PluginProbe
Super RSS Reader – Add attractive RSS Feed Widget / 4.7
Super RSS Reader – Add attractive RSS Feed Widget v4.7
trunk 0.8 2.0 2.1 2.2 2.3 2.4 2.5 2.6 2.7 2.8 3.0 3.1 3.2 4.0 4.0.1 4.1 4.2 4.3 4.4 4.4.1 4.5 4.6 4.7 4.8 All 33 releases
← All changes | includes/feed.php +78 -46 4.34.7 View file →
@@ -17,30 +17,33 @@
17 17 }
18 18
19 19 public function html(){
20 20
21 - $urls = stripslashes( trim( $this->options['urls'] ) );
22 - $tab_titles = stripslashes( $this->options['tab_titles'] );
21 + $urls = trim( $this->options['urls'] );
22 + $tab_titles = $this->options['tab_titles'];
23 23 $count = intval( $this->options['count'] );
24 24
25 25 $show_date = intval( $this->options['show_date'] );
26 26 $show_desc = intval( $this->options['show_desc'] );
27 27 $show_author = intval( $this->options['show_author'] );
28 - $show_thumb = stripslashes( $this->options['show_thumb'] );
28 + $show_thumb = intval( $this->options['show_thumb'] );
29 29 $open_newtab = intval( $this->options['open_newtab'] );
30 30 $add_nofollow = intval( $this->options['add_nofollow'] );
31 31 $strip_desc = intval( $this->options['strip_desc'] );
32 32 $strip_title = intval( $this->options['strip_title'] );
33 - $date_format = htmlspecialchars( $this->options['date_format'] );
34 - $order_by = htmlspecialchars( $this->options['order_by'] );
35 - $read_more = htmlspecialchars( $this->options['read_more'] );
33 + $date_format = $this->options['date_format'];
34 + $date_timezone = $this->options['date_timezone'];
35 + $order_by = $this->options['order_by'];
36 + $read_more = $this->options['read_more'];
36 37 $rich_desc = intval( $this->options['rich_desc'] );
37 - $thumbnail_position = htmlspecialchars( $this->options['thumbnail_position'] );
38 - $thumbnail_size = htmlspecialchars( $this->options['thumbnail_size'] );
39 - $thumbnail_default = htmlspecialchars( $this->options['thumbnail_default'] );
38 + $desc_type = $this->options['desc_type'];
39 + $thumbnail_position = $this->options['thumbnail_position'];
40 + $thumbnail_size = $this->options['thumbnail_size'];
41 + $thumbnail_default = $this->options['thumbnail_default'];
42 + $no_feed_text = $this->options['no_feed_text'];
40 43
41 - $color_theme = stripslashes( $this->options['color_style'] );
42 - $display_type = stripslashes( $this->options['display_type'] );
44 + $color_theme = $this->options['color_style'];
45 + $display_type = $this->options['display_type'];
43 46 $visible_items = intval( $this->options['visible_items'] );
44 47 $ticker_speed = intval( $this->options['ticker_speed'] ) * 1000;
45 48
46 49 if( empty( $urls ) ){
@@ -55,8 +58,9 @@
55 58 $url_count = count( $urls );
56 59
57 60 $feeds = array();
58 61 $html = '';
62 + $no_feed_html = '<div>' . wp_kses_post( $no_feed_text ) . '</div>';
59 63
60 64 $classes = array( 'srr-wrap', 'srr-style-' . $color_theme );
61 65 if( $display_type == 'vertical_ticker' ) array_push( $classes, 'srr-vticker' );
62 66 $class = implode( ' ', $classes );
@@ -63,14 +67,20 @@
63 67
64 68 // Fetch the feed
65 69 for( $i=0; $i < $url_count; $i++ ){
66 70 $feed_url = trim( $urls[$i] );
71 +
