PluginProbe
Super RSS Reader – Add attractive RSS Feed Widget / 4.7
Super RSS Reader – Add attractive RSS Feed Widget v4.7
trunk 0.8 2.0 2.1 2.2 2.3 2.4 2.5 2.6 2.7 2.8 3.0 3.1 3.2 4.0 4.0.1 4.1 4.2 4.3 4.4 4.4.1 4.5 4.6 4.7 4.8 All 33 releases
← All changes | includes/feed.php +142 -57 4.0.14.7 View file →
@@ -17,27 +17,33 @@
17 17 }
18 18
19 19 public function html(){
20 20
21 - $urls = stripslashes( trim( $this->options['urls'] ) );
22 - $tab_titles = stripslashes( $this->options['tab_titles'] );
21 + $urls = trim( $this->options['urls'] );
22 + $tab_titles = $this->options['tab_titles'];
23 23 $count = intval( $this->options['count'] );
24 24
25 25 $show_date = intval( $this->options['show_date'] );
26 26 $show_desc = intval( $this->options['show_desc'] );
27 27 $show_author = intval( $this->options['show_author'] );
28 - $show_thumb = stripslashes( $this->options['show_thumb'] );
28 + $show_thumb = intval( $this->options['show_thumb'] );
29 29 $open_newtab = intval( $this->options['open_newtab'] );
30 30 $add_nofollow = intval( $this->options['add_nofollow'] );
31 31 $strip_desc = intval( $this->options['strip_desc'] );
32 32 $strip_title = intval( $this->options['strip_title'] );
33 - $read_more = htmlspecialchars( $this->options['read_more'] );
33 + $date_format = $this->options['date_format'];
34 + $date_timezone = $this->options['date_timezone'];
35 + $order_by = $this->options['order_by'];
36 + $read_more = $this->options['read_more'];
34 37 $rich_desc = intval( $this->options['rich_desc'] );
35 - $thumbnail_position = htmlspecialchars( $this->options['thumbnail_position'] );
36 - $thumbnail_size = htmlspecialchars( $this->options['thumbnail_size'] );
38 + $desc_type = $this->options['desc_type'];
39 + $thumbnail_position = $this->options['thumbnail_position'];
40 + $thumbnail_size = $this->options['thumbnail_size'];
41 + $thumbnail_default = $this->options['thumbnail_default'];
42 + $no_feed_text = $this->options['no_feed_text'];
37 43
38 - $color_theme = stripslashes( $this->options['color_style'] );
39 - $display_type = stripslashes( $this->options['display_type'] );
44 + $color_theme = $this->options['color_style'];
45 + $display_type = $this->options['display_type'];
40 46 $visible_items = intval( $this->options['visible_items'] );
41 47 $ticker_speed = intval( $this->options['ticker_speed'] ) * 1000;
42 48
43 49 if( empty( $urls ) ){
@@ -52,8 +58,9 @@
52 58 $url_count = count( $urls );
53 59
54 60 $feeds = array();
55 61 $html = '';
62 + $no_feed_html = '<div>' . wp_kses_post( $no_feed_text ) . '</div>';
56 63
57 64 $classes = array( 'srr-wrap', 'srr-style-' . $color_theme );
58 65 if( $display_type == 'vertical_ticker' ) array_push( $classes, 'srr-vticker' );
59 66 $class = implode( ' ', $classes );
@@ -60,14 +67,20 @@
60 67
61 68 // Fetch the feed
62 69 for( $i=0; $i < $url_count; $i++ ){
63 70 $feed_url = trim( $urls[$i] );
71 +
72 + // Skip if the RSS feed URL is same as the site URL
73 + if ( in_array( untrailingslashit( $feed_url ), array( site_url(), home_url() ), true ) ) {
