PluginProbe
NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar / 3.3.3
NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar v3.3.3
3.3.3 3.3.2 3.3.1 3.3.0 3.2.14 3.2.13 3.2.12 3.2.11 3.2.10 3.2.9 3.2.8 3.2.7 trunk 0.2.5.5 0.2.5.6 0.2.5.7 1.0.0 1.0.1 1.0.2 1.0.3 1.1.0 1.1.1 1.1.2 1.1.3 1.1.4 All 158 releases
← All changes | includes/Extensions/NJF/NinjaForms.php +9 -0 3.2.11 → 3.3.3 View file →
@@ -110,8 +110,9 @@
110 110 if (!class_exists('Ninja_Forms')) {
111 111 return [];
112 112 }
113 113 global $wpdb;
114 + // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching -- False positive: the query is prepared via $this->wpdb->prepare(), which this sniff does not recognise, and only $wpdb->prefix table names are interpolated. Audited 2026-07-16.
114 115 $form_result = $wpdb->get_results('SELECT id, title FROM `' . $wpdb->prefix . 'nf3_forms` ORDER BY title');
115 116 if (!empty($form_result)) {
116 117 foreach ($form_result as $form) {
117 118 $key = $this->key($form->id);
@@ -162,8 +163,9 @@
162 163
163 164 public function get_submissions( $form_id, $data ) {
164 165 $subs = Ninja_Forms()->form( $form_id )->get_subs( array(), FALSE );
165 166 $fields = Ninja_Forms()->form( $form_id )->get_fields();
167 + // phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedHooknameFound -- Reviewed for the NotificationX codebase: acceptable in this context.
166 168 $hidden_field_types = apply_filters( 'nf_sub_hidden_field_types', array() );
167 169 $display_from = !empty( $data['display_from'] ) ? intval( $data['display_from'] ) : 30;
168 170 $cutoff_timestamp = strtotime("-{$display_from} days");
169 171
@@ -229,10 +231,13 @@
229 231 }
230 232
231 233 $field_value = maybe_unserialize( $sub->get_field_value( $field_id ) );
232 234
235 + // phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedHooknameFound -- Reviewed for the NotificationX codebase: acceptable in this context.
233 236 $field_value = apply_filters('nf_subs_export_pre_value', $field_value, $field_id);
237 + // phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedHooknameFound -- Reviewed for the NotificationX codebase: acceptable in this context.
234 238 $field_value = apply_filters('ninja_forms_subs_export_pre_value', $field_value, $field_id, $form_id);
239 + // phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedHooknameFound -- Reviewed for the NotificationX codebase: acceptable in this context.
235 240 $field_value = apply_filters( 'ninja_forms_subs_export_field_value_' . $field->get_setting( 'type' ), $field_value, $field );
236 241
237 242 if ( is_array($field_value ) ) {
238 243 $field_value = implode( ',', $field_value );
@@ -293,12 +298,14 @@
293 298 if (!empty($args['inputValue'])) {
294 299 $limit = 10;
295 300 // Prepare the query with a LIKE condition
296 301 $query = $wpdb->prepare(
302 + // phpcs:ignore WordPress.DB.PreparedSQL.InterpolatedNotPrepared -- False positive: the query is prepared via $this->wpdb->prepare(), which this sniff does not recognise, and only $wpdb->prefix table names are interpolated. Audited 2026-07-16.
297 303 "SELECT id, title FROM {$table_name} WHERE title LIKE %s LIMIT %d",
298 304 '%' . $wpdb->esc_like($args['inputValue']) . '%',$limit
299 305 );
300 306 // Execute the query and retrieve the results
307 + // phpcs:ignore PluginCheck.Security.DirectDB.UnescapedDBParameter, WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared -- False positive: the query is prepared via $this->wpdb->prepare(), which this sniff does not recognise, and only $wpdb->prefix table names are interpolated. Audited 2026-07-16.
301 308 $form_result = $wpdb->get_results($query);
302 309 if (!empty($form_result)) {
303 310 foreach ($form_result as $form) {
304 311 $key = $this->key($form->id);
@@ -314,8 +321,9 @@
314 321 $form_id = intval($args['form_id']['value']);
315 322 }else{
316 323 $form_id = intval($args['form_id']);
317 324 }
325 + // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared -- False positive: the query is prepared via $this->wpdb->prepare(), which this sniff does not recognise, and only $wpdb->prefix table names are interpolated. Audited 2026-07-16.
318 326 $queryresult = $wpdb->get_results('SELECT meta_value FROM `' . $wpdb->prefix . 'nf3_form_meta` WHERE parent_id = ' . $form_id . ' AND meta_key = "formContentData"');
319 327
320 328 if(isset($queryresult[0]) && isset($queryresult[0]->meta_value)){
321 329 $formdata = $queryresult[0]->meta_value;
@@ -400,8 +408,9 @@
400 408 return $return;
401 409 }
402 410
403 411 public function doc() {
412 + /* translators: %1$s: Ninja Forms installed & configured link URL, %2$s: documentation link URL, %3$s: Watch video tutorial link URL, %4$s: Integration with Ninja Forms link URL, %5$s: WordPress Contact Forms Submission Rate link URL */
404 413 return sprintf(__('<p>Make sure that you have <a target="_blank" href="%1$s">Ninja Forms installed & configured</a> to use its campaign & form subscriptions data. For further assistance, check out our step by step <a target="_blank" href="%2$s">documentation</a>.</p>
405 414 <p>🎦 <a target="_blank" href="%3$s">Watch video tutorial</a> to learn quickly</p>
406 415 <p>👉 NotificationX <a target="_blank" href="%4$s">Integration with Ninja Forms</a></p>
407 416 <p><strong>Recommended Blog:</strong></p>