72 + // Skip if the RSS feed URL is same as the site URL
73 + if ( in_array( untrailingslashit( $feed_url ), array( site_url(), home_url() ), true ) ) {
74 + continue;
75 + }
76 +
67 77 $feed = fetch_feed( $feed_url );
68 78
69 79 if( is_wp_error( $feed ) ){
70 - $feed_title = 'Error';
80 + $feed_title = __( 'Error' );
71 81 }else{
72 - $feed_title = ( isset( $tab_titles[$i] ) && !empty( $tab_titles[$i] ) ) ? $tab_titles[$i] : esc_attr( strip_tags( $feed->get_title() ) );
82 + $feed_title = ( isset( $tab_titles[$i] ) && !empty( $tab_titles[$i] ) ) ? $tab_titles[$i] : strip_tags( $feed->get_title() );
73 83 }
74 84
75 85 $feeds[ $feed_url ] = array(
76 86 'id' => rand( 100, 999 ),
@@ -80,17 +90,13 @@
80 90 }
81 91
82 92 // Generate tabs
83 93 if( $url_count > 1 ){
84 - $html .= '<ul class="srr-tab-wrap srr-tab-style-' . $color_theme . ' srr-clearfix">';
94 + $html .= '<ul class="srr-tab-wrap srr-tab-style-' . esc_attr( $color_theme ) . ' srr-clearfix">';
85 95 foreach( $feeds as $url => $data ){
86 96 $id = $data[ 'id' ];
87 97 $feed = $data[ 'feed' ];
88 - if( is_wp_error( $feed ) ){
89 - $html .= '<li data-tab="srr-tab-' . $id . '">Error</li>';
90 - }else{
91 - $html .= '<li data-tab="srr-tab-' . $id . '">' . $data[ 'title' ] . '</li>';
92 - }
98 + $html .= '<li data-tab="srr-tab-' . esc_attr( $id ) . '">' . wp_kses_post( $data[ 'title' ] ) . '</li>';
93 99 }
94 100 $html .= '</ul>';
95 101 }
96 102
@@ -101,18 +107,22 @@
101 107 $feed = $data[ 'feed' ];
102 108
103 109 // Check for feed errors
104 110 if ( is_wp_error( $feed ) ){
105 - $html .= '<div class="srr-wrap srr-style-' . $color_theme .'" data-id="srr-tab-' . $id . '"><p>RSS Error: ' . $feed->get_error_message() . '</p></div>';
111 + $html .= '<div class="srr-wrap srr-style-' . esc_attr( $color_theme ) .'" data-id="srr-tab-' . esc_attr( $id ) . '"><p>RSS Error: ' . wp_kses_post( $feed->get_error_message() ) . '</p></div>';
106 112 continue;
107 113 }
108 114
109 - if( method_exists( $feed, 'enable_order_by_date' ) && in_array( $order_by, array( 'date', 'date_reverse' ) ) ){
110 - $feed->enable_order_by_date( true );
115 + if( method_exists( $feed, 'enable_order_by_date' ) ){
116 + if( in_array( $order_by, array( 'date', 'date_reverse' ) ) ){
117 + $feed->enable_order_by_date( true );
118 + }else{
119 + $feed->enable_order_by_date( false );
120 + }
111 121 }
112 122
113 123 // Outer wrap start
114 - $html .= '<div class="' . $class . '" data-visible="' . $visible_items . '" data-speed="' . $ticker_speed . '" data-id="srr-tab-' . $id . '">';
124 + $html .= '<div class="' . esc_attr( $class ) . '" data-visible="' . esc_attr( $visible_items ) . '" data-speed="' . esc_attr( $ticker_speed ) . '" data-id="srr-tab-' . esc_attr( $id ) . '">';
115 125 $html .= '<div>';
116 126
117 127 $max_items = $feed->get_item_quantity();
118 128
@@ -117,9 +127,9 @@
117 127 $max_items = $feed->get_item_quantity();
118 128
119 129 // Check feed items
120 130 if ( $max_items == 0 ){
121 - $html .= '<div>' . __( 'No items', 'super-rss-reader' ) . '</div>';
131 + $html .= $no_feed_html;
122 132 }else{
123 133
124 134 $feed_items = $feed->get_items();