74 + continue;
75 + }
76 +
64 77 $feed = fetch_feed( $feed_url );
65 78
66 79 if( is_wp_error( $feed ) ){
67 - $feed_title = 'Error';
80 + $feed_title = __( 'Error' );
68 81 }else{
69 - $feed_title = ( isset( $tab_titles[$i] ) && !empty( $tab_titles[$i] ) ) ? $tab_titles[$i] : esc_attr( strip_tags( $feed->get_title() ) );
82 + $feed_title = ( isset( $tab_titles[$i] ) && !empty( $tab_titles[$i] ) ) ? $tab_titles[$i] : strip_tags( $feed->get_title() );
70 83 }
71 84
72 85 $feeds[ $feed_url ] = array(
73 86 'id' => rand( 100, 999 ),
@@ -77,17 +90,13 @@
77 90 }
78 91
79 92 // Generate tabs
80 93 if( $url_count > 1 ){
81 - $html .= '<ul class="srr-tab-wrap srr-tab-style-' . $color_theme . ' srr-clearfix">';
94 + $html .= '<ul class="srr-tab-wrap srr-tab-style-' . esc_attr( $color_theme ) . ' srr-clearfix">';
82 95 foreach( $feeds as $url => $data ){
83 96 $id = $data[ 'id' ];
84 97 $feed = $data[ 'feed' ];
85 - if( is_wp_error( $feed ) ){
86 - $html .= '<li data-tab="srr-tab-' . $id . '">Error</li>';
87 - }else{
88 - $html .= '<li data-tab="srr-tab-' . $id . '">' . $data[ 'title' ] . '</li>';
89 - }
98 + $html .= '<li data-tab="srr-tab-' . esc_attr( $id ) . '">' . wp_kses_post( $data[ 'title' ] ) . '</li>';
90 99 }
91 100 $html .= '</ul>';
92 101 }
93 102
@@ -98,28 +107,35 @@
98 107 $feed = $data[ 'feed' ];
99 108
100 109 // Check for feed errors
101 110 if ( is_wp_error( $feed ) ){
102 - $html .= '<div class="srr-wrap srr-style-' . $color_theme .'" data-id="srr-tab-' . $id . '"><p>RSS Error: ' . $feed->get_error_message() . '</p></div>';
111 + $html .= '<div class="srr-wrap srr-style-' . esc_attr( $color_theme ) .'" data-id="srr-tab-' . esc_attr( $id ) . '"><p>RSS Error: ' . wp_kses_post( $feed->get_error_message() ) . '</p></div>';
103 112 continue;
104 113 }
105 114
106 115 if( method_exists( $feed, 'enable_order_by_date' ) ){
107 - $feed->enable_order_by_date( false );
116 + if( in_array( $order_by, array( 'date', 'date_reverse' ) ) ){
117 + $feed->enable_order_by_date( true );
118 + }else{
119 + $feed->enable_order_by_date( false );
120 + }
108 121 }
109 122
110 - $max_items = $feed->get_item_quantity( $count );
111 - $feed_items = $feed->get_items( 0, $max_items );
112 -
113 123 // Outer wrap start
114 - $html .= '<div class="' . $class . '" data-visible="' . $visible_items . '" data-speed="' . $ticker_speed . '" data-id="srr-tab-' . $id . '">';
124 + $html .= '<div class="' . esc_attr( $class ) . '" data-visible="' . esc_attr( $visible_items ) . '" data-speed="' . esc_attr( $ticker_speed ) . '" data-id="srr-tab-' . esc_attr( $id ) . '">';
115 125 $html .= '<div>';
116 126
127 + $max_items = $feed->get_item_quantity();
128 +
117 129 // Check feed items
118 130 if ( $max_items == 0 ){
119 - $html .= '<div>' . __( 'No items', 'super-rss-reader' ) . '</div>';
131 + $html .= $no_feed_html;
120 132 }else{
133 +
134 + $feed_items = $feed->get_items();
135 + $feed_items = $this->process_items( $feed_items, $count, $order_by );
