| @@ -13,9 +13,9 @@ | ||
| 13 | 13 | public function get_name() { |
| 14 | 14 | return 'poll-maker'; |
| 15 | 15 | } |
| 16 | 16 | public function get_title() { |
| 17 | - return __( 'Poll Maker', 'poll-maker' ); | |
| 17 | + return esc_html__( 'Poll Maker', 'poll-maker' ); | |
| 18 | 18 | } |
| 19 | 19 | public function get_icon() { |
| 20 | 20 | // Icon name from the Elementor font file, as per http://dtbaker.net/web-development/creating-your-own-custom-elementor-widgets/ |
| 21 | 21 | // return 'fas fa-poll ays_fa_poll'; |
| @@ -35,19 +35,19 @@ | ||
| 35 | 35 | |
| 36 | 36 | $this->add_control( |
| 37 | 37 | 'poll_title', |
| 38 | 38 | array( |
| 39 | - 'label' => __( 'Poll Title', 'poll-maker' ), | |
| 39 | + 'label' =>esc_html__( 'Poll Title', 'poll-maker' ), | |
| 40 | 40 | 'type' => Controls_Manager::TEXT, |
| 41 | 41 | 'default' => '', |
| 42 | - 'title' => __( 'Enter the poll title', 'poll-maker' ), | |
| 43 | - 'placeholder' => __( 'Enter the poll title', 'poll-maker' ), | |
| 42 | + 'title' =>esc_html__( 'Enter the poll title', 'poll-maker' ), | |
| 43 | + 'placeholder' =>esc_html__( 'Enter the poll title', 'poll-maker' ), | |
| 44 | 44 | ) |
| 45 | 45 | ); |
| 46 | 46 | $this->add_control( |
| 47 | 47 | 'poll_title_alignment', |
| 48 | 48 | array( |
| 49 | - 'label' => __( 'Title Alignment', 'poll-maker' ), | |
| 49 | + 'label' =>esc_html__( 'Title Alignment', 'poll-maker' ), | |
| 50 | 50 | 'type' => Controls_Manager::SELECT, |
| 51 | 51 | 'default' => 'left', |
| 52 | 52 | 'options' => array( |
| 53 | 53 | 'left' => 'Left', |
| @@ -58,9 +58,9 @@ | ||
| 58 | 58 | ); |
| 59 | 59 | $this->add_control( |
| 60 | 60 | 'poll_selector', |
| 61 | 61 | array( |
| 62 | - 'label' => __( 'Select Poll', 'poll-maker' ), | |
| 62 | + 'label' =>esc_html__( 'Select Poll', 'poll-maker' ), | |
| 63 | 63 | 'type' => Controls_Manager::SELECT, |
| 64 | 64 | 'default' => $this->get_default_poll(), |
| 65 | 65 | 'options' => $this->get_active_polls() |
| 66 | 66 | ) |
| @@ -69,10 +69,10 @@ | ||
| 69 | 69 | $this->end_controls_section(); |
| 70 | 70 | } |
| 71 | 71 | protected function render( $instance = array() ) { |
| 72 | 72 | $settings = $this->get_settings_for_display(); |
| 73 | - echo ( isset( $settings['poll_title'] ) && ! empty( $settings['poll_title'] ) ) ? "<h2 style='text-align: {$settings['poll_title_alignment']}'>{$settings['poll_title']}</h2>" : ""; | |
| 74 | - echo do_shortcode("[ays_poll id={$settings['poll_selector']}]"); | |
| 73 | + echo ( isset( $settings['poll_title'] ) && ! empty( $settings['poll_title'] ) ) ? "<h2 style='text-align: ". esc_attr( $settings['poll_title_alignment'] ) ."'>". esc_html($settings['poll_title']) ."</h2>" : ""; | |
| 74 | + echo do_shortcode("[ays_poll id=". esc_attr( $settings['poll_selector'] ) ."]"); | |
| 75 | 75 | } |
| 76 | 76 | |
| 77 | 77 | public function get_active_polls(){ |
| 78 | 78 | global $wpdb; |