125 135 $feed_items = $this->process_items( $feed_items, $count, $order_by );
@@ -130,12 +140,12 @@
130 140
131 141 // Link
132 142 $link = $item->get_link();
133 143 while ( stristr( $link, 'http' ) != $link ){ $link = substr( $link, 1 ); }
134 - $link = esc_url( strip_tags($link) );
144 + $link = strip_tags($link);
135 145
136 146 // Title
137 - $title = esc_attr( strip_tags( $item->get_title() ) );
147 + $title = strip_tags( $item->get_title() );
138 148 $title_full = $title;
139 149
140 150 if ( empty( $title ) ){
141 151 $title = __( 'No Title', 'super-rss-reader' );
@@ -150,12 +160,28 @@
150 160
151 161 // Add no follow attribute
152 162 $no_follow = $add_nofollow ? ' rel="nofollow noopener noreferrer"' : '';
153 163
164 + if( empty( $link ) ){
165 + $link = '#';
166 + $new_tab = '';
167 + }
168 +
154 169 // Date
155 - $date = date_i18n( $date_format, $item->get_date( 'U' ) );
156 - $date_full = esc_attr( $item->get_date() );
170 + $date = '';
171 + $date_full = strip_tags( $item->get_date() );
157 172
173 + if( strtolower( $date_format ) == 'relative' ){
174 + $item_date = $item->get_date( 'U' );
175 + if( $item_date ){
176 + $date = human_time_diff( $item_date, current_time( 'U' ) ) . ' ' . __( 'ago' );
177 + }else{
178 + $date = __( 'Today' );
179 + }
180 + }else{
181 + $date = SRR_Utilities::date_i18n( $date_format, $item->get_date( 'U' ), $date_timezone );
182 + }
183 +
158 184 // Thumbnail
159 185 $thumb = '';
160 186 if ( $show_thumb == 1 ){
161 187 $thumb_url = $this->get_thumbnail_url( $item, $thumbnail_default );
@@ -168,9 +194,9 @@
168 194 $thumb_style = '';
169 195 foreach( $thumb_styles as $prop => $val ){
170 196 $thumb_style .= "$prop:$val;";
171 197 }
172 - $thumb = '<a href="' . $link . '" class="srr-thumb srr-thumb-' . $thumbnail_position . '" style="' . $thumb_style . '" ' . $new_tab . $no_follow . '><img src="' . $thumb_url . '" alt="' . $title_full . '" align="left" /></a>';
198 + $thumb = '<a href="' . esc_url( $link ) . '" class="srr-thumb srr-thumb-' . esc_attr( $thumbnail_position ) . '" style="' . esc_attr( $thumb_style ) . '" ' . $new_tab . $no_follow . '><img src="' . esc_url( $thumb_url ) . '" alt="' . esc_attr( $title_full ) . '" align="left"' . ( wp_lazy_loading_enabled( 'img', 'srr-thumbnail' ) ? ' loading="lazy"' : '' ) . ' /></a>';
173 199 }
174 200 }
175 201
176 202 // Description
@@ -175,38 +201,39 @@
175 201
176 202 // Description
177 203 $desc = '';
178 204 if( $show_desc ){
205 + $desc_content = ( $desc_type == 'summary' ) ? $item->get_description() : $item->get_content();
179 206 if( $rich_desc ){
180 - $desc = strip_tags( $item->get_description(), '<p><a><img><em><strong><font><strike><s><u><i>' );
207 + $desc = wp_kses_post( strip_tags( $desc_content, '<p><a><img><em><strong><font><strike><s><u><i><br>' ) );
181 208 }else{
209 + $desc = str_replace( array( "\n", "\r" ), ' ', strip_tags( @html_entity_decode( $desc_content, ENT_QUOTES, get_option('blog_charset') ) ) );
182 210
183 - $desc = str_replace( array( "\n", "\r" ), ' ', esc_attr( strip_tags( @html_entity_decode( $item->get_description(), ENT_QUOTES, get_option('blog_charset') ) ) ) );