121 136 $j=1;
137 +
122 138 // Loop through each feed item
123 139 foreach( $feed_items as $item ){
124 140
125 141 // Link
@@ -124,12 +140,12 @@
124 140
125 141 // Link
126 142 $link = $item->get_link();
127 143 while ( stristr( $link, 'http' ) != $link ){ $link = substr( $link, 1 ); }
128 - $link = esc_url( strip_tags($link) );
144 + $link = strip_tags($link);
129 145
130 146 // Title
131 - $title = esc_attr( strip_tags( $item->get_title() ) );
147 + $title = strip_tags( $item->get_title() );
132 148 $title_full = $title;
133 149
134 150 if ( empty( $title ) ){
135 151 $title = __( 'No Title', 'super-rss-reader' );
@@ -144,16 +160,33 @@
144 160
145 161 // Add no follow attribute
146 162 $no_follow = $add_nofollow ? ' rel="nofollow noopener noreferrer"' : '';
147 163
164 + if( empty( $link ) ){
165 + $link = '#';
166 + $new_tab = '';
167 + }
168 +
148 169 // Date
149 - $date = $item->get_date( 'j F Y' );
150 - $date_full = esc_attr( $item->get_date() );
170 + $date = '';
171 + $date_full = strip_tags( $item->get_date() );
151 172
173 + if( strtolower( $date_format ) == 'relative' ){
174 + $item_date = $item->get_date( 'U' );
175 + if( $item_date ){
176 + $date = human_time_diff( $item_date, current_time( 'U' ) ) . ' ' . __( 'ago' );
177 + }else{
178 + $date = __( 'Today' );
179 + }
180 + }else{
181 + $date = SRR_Utilities::date_i18n( $date_format, $item->get_date( 'U' ), $date_timezone );
182 + }
183 +
152 184 // Thumbnail
153 185 $thumb = '';
154 186 if ( $show_thumb == 1 ){
155 - $thumb_url = $this->get_thumbnail_url( $item );
187 + $thumb_url = $this->get_thumbnail_url( $item, $thumbnail_default );
188 + $thumb_url = apply_filters( 'srr_mod_thumbnail_url', $thumb_url, $item, $feed, $thumbnail_default );
156 189 if( !empty( $thumb_url ) ){
157 190 $thumb_styles = array(
158 191 'width' => $thumbnail_size,
159 192 'height' => $thumbnail_size
@@ -161,9 +194,9 @@
161 194 $thumb_style = '';
162 195 foreach( $thumb_styles as $prop => $val ){
163 196 $thumb_style .= "$prop:$val;";
164 197 }
165 - $thumb = '<a href="' . $link . '" class="srr-thumb srr-thumb-' . $thumbnail_position . '" style="' . $thumb_style . '" ' . $new_tab . $no_follow . '><img src="' . $thumb_url . '" alt="' . $title_full . '" align="left" /></a>';
198 + $thumb = '<a href="' . esc_url( $link ) . '" class="srr-thumb srr-thumb-' . esc_attr( $thumbnail_position ) . '" style="' . esc_attr( $thumb_style ) . '" ' . $new_tab . $no_follow . '><img src="' . esc_url( $thumb_url ) . '" alt="' . esc_attr( $title_full ) . '" align="left"' . ( wp_lazy_loading_enabled( 'img', 'srr-thumbnail' ) ? ' loading="lazy"' : '' ) . ' /></a>';
166 199 }
167 200 }
168 201
169 202 // Description
@@ -168,74 +201,103 @@
168 201
169 202 // Description
170 203 $desc = '';
171 204 if( $show_desc ){
205 + $desc_content = ( $desc_type == 'summary' ) ? $item->get_description() : $item->get_content();
172 206 if( $rich_desc ){
173 - $desc = strip_tags( $item->get_description(), '<p><a><img><em><strong><font><strike><s><u><i>' );
