PluginProbe
Super RSS Reader – Add attractive RSS Feed Widget / 4.7
Super RSS Reader – Add attractive RSS Feed Widget v4.7
trunk 0.8 2.0 2.1 2.2 2.3 2.4 2.5 2.6 2.7 2.8 3.0 3.1 3.2 4.0 4.0.1 4.1 4.2 4.3 4.4 4.4.1 4.5 4.6 4.7 4.8 All 33 releases
← All changes | includes/feed.php +107 -47 4.14.7 View file →
@@ -17,29 +17,33 @@
17 17 }
18 18
19 19 public function html(){
20 20
21 - $urls = stripslashes( trim( $this->options['urls'] ) );
22 - $tab_titles = stripslashes( $this->options['tab_titles'] );
21 + $urls = trim( $this->options['urls'] );
22 + $tab_titles = $this->options['tab_titles'];
23 23 $count = intval( $this->options['count'] );
24 24
25 25 $show_date = intval( $this->options['show_date'] );
26 26 $show_desc = intval( $this->options['show_desc'] );
27 27 $show_author = intval( $this->options['show_author'] );
28 - $show_thumb = stripslashes( $this->options['show_thumb'] );
28 + $show_thumb = intval( $this->options['show_thumb'] );
29 29 $open_newtab = intval( $this->options['open_newtab'] );
30 30 $add_nofollow = intval( $this->options['add_nofollow'] );
31 31 $strip_desc = intval( $this->options['strip_desc'] );
32 32 $strip_title = intval( $this->options['strip_title'] );
33 - $date_format = htmlspecialchars( $this->options['date_format'] );
34 - $read_more = htmlspecialchars( $this->options['read_more'] );
33 + $date_format = $this->options['date_format'];
34 + $date_timezone = $this->options['date_timezone'];
35 + $order_by = $this->options['order_by'];
36 + $read_more = $this->options['read_more'];
35 37 $rich_desc = intval( $this->options['rich_desc'] );
36 - $thumbnail_position = htmlspecialchars( $this->options['thumbnail_position'] );
37 - $thumbnail_size = htmlspecialchars( $this->options['thumbnail_size'] );
38 - $thumbnail_default = htmlspecialchars( $this->options['thumbnail_default'] );
38 + $desc_type = $this->options['desc_type'];
39 + $thumbnail_position = $this->options['thumbnail_position'];
40 + $thumbnail_size = $this->options['thumbnail_size'];
41 + $thumbnail_default = $this->options['thumbnail_default'];
42 + $no_feed_text = $this->options['no_feed_text'];
39 43
40 - $color_theme = stripslashes( $this->options['color_style'] );
41 - $display_type = stripslashes( $this->options['display_type'] );
44 + $color_theme = $this->options['color_style'];
45 + $display_type = $this->options['display_type'];
42 46 $visible_items = intval( $this->options['visible_items'] );
43 47 $ticker_speed = intval( $this->options['ticker_speed'] ) * 1000;
44 48
45 49 if( empty( $urls ) ){
@@ -54,8 +58,9 @@
54 58 $url_count = count( $urls );
55 59
56 60 $feeds = array();
57 61 $html = '';
62 + $no_feed_html = '<div>' . wp_kses_post( $no_feed_text ) . '</div>';
58 63
59 64 $classes = array( 'srr-wrap', 'srr-style-' . $color_theme );
60 65 if( $display_type == 'vertical_ticker' ) array_push( $classes, 'srr-vticker' );
61 66 $class = implode( ' ', $classes );
@@ -62,14 +67,20 @@
62 67
63 68 // Fetch the feed
64 69 for( $i=0; $i < $url_count; $i++ ){
65 70 $feed_url = trim( $urls[$i] );
71 +
72 + // Skip if the RSS feed URL is same as the site URL
73 + if ( in_array( untrailingslashit( $feed_url ), array( site_url(), home_url() ), true ) ) {
74 + continue;
75 + }
76 +
66 77 $feed = fetch_feed( $feed_url );
67 78
68 79 if( is_wp_error( $feed ) ){
69 - $feed_title = 'Error';
80 + $feed_title = __( 'Error' );
