PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3
Jetpack – WP Security, Backup, Speed, & Growth v16.3
16.3 16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 All 508 releases
← All changes | class.jetpack-gutenberg.php +9 -0 16.3-a.5 → 16.3 View file →
@@ -941,8 +941,9 @@
941 941 'subscribe_placements' => current_user_can( 'manage_options' ) ? array(
942 942 'sm_enabled' => (bool) get_option( 'sm_enabled', false ),
943 943 'jetpack_subscribe_overlay_enabled' => (bool) get_option( 'jetpack_subscribe_overlay_enabled', false ),
944 944 'jetpack_subscribe_floating_button_enabled' => (bool) get_option( 'jetpack_subscribe_floating_button_enabled', false ),
945 + 'wpcom_action_bar' => ( new Host() )->is_wpcom_simple() && ! get_option( 'wpcom_hide_action_bar' ),
945 946 ) : null,
946 947 // this is the equivalent of JP initial state siteData.showMyJetpack (class-jetpack-redux-state-helper)
947 948 // used to determine if we can link to My Jetpack from the block editor
948 949 'is_my_jetpack_available' => My_Jetpack_Initializer::should_initialize(),
@@ -1580,8 +1581,16 @@
1580 1581 $url_components = wp_parse_url( $url );
1581 1582
1582 1583 // Bail early if we cannot find a host.
1583 1584 if ( empty( $url_components['host'] ) ) {
1585 + return false;
1586 + }
1587 +
1588 + // Only http and https URLs are valid.
1589 + if (
1590 + isset( $url_components['scheme'] )
1591 + && ! in_array( strtolower( $url_components['scheme'] ), array( 'http', 'https' ), true )
1592 + ) {
1584 1593 return false;
1585 1594 }
1586 1595
1587 1596 // Normalize URL.