| @@ -10,8 +10,9 @@ | ||
| 10 | 10 | if ( ! defined( 'ABSPATH' ) ) exit; // Exit if accessed directly |
| 11 | 11 | |
| 12 | 12 | global $post, $property; |
| 13 | 13 | |
| 14 | +// phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedVariableFound -- Template-local variable; the template is included through a helper/function scope, so PrefixAllGlobals misclassifies the file when checked standalone. | |
| 14 | 15 | $features = $property->get_features(); |
| 15 | 16 | |
| 16 | 17 | if ( !empty($features) ) |
| 17 | 18 | { |
| @@ -17,16 +18,17 @@ | ||
| 17 | 18 | { |
| 18 | 19 | ?> |
| 19 | 20 | <div class="features"> |
| 20 | 21 | |
| 21 | - <h4><?php _e( 'Property Features', 'propertyhive' ); ?></h4> | |
| 22 | + <h4><?php echo esc_html(__( 'Property Features', 'propertyhive' )); ?></h4> | |
| 22 | 23 | |
| 23 | 24 | <ul> |
| 24 | 25 | <?php |
| 26 | + // phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedVariableFound -- Template-local variable; the template is included through a helper/function scope, so PrefixAllGlobals misclassifies the file when checked standalone. | |
| 25 | 27 | foreach ($features as $feature) |
| 26 | 28 | { |
| 27 | 29 | ?> |
| 28 | - <li><?php echo $feature; ?></li> | |
| 30 | + <li><?php echo esc_html($feature); ?></li> | |
| 29 | 31 | <?php |
| 30 | 32 | } |
| 31 | 33 | ?> |
| 32 | 34 | </ul> |