70 81 }else{
71 - $feed_title = ( isset( $tab_titles[$i] ) && !empty( $tab_titles[$i] ) ) ? $tab_titles[$i] : esc_attr( strip_tags( $feed->get_title() ) );
82 + $feed_title = ( isset( $tab_titles[$i] ) && !empty( $tab_titles[$i] ) ) ? $tab_titles[$i] : strip_tags( $feed->get_title() );
72 83 }
73 84
74 85 $feeds[ $feed_url ] = array(
75 86 'id' => rand( 100, 999 ),
@@ -79,17 +90,13 @@
79 90 }
80 91
81 92 // Generate tabs
82 93 if( $url_count > 1 ){
83 - $html .= '<ul class="srr-tab-wrap srr-tab-style-' . $color_theme . ' srr-clearfix">';
94 + $html .= '<ul class="srr-tab-wrap srr-tab-style-' . esc_attr( $color_theme ) . ' srr-clearfix">';
84 95 foreach( $feeds as $url => $data ){
85 96 $id = $data[ 'id' ];
86 97 $feed = $data[ 'feed' ];
87 - if( is_wp_error( $feed ) ){
88 - $html .= '<li data-tab="srr-tab-' . $id . '">Error</li>';
89 - }else{
90 - $html .= '<li data-tab="srr-tab-' . $id . '">' . $data[ 'title' ] . '</li>';
91 - }
98 + $html .= '<li data-tab="srr-tab-' . esc_attr( $id ) . '">' . wp_kses_post( $data[ 'title' ] ) . '</li>';
92 99 }
93 100 $html .= '</ul>';
94 101 }
95 102
@@ -100,28 +107,35 @@
100 107 $feed = $data[ 'feed' ];
101 108
102 109 // Check for feed errors
103 110 if ( is_wp_error( $feed ) ){
104 - $html .= '<div class="srr-wrap srr-style-' . $color_theme .'" data-id="srr-tab-' . $id . '"><p>RSS Error: ' . $feed->get_error_message() . '</p></div>';
111 + $html .= '<div class="srr-wrap srr-style-' . esc_attr( $color_theme ) .'" data-id="srr-tab-' . esc_attr( $id ) . '"><p>RSS Error: ' . wp_kses_post( $feed->get_error_message() ) . '</p></div>';
105 112 continue;
106 113 }
107 114
108 115 if( method_exists( $feed, 'enable_order_by_date' ) ){
109 - $feed->enable_order_by_date( false );
116 + if( in_array( $order_by, array( 'date', 'date_reverse' ) ) ){
117 + $feed->enable_order_by_date( true );
118 + }else{
119 + $feed->enable_order_by_date( false );
120 + }
110 121 }
111 122
112 - $max_items = $feed->get_item_quantity( $count );
113 - $feed_items = $feed->get_items( 0, $max_items );
114 -
115 123 // Outer wrap start
116 - $html .= '<div class="' . $class . '" data-visible="' . $visible_items . '" data-speed="' . $ticker_speed . '" data-id="srr-tab-' . $id . '">';
124 + $html .= '<div class="' . esc_attr( $class ) . '" data-visible="' . esc_attr( $visible_items ) . '" data-speed="' . esc_attr( $ticker_speed ) . '" data-id="srr-tab-' . esc_attr( $id ) . '">';
117 125 $html .= '<div>';
118 126
127 + $max_items = $feed->get_item_quantity();
128 +
119 129 // Check feed items
120 130 if ( $max_items == 0 ){
121 - $html .= '<div>' . __( 'No items', 'super-rss-reader' ) . '</div>';
131 + $html .= $no_feed_html;
122 132 }else{
133 +
134 + $feed_items = $feed->get_items();
135 + $feed_items = $this->process_items( $feed_items, $count, $order_by );
123 136 $j=1;
137 +
124 138 // Loop through each feed item
125 139 foreach( $feed_items as $item ){
126 140
127 141 // Link
@@ -126,12 +140,12 @@
126 140
127 141 // Link
128 142 $link = $item->get_link();
129 143 while ( stristr( $link, 'http' ) != $link ){ $link = substr( $link, 1 ); }
130 - $link = esc_url( strip_tags($link) );
144 + $link = strip_tags($link);
131 145
132 146 // Title
133 - $title = esc_attr( strip_tags( $item->get_title() ) );
147 + $title = strip_tags( $item->get_title() );
134 148 $title_full = $title;
135 149
136 150 if ( empty( $title ) ){
