {
813 - return self::$resolved_allowed_html_wrapper_tags;
814 - }
815 -
816 - /**
817 - * Allowed HTML wrapper tags.
818 - *
819 - * Filters the list of allowed HTML tag names used by `validate_html_tag()`.
820 - *
821 - * Note: tags in `Utils::FORBIDDEN_HTML_WRAPPER_TAGS` (e.g. `script`, `iframe`,
822 - * `object`) are always stripped after this filter runs and cannot be re-added,
823 - * to prevent XSS via a wrapper tag that executes script or embeds external content.
824 - *
825 - * @since 4.4.0
826 - *
827 - * @param string[] $tags A list of lowercase HTML tag name strings.
828 - */
829 - $tags = apply_filters( 'elementor/allowed_html_wrapper_tags', self::ALLOWED_HTML_WRAPPER_TAGS );
830 -
831 - self::$resolved_allowed_html_wrapper_tags = self::normalize_allowed_html_wrapper_tags( $tags );
832 -
833 - return self::$resolved_allowed_html_wrapper_tags;
834 - }
835 -
836 - /**
837 751 * Validate an HTML tag against a safe allowed list.
838 752 *
839 753 * @param string $tag
840 754 *
@@ -840,37 +754,12 @@
840 754 *
841 755 * @return string
842 756 */
843 757 public static function validate_html_tag( $tag ) {
844 - return $tag && in_array( strtolower( $tag ), self::get_allowed_html_wrapper_tags(), true ) ? $tag : 'div';
758 + return $tag && in_array( strtolower( $tag ), self::ALLOWED_HTML_WRAPPER_TAGS ) ? $tag : 'div';
845 759 }
846 760
847 761 /**
848 - * @param array $tags
849 - *
850 - * @return string[]
851 - */
852 - private static function normalize_allowed_html_wrapper_tags( array $tags ): array {
853 - $normalized_tags = [];
854 -
855 - foreach ( $tags as $tag ) {
856 - if ( ! is_string( $tag ) ) {
857 - continue;
858 - }
859 -
860 - $tag = strtolower( $tag );
861 -
862 - if ( in_array( $tag, self::FORBIDDEN_HTML_WRAPPER_TAGS, true ) ) {
863 - continue;
864 - }
865 -
866 - $normalized_tags[] = $tag;
867 - }
868 -
869 - return array_values( array_unique( $normalized_tags ) );
870 - }
871 -
872 - /**
873 762 * Safe print a validated HTML tag.
874 763 *
875 764 * @param string $tag
876 765 */
@@ -881,10 +770,10 @@
881 770
882 771 /**
883 772 * Print internal content (not user input) without escaping.
884 773 */
885 - public static function print_unescaped_internal_string( $internal_string ) {
886 - echo $internal_string; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
774 + public static function print_unescaped_internal_string( $string ) {
775 + echo $string; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
887 776 }
888 777
889 778 /**
890 779 * Get recently edited posts query.
@@ -909,9 +798,9 @@
909 798
910 799 return new \WP_Query( $args );
911 800 }
912 801
913 - public static function print_wp_kses_extended( $text, array $tags ) {
802 + public static function print_wp_kses_extended( $string, array $tags ) {
914 803 $allowed_html = wp_kses_allowed_html( 'post' );
915 804
916 805 foreach ( $tags as $tag ) {
917 806 if ( isset( self::EXTENDED_ALLOWED_HTML_TAGS[ $tag ] ) ) {
@@ -919,17 +808,11 @@
919 808 $allowed_html = array_replace_recursive( $allowed_html, $extended_tags );
920 809 }
921 810 }
922 811
923 - echo wp_kses( $text, $allowed_html );
812 + echo wp_kses( $string, $allowed_html );
924 813 }
925 814
926 - public static function kses_post_deep( $data ) {
927 - return map_deep( $data, function ( $value ) {
928 - return is_string( $value ) ? wp_kses_post( $value ) : $value;
929 - } );
930 - }
931 -
932 815 public static function is_elementor_path( $path ) {
933 816 $path = wp_normalize_path( $path );
934 817
935 818 /**
@@ -991,21 +874,21 @@
991 874
992 875 /**
993 876 * Return specific object property value if exist from array of keys.
994 877 *
995 - * @param array $base_array
878 + * @param array $array
996 879 * @param array $keys
997 880 * @return mixed|null
998 881 */
999 - public static function get_array_value_by_keys( $base_array, $keys ) {
882 + public static function get_array_value_by_keys( $array, $keys ) {
1000 883 $keys = (array) $keys;
1001 884 foreach ( $keys as $key ) {
1002 - if ( ! isset( $base_array[ $key ] ) ) {
885 + if ( ! isset( $array[ $key ] ) ) {
1003 886 return null;
1004 887 }
1005 - $base_array = $base_array[ $key ];
888 + $array = $array[ $key ];
1006 889 }
1007 - return $base_array;
890 + return $array;
1008 891 }
1009 892
1010 893 public static function get_cached_callback( $callback, $cache_key, $cache_time = 24 * HOUR_IN_SECONDS ) {
1011 894 $cache = get_site_transient( $cache_key );
@@ -1021,10 +904,10 @@
1021 904 return $cache;
1022 905 }
1023 906
1024 907 public static function is_sale_time(): bool {
1025 - $sale_start_time = gmmktime( 10, 0, 0, 6, 15, 2026 );
1026 - $sale_end_time = gmmktime( 3, 59, 0, 6, 17, 2026 );
908 + $sale_start_time = gmmktime( 13, 0, 0, 11, 26, 2024 );
909 + $sale_end_time = gmmktime( 9, 59, 0, 12, 4, 2024 );
1027 910
1028 911 $now_time = gmdate( 'U' );
1029 912
1030 913 return $now_time >= $sale_start_time && $now_time <= $sale_end_time;
@@ -1054,35 +937,6 @@
1054 937 $password_required = post_password_required( $post->ID )
1055 938 && ! current_user_can( 'edit_post', $post->ID );
1056 939
1057 940 return $is_private || $not_allowed || $password_required;
1058 - }
1059 -
1060 - public static function is_custom_kit_applied() {
1061 - return (bool) Plugin::$instance->kits_manager->get_previous_id();
1062 - }
1063 -
1064 - public static function decode_string( string $encoded_string, ?string $fallback = '' ) {
1065 - try {
1066 - return base64_decode( $encoded_string, true ) ?? $fallback;
1067 - } catch ( \Exception $e ) {
1068 - return $fallback;
1069 - }
1070 - }
1071 -
1072 - public static function encode_string( string $decoded_string ): string {
1073 - return base64_encode( $decoded_string );
1074 - }
1075 -
1076 - public static function html_to_plain_text( string $html ): string {
1077 - if ( empty( $html ) ) {
1078 - return '';
1079 - }
1080 -
1081 - $text = preg_replace( '#<br\s*/?\s*>#i', ' ', $html );
1082 - $text = preg_replace( '#</?[a-z][^>]*>#i', ' ', $text );
1083 - $text = html_entity_decode( $text, ENT_QUOTES, 'UTF-8' );
1084 - $text = str_replace( "\xE2\x80\x8B", '', $text );
1085 -
1086 - return trim( preg_replace( '/\s+/', ' ', $text ) );
1087 941 }
1088 942 }