207 + $desc = wp_kses_post( strip_tags( $desc_content, '<p><a><img><em><strong><font><strike><s><u><i><br>' ) );
174 208 }else{
209 + $desc = str_replace( array( "\n", "\r" ), ' ', strip_tags( @html_entity_decode( $desc_content, ENT_QUOTES, get_option('blog_charset') ) ) );
175 210
176 - $desc = str_replace( array( "\n", "\r" ), ' ', esc_attr( strip_tags( @html_entity_decode( $item->get_description(), ENT_QUOTES, get_option('blog_charset') ) ) ) );
177 - $read_more_link = '';
178 -
179 211 if( $strip_desc != 0 ){
180 212 $desc = wp_trim_words( $desc, $strip_desc );
181 - $read_more_link = !empty( $read_more ) ? ' <a href="' . $link . '" title="' . __( 'Read more', 'super-rss-reader' ) . '"' . $new_tab . $no_follow . ' class="srr-read-more">' . $read_more . '</a>' : '';
182 -
183 213 if ( '[...]' == substr( $desc, -5 ) ){
184 214 $desc = substr( $desc, 0, -5 );
185 215 }elseif ( '[&hellip;]' != substr( $desc, -10 ) ){
186 216 $desc .= '';
187 217 }
218 + }
188 219
189 - $desc = esc_html( $desc );
220 + $desc = trim( esc_html( $desc ) );
221 + if( !empty( $desc ) ){
222 + $read_more_link = !empty( $read_more ) ? ' <a href="' . esc_url( $link ) . '" title="' . esc_attr__( 'Read more', 'super-rss-reader' ) . '"' . $new_tab . $no_follow . ' class="srr-read-more">' . esc_html( $read_more ) . '</a>' : '';
223 + $desc = $desc . $read_more_link;
190 224 }
191 225
192 - $desc = $desc . $read_more_link;
193 -
194 226 }
195 227 }
196 228
197 229 // Author
198 - $author = $item->get_author();
199 - if ( is_object( $author ) ) {
200 - $author = $author->get_name();
201 - $author = esc_html( strip_tags( $author ) );
230 + $author = '';
231 + if( $show_author ){
232 + $author = $item->get_author();
233 + if ( is_object( $author ) ) {
234 + $author = strip_tags( $author->get_name() );
235 + }
202 236 }
203 237
204 - // Display the feed items
205 - $html .= '<div class="srr-item ' . ( ( $j%2 == 0 ) ? 'srr-stripe' : '') . '">';
206 - $html .= '<div class="srr-clearfix">';
238 + $t_title = '';
239 + $t_meta = '';
240 + $t_thumb = '';
241 + $t_desc = '';
207 242
208 - $html .= '<div class="srr-title"><a href="' . $link . '"' . $new_tab . $no_follow . ' title="' . $title_full . '">' . $title . '</a></div>';
243 + $t_title .= '<div class="srr-title"><a href="' . esc_url( $link ) . '"' . $new_tab . $no_follow . ' title="' . esc_attr( $title_full ) . '">' . esc_html( $title ) . '</a></div>';
209 244
210 245 // Metadata
211 246 if( $show_date || $show_author ){
212 - $html .= '<div class="srr-meta">';
247 + $t_meta .= '<div class="srr-meta">';
213 248 if( $show_date && !empty( $date ) ){
214 - $html .= '<time class="srr-date" title="' . $date_full . '">' . $date . '</time>';
249 + $t_meta .= '<time class="srr-date" title="' . esc_attr( $date_full ) . ' UTC">' . esc_html( $date ) . '</time>';
215 250 }
216 251
217 252 if( $show_author && !empty( $author ) ){
218 - $html .= ' - <cite class="srr-author">' . $author . '</cite>';
253 + $t_meta .= ' - <cite class="srr-author">' . esc_html( $author ) . '</cite>';