137 151 $title = __( 'No Title', 'super-rss-reader' );
@@ -146,16 +160,33 @@
146 160
147 161 // Add no follow attribute
148 162 $no_follow = $add_nofollow ? ' rel="nofollow noopener noreferrer"' : '';
149 163
164 + if( empty( $link ) ){
165 + $link = '#';
166 + $new_tab = '';
167 + }
168 +
150 169 // Date
151 - $date = date_i18n( $date_format, $item->get_date( 'U' ) );
152 - $date_full = esc_attr( $item->get_date() );
170 + $date = '';
171 + $date_full = strip_tags( $item->get_date() );
153 172
173 + if( strtolower( $date_format ) == 'relative' ){
174 + $item_date = $item->get_date( 'U' );
175 + if( $item_date ){
176 + $date = human_time_diff( $item_date, current_time( 'U' ) ) . ' ' . __( 'ago' );
177 + }else{
178 + $date = __( 'Today' );
179 + }
180 + }else{
181 + $date = SRR_Utilities::date_i18n( $date_format, $item->get_date( 'U' ), $date_timezone );
182 + }
183 +
154 184 // Thumbnail
155 185 $thumb = '';
156 186 if ( $show_thumb == 1 ){
157 187 $thumb_url = $this->get_thumbnail_url( $item, $thumbnail_default );
188 + $thumb_url = apply_filters( 'srr_mod_thumbnail_url', $thumb_url, $item, $feed, $thumbnail_default );
158 189 if( !empty( $thumb_url ) ){
159 190 $thumb_styles = array(
160 191 'width' => $thumbnail_size,
161 192 'height' => $thumbnail_size
@@ -163,9 +194,9 @@
163 194 $thumb_style = '';
164 195 foreach( $thumb_styles as $prop => $val ){
165 196 $thumb_style .= "$prop:$val;";
166 197 }
167 - $thumb = '<a href="' . $link . '" class="srr-thumb srr-thumb-' . $thumbnail_position . '" style="' . $thumb_style . '" ' . $new_tab . $no_follow . '><img src="' . $thumb_url . '" alt="' . $title_full . '" align="left" /></a>';
198 + $thumb = '<a href="' . esc_url( $link ) . '" class="srr-thumb srr-thumb-' . esc_attr( $thumbnail_position ) . '" style="' . esc_attr( $thumb_style ) . '" ' . $new_tab . $no_follow . '><img src="' . esc_url( $thumb_url ) . '" alt="' . esc_attr( $title_full ) . '" align="left"' . ( wp_lazy_loading_enabled( 'img', 'srr-thumbnail' ) ? ' loading="lazy"' : '' ) . ' /></a>';
168 199 }
169 200 }
170 201
171 202 // Description
@@ -170,38 +201,39 @@
170 201
171 202 // Description
172 203 $desc = '';
173 204 if( $show_desc ){
205 + $desc_content = ( $desc_type == 'summary' ) ? $item->get_description() : $item->get_content();
174 206 if( $rich_desc ){
175 - $desc = strip_tags( $item->get_description(), '<p><a><img><em><strong><font><strike><s><u><i>' );
207 + $desc = wp_kses_post( strip_tags( $desc_content, '<p><a><img><em><strong><font><strike><s><u><i><br>' ) );
176 208 }else{
209 + $desc = str_replace( array( "\n", "\r" ), ' ', strip_tags( @html_entity_decode( $desc_content, ENT_QUOTES, get_option('blog_charset') ) ) );
177 210
178 - $desc = str_replace( array( "\n", "\r" ), ' ', esc_attr( strip_tags( @html_entity_decode( $item->get_description(), ENT_QUOTES, get_option('blog_charset') ) ) ) );
179 - $read_more_link = '';
180 -
181 211 if( $strip_desc != 0 ){
182 212 $desc = wp_trim_words( $desc, $strip_desc );
183 - $read_more_link = !empty( $read_more ) ? ' <a href="' . $link . '" title="' . __( 'Read more', 'super-rss-reader' ) . '"' . $new_tab . $no_follow . ' class="srr-read-more">' . $read_more . '</a>' : '';
184 -
185 213 if ( '[...]' == substr( $desc, -5 ) ){
186 214 $desc = substr( $desc, 0, -5 );
187 215 }elseif ( '[&hellip;]' != substr( $desc, -10 ) ){
188 216 $desc .= '';
189 217 }