184 - $read_more_link = '';
185 -
186 211 if( $strip_desc != 0 ){
187 212 $desc = wp_trim_words( $desc, $strip_desc );
188 - $read_more_link = !empty( $read_more ) ? ' <a href="' . $link . '" title="' . __( 'Read more', 'super-rss-reader' ) . '"' . $new_tab . $no_follow . ' class="srr-read-more">' . $read_more . '</a>' : '';
189 -
190 213 if ( '[...]' == substr( $desc, -5 ) ){
191 214 $desc = substr( $desc, 0, -5 );
192 215 }elseif ( '[&hellip;]' != substr( $desc, -10 ) ){
193 216 $desc .= '';
194 217 }
218 + }
195 219
196 - $desc = esc_html( $desc );
220 + $desc = trim( esc_html( $desc ) );
221 + if( !empty( $desc ) ){
222 + $read_more_link = !empty( $read_more ) ? ' <a href="' . esc_url( $link ) . '" title="' . esc_attr__( 'Read more', 'super-rss-reader' ) . '"' . $new_tab . $no_follow . ' class="srr-read-more">' . esc_html( $read_more ) . '</a>' : '';
223 + $desc = $desc . $read_more_link;
197 224 }
198 225
199 - $desc = $desc . $read_more_link;
200 -
201 226 }
202 227 }
203 228
204 229 // Author
205 - $author = $item->get_author();
206 - if ( is_object( $author ) ) {
207 - $author = $author->get_name();
208 - $author = esc_html( strip_tags( $author ) );
230 + $author = '';
231 + if( $show_author ){
232 + $author = $item->get_author();
233 + if ( is_object( $author ) ) {
234 + $author = strip_tags( $author->get_name() );
235 + }
209 236 }
210 237
211 238 $t_title = '';
212 239 $t_meta = '';
@@ -212,19 +239,19 @@
212 239 $t_meta = '';
213 240 $t_thumb = '';
214 241 $t_desc = '';
215 242
216 - $t_title .= '<div class="srr-title"><a href="' . $link . '"' . $new_tab . $no_follow . ' title="' . $title_full . '">' . $title . '</a></div>';
243 + $t_title .= '<div class="srr-title"><a href="' . esc_url( $link ) . '"' . $new_tab . $no_follow . ' title="' . esc_attr( $title_full ) . '">' . esc_html( $title ) . '</a></div>';
217 244
218 245 // Metadata
219 246 if( $show_date || $show_author ){
220 247 $t_meta .= '<div class="srr-meta">';
221 248 if( $show_date && !empty( $date ) ){
222 - $t_meta .= '<time class="srr-date" title="' . $date_full . ' UTC">' . $date . '</time>';
249 + $t_meta .= '<time class="srr-date" title="' . esc_attr( $date_full ) . ' UTC">' . esc_html( $date ) . '</time>';
223 250 }
224 251
225 252 if( $show_author && !empty( $author ) ){
226 - $t_meta .= ' - <cite class="srr-author">' . $author . '</cite>';
253 + $t_meta .= ' - <cite class="srr-author">' . esc_html( $author ) . '</cite>';
227 254 }
228 255 $t_meta .= '</div>'; // End meta
229 256 }
230 257
@@ -231,9 +258,9 @@
231 258 if ( $show_thumb ){
232 259 $t_thumb .= $thumb;
233 260 }
234 261
235 - if( $show_desc ){
262 + if( $show_desc && !empty( $desc ) ){
236 263 $t_desc .= '<div class="srr-summary srr-clearfix">';
237 264 $t_desc .= $rich_desc ? $desc : ( '<p>' . $desc . '</p>' );
238 265 $t_desc .= '</div>'; // End summary
239 266 }
@@ -264,8 +291,13 @@
264 291 $html .= '</div>'; // End feed item
265 292
266 293 $j++;
267 294 }
295 +
296 + if( $j == 1 ){
297 + $html .= $no_feed_html;
298 + }
299 +
268 300 }
269 301
270 302 // Outer wrap end
271 303 $html .= '</div></div>' ;