| @@ -6,8 +6,12 @@ | ||
| 6 | 6 | * |
| 7 | 7 | * @package automattic/jetpack |
| 8 | 8 | */ |
| 9 | 9 | |
| 10 | +if ( ! defined( 'ABSPATH' ) ) { | |
| 11 | + exit( 0 ); | |
| 12 | +} | |
| 13 | + | |
| 10 | 14 | // phpcs:disable Universal.Files.SeparateFunctionsFromOO.Mixed -- TODO: Move classes to appropriately-named class files. |
| 11 | 15 | |
| 12 | 16 | /** |
| 13 | 17 | * Register the widget. |
| @@ -59,9 +63,9 @@ | ||
| 59 | 63 | * Displays the form for this widget on the Widgets page of the WP Admin area. |
| 60 | 64 | * |
| 61 | 65 | * @param array $instance Instance configuration. |
| 62 | 66 | * |
| 63 | - * @return void | |
| 67 | + * @return string|void | |
| 64 | 68 | */ |
| 65 | 69 | public function form( $instance ) { |
| 66 | 70 | $defaults = array( |
| 67 | 71 | 'title' => __( 'Upcoming Events', 'jetpack' ), |
| @@ -84,9 +88,9 @@ | ||
| 84 | 88 | <p> |
| 85 | 89 | <label for="<?php echo esc_attr( $this->get_field_id( 'count' ) ); ?>"><?php esc_html_e( 'Items to show:', 'jetpack' ); ?></label> |
| 86 | 90 | <select id="<?php echo esc_attr( $this->get_field_id( 'count' ) ); ?>" name="<?php echo esc_attr( $this->get_field_name( 'count' ) ); ?>"> |
| 87 | 91 | <?php for ( $i = 1; $i <= 10; $i++ ) { ?> |
| 88 | - <option <?php selected( $instance['count'], $i ); ?>><?php echo (int) $i; ?></option> | |
| 92 | + <option <?php selected( $instance['count'], $i ); ?>><?php echo esc_html( (string) $i ); ?></option> | |
| 89 | 93 | <?php } ?> |
| 90 | 94 | <option value="0" <?php selected( $instance['count'], 0 ); ?>><?php esc_html_e( 'All', 'jetpack' ); ?></option> |
| 91 | 95 | </select> |
| 92 | 96 | </p> |
| @@ -151,9 +155,9 @@ | ||
| 151 | 155 | <?php foreach ( $events as $event ) : ?> |
| 152 | 156 | <li> |
| 153 | 157 | <strong class="event-summary"> |
| 154 | 158 | <?php |
| 155 | - echo $ical->escape( stripslashes( $event['SUMMARY'] ) ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- this method is built to escape. | |
| 159 | + echo $ical->escape( stripslashes( $event['SUMMARY'] ?? '' ) ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- this method is built to escape. | |
| 156 | 160 | ?> |
| 157 | 161 | </strong> |
| 158 | 162 | <span class="event-when"><?php echo esc_html( $ical->formatted_date( $event ) ); ?></span> |
| 159 | 163 | <?php if ( ! empty( $event['LOCATION'] ) ) : ?> |