218 + }
190 219
191 - $desc = esc_html( $desc );
220 + $desc = trim( esc_html( $desc ) );
221 + if( !empty( $desc ) ){
222 + $read_more_link = !empty( $read_more ) ? ' <a href="' . esc_url( $link ) . '" title="' . esc_attr__( 'Read more', 'super-rss-reader' ) . '"' . $new_tab . $no_follow . ' class="srr-read-more">' . esc_html( $read_more ) . '</a>' : '';
223 + $desc = $desc . $read_more_link;
192 224 }
193 225
194 - $desc = $desc . $read_more_link;
195 -
196 226 }
197 227 }
198 228
199 229 // Author
200 - $author = $item->get_author();
201 - if ( is_object( $author ) ) {
202 - $author = $author->get_name();
203 - $author = esc_html( strip_tags( $author ) );
230 + $author = '';
231 + if( $show_author ){
232 + $author = $item->get_author();
233 + if ( is_object( $author ) ) {
234 + $author = strip_tags( $author->get_name() );
235 + }
204 236 }
205 237
206 238 $t_title = '';
207 239 $t_meta = '';
@@ -207,19 +239,19 @@
207 239 $t_meta = '';
208 240 $t_thumb = '';
209 241 $t_desc = '';
210 242
211 - $t_title .= '<div class="srr-title"><a href="' . $link . '"' . $new_tab . $no_follow . ' title="' . $title_full . '">' . $title . '</a></div>';
243 + $t_title .= '<div class="srr-title"><a href="' . esc_url( $link ) . '"' . $new_tab . $no_follow . ' title="' . esc_attr( $title_full ) . '">' . esc_html( $title ) . '</a></div>';
212 244
213 245 // Metadata
214 246 if( $show_date || $show_author ){
215 247 $t_meta .= '<div class="srr-meta">';
216 248 if( $show_date && !empty( $date ) ){
217 - $t_meta .= '<time class="srr-date" title="' . $date_full . ' UTC">' . $date . '</time>';
249 + $t_meta .= '<time class="srr-date" title="' . esc_attr( $date_full ) . ' UTC">' . esc_html( $date ) . '</time>';
218 250 }
219 251
220 252 if( $show_author && !empty( $author ) ){
221 - $t_meta .= ' - <cite class="srr-author">' . $author . '</cite>';
253 + $t_meta .= ' - <cite class="srr-author">' . esc_html( $author ) . '</cite>';
222 254 }
223 255 $t_meta .= '</div>'; // End meta
224 256 }
225 257
@@ -226,9 +258,9 @@
226 258 if ( $show_thumb ){
227 259 $t_thumb .= $thumb;
228 260 }
229 261
230 - if( $show_desc ){
262 + if( $show_desc && !empty( $desc ) ){
231 263 $t_desc .= '<div class="srr-summary srr-clearfix">';
232 264 $t_desc .= $rich_desc ? $desc : ( '<p>' . $desc . '</p>' );
233 265 $t_desc .= '</div>'; // End summary
234 266 }
@@ -259,8 +291,13 @@
259 291 $html .= '</div>'; // End feed item
260 292
261 293 $j++;
262 294 }
295 +
296 + if( $j == 1 ){
297 + $html .= $no_feed_html;
298 + }
299 +
263 300 }
264 301
265 302 // Outer wrap end
266 303 $html .= '</div></div>' ;
@@ -274,8 +311,31 @@
274 311
275 312 $html = '<div class="srr-main">' . $html . '</div>';
276 313
277 314 return $html;
315 +
316 + }
317 +
318 + function process_items( $items, $count, $order_by ){
319 +
320 + if( count( $items ) == 0 ){
321 + return $items;
322 + }
323 +
324 + // For shuffle order - Shuffle first and then slice as per count
325 + if( $order_by == 'random' ){
326 + shuffle( $items );
327 + return array_slice( $items, 0, $count );
328 + }
329 +
330 + // For date based order - slice first and then order
331 + $items = array_slice( $items, 0, $count );
332 +
333 + if( $order_by == 'date_reverse' ){
334 + $items = array_reverse( $items );
335 + }
336 +
337 + return $items;
278 338
279 339 }
280 340
281 341 function get_thumbnail_url( $item, $thumbnail_default ){