| @@ -26,11 +26,12 @@ | ||
| 26 | 26 | public function get_header_snippet() |
| 27 | 27 | { |
| 28 | 28 | $code_snippet_options = get_option(Metasync::option_name)['codesnippets'] ?? ''; |
| 29 | 29 | $header_snippet_option = $code_snippet_options['header_snippet'] ?? ''; |
| 30 | + // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- raw header/footer snippet feature: customers paste arbitrary analytics/GTM markup and it must render verbatim | |
| 30 | 31 | echo $header_snippet_option; |
| 31 | - echo get_post_meta(get_the_ID())['custom_post_header'][0] ?? ''; | |
| 32 | - echo get_post_meta(get_the_ID())['searchatlas_embed_top'][0] ?? ''; | |
| 32 | + echo get_post_meta(get_the_ID())['custom_post_header'][0] ?? ''; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- raw per-post header snippet feature: customers paste arbitrary analytics/GTM markup and it must render verbatim | |
| 33 | + echo get_post_meta(get_the_ID())['searchatlas_embed_top'][0] ?? ''; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- raw per-post header snippet feature: customers paste arbitrary analytics/GTM markup and it must render verbatim | |
| 33 | 34 | |
| 34 | 35 | } |
| 35 | 36 | |
| 36 | 37 | /** |
| @@ -40,9 +41,10 @@ | ||
| 40 | 41 | public function get_footer_snippet() |
| 41 | 42 | { |
| 42 | 43 | $code_snippet_options = get_option(Metasync::option_name)['codesnippets'] ?? ''; |
| 43 | 44 | $footer_snippet_option = $code_snippet_options['footer_snippet'] ?? ''; |
| 45 | + // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- raw header/footer snippet feature: customers paste arbitrary analytics/GTM markup and it must render verbatim | |
| 44 | 46 | echo $footer_snippet_option; |
| 45 | - echo get_post_meta(get_the_ID())['custom_post_footer'][0] ?? ''; | |
| 46 | - echo get_post_meta(get_the_ID())['searchatlas_embed_bottom'][0] ?? ''; | |
| 47 | + echo get_post_meta(get_the_ID())['custom_post_footer'][0] ?? ''; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- raw per-post footer snippet feature: customers paste arbitrary analytics/GTM markup and it must render verbatim | |
| 48 | + echo get_post_meta(get_the_ID())['searchatlas_embed_bottom'][0] ?? ''; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- raw per-post footer snippet feature: customers paste arbitrary analytics/GTM markup and it must render verbatim | |
| 47 | 49 | } |
| 48 | 50 | } |