219 254 }
220 - $html .= '</div>'; // End meta
255 + $t_meta .= '</div>'; // End meta
221 256 }
222 257
223 258 if ( $show_thumb ){
224 - $html .= $thumb;
259 + $t_thumb .= $thumb;
225 260 }
226 261
227 - if( $show_desc ){
228 - $html .= '<div class="srr-summary srr-clearfix">';
229 - $html .= $rich_desc ? $desc : ( '<p>' . $desc . '</p>' );
230 - $html .= '</div>'; // End summary
262 + if( $show_desc && !empty( $desc ) ){
263 + $t_desc .= '<div class="srr-summary srr-clearfix">';
264 + $t_desc .= $rich_desc ? $desc : ( '<p>' . $desc . '</p>' );
265 + $t_desc .= '</div>'; // End summary
231 266 }
232 267
268 + $f_data = apply_filters( 'srr_mod_item_html', array(
269 + 'title' => $t_title,
270 + 'meta' => $t_meta,
271 + 'thumbnail' => $t_thumb,
272 + 'description' => $t_desc,
273 + 'before' => '',
274 + 'after' => ''
275 + ), $url, $item );
276 +
277 + $f_title = !isset( $f_data[ 'title' ] ) ? '' : $f_data[ 'title' ];
278 + $f_meta = !isset( $f_data[ 'meta' ] ) ? '' : $f_data[ 'meta' ];
279 + $f_thumb = !isset( $f_data[ 'thumbnail' ] ) ? '' : $f_data[ 'thumbnail' ];
280 + $f_desc = !isset( $f_data[ 'description' ] ) ? '' : $f_data[ 'description' ];
281 + $f_before = !isset( $f_data[ 'before' ] ) ? '' : $f_data[ 'before' ];
282 + $f_after = !isset( $f_data[ 'after' ] ) ? '' : $f_data[ 'after' ];
283 +
284 + // Display the feed items
285 + $html .= '<div class="srr-item ' . ( ( $j%2 == 0 ) ? 'srr-stripe' : '') . '">';
286 + $html .= '<div class="srr-clearfix">';
287 + $html .= $f_before;
288 + $html .= $f_title . $f_meta . $f_thumb . $f_desc;
289 + $html .= $f_after;
233 290 $html .= '</div>'; // End item inner clearfix
234 291 $html .= '</div>'; // End feed item
235 292
236 293 $j++;
237 294 }
295 +
296 + if( $j == 1 ){
297 + $html .= $no_feed_html;
298 + }
299 +
238 300 }
239 301
240 302 // Outer wrap end
241 303 $html .= '</div></div>' ;
@@ -252,10 +314,33 @@
252 314 return $html;
253 315
254 316 }
255 317
256 - function get_thumbnail_url( $item ){
318 + function process_items( $items, $count, $order_by ){
257 319
320 + if( count( $items ) == 0 ){
321 + return $items;
322 + }
323 +
324 + // For shuffle order - Shuffle first and then slice as per count
325 + if( $order_by == 'random' ){
326 + shuffle( $items );
327 + return array_slice( $items, 0, $count );
328 + }
329 +
330 + // For date based order - slice first and then order
331 + $items = array_slice( $items, 0, $count );
332 +
333 + if( $order_by == 'date_reverse' ){
334 + $items = array_reverse( $items );
335 + }
336 +
337 + return $items;
338 +
339 + }
340 +
341 + function get_thumbnail_url( $item, $thumbnail_default ){
342 +
258 343 // Try to get from the item enclosure
259 344 $enclosure = $item->get_enclosure();
260 345
261 346 if ( $enclosure->get_thumbnail() ) {
@@ -282,9 +367,9 @@
282 367 if( isset( $image[0]['data'] ) ){
283 368 return $image[0]['data'];
284 369 }
285 370
286 - return '';
371 + return trim( $thumbnail_default );
287 372
288 373 }
289 374
290 375 }