PluginProbe
Super RSS Reader – Add attractive RSS Feed Widget / 4.7
Super RSS Reader – Add attractive RSS Feed Widget v4.7
trunk 0.8 2.0 2.1 2.2 2.3 2.4 2.5 2.6 2.7 2.8 3.0 3.1 3.2 4.0 4.0.1 4.1 4.2 4.3 4.4 4.4.1 4.5 4.6 4.7 4.8 All 33 releases
← All changes | includes/feed.php +44 -45 4.64.7 View file →
@@ -17,33 +17,33 @@
17 17 }
18 18
19 19 public function html(){
20 20
21 - $urls = stripslashes( trim( $this->options['urls'] ) );
22 - $tab_titles = stripslashes( $this->options['tab_titles'] );
21 + $urls = trim( $this->options['urls'] );
22 + $tab_titles = $this->options['tab_titles'];
23 23 $count = intval( $this->options['count'] );
24 24
25 25 $show_date = intval( $this->options['show_date'] );
26 26 $show_desc = intval( $this->options['show_desc'] );
27 27 $show_author = intval( $this->options['show_author'] );
28 - $show_thumb = stripslashes( $this->options['show_thumb'] );
28 + $show_thumb = intval( $this->options['show_thumb'] );
29 29 $open_newtab = intval( $this->options['open_newtab'] );
30 30 $add_nofollow = intval( $this->options['add_nofollow'] );
31 31 $strip_desc = intval( $this->options['strip_desc'] );
32 32 $strip_title = intval( $this->options['strip_title'] );
33 - $date_format = htmlspecialchars( $this->options['date_format'] );
34 - $date_timezone = htmlspecialchars( $this->options['date_timezone'] );
35 - $order_by = htmlspecialchars( $this->options['order_by'] );
36 - $read_more = htmlspecialchars( $this->options['read_more'] );
33 + $date_format = $this->options['date_format'];
34 + $date_timezone = $this->options['date_timezone'];
35 + $order_by = $this->options['order_by'];
36 + $read_more = $this->options['read_more'];
37 37 $rich_desc = intval( $this->options['rich_desc'] );
38 - $desc_type = htmlspecialchars( $this->options['desc_type'] );
39 - $thumbnail_position = htmlspecialchars( $this->options['thumbnail_position'] );
40 - $thumbnail_size = htmlspecialchars( $this->options['thumbnail_size'] );
41 - $thumbnail_default = htmlspecialchars( $this->options['thumbnail_default'] );
42 - $no_feed_text = htmlspecialchars( $this->options['no_feed_text'] );
38 + $desc_type = $this->options['desc_type'];
39 + $thumbnail_position = $this->options['thumbnail_position'];
40 + $thumbnail_size = $this->options['thumbnail_size'];
41 + $thumbnail_default = $this->options['thumbnail_default'];
42 + $no_feed_text = $this->options['no_feed_text'];
43 43
44 - $color_theme = stripslashes( $this->options['color_style'] );
45 - $display_type = stripslashes( $this->options['display_type'] );
44 + $color_theme = $this->options['color_style'];
45 + $display_type = $this->options['display_type'];
46 46 $visible_items = intval( $this->options['visible_items'] );
47 47 $ticker_speed = intval( $this->options['ticker_speed'] ) * 1000;
48 48
49 49 if( empty( $urls ) ){
@@ -58,9 +58,9 @@
58 58 $url_count = count( $urls );
59 59
60 60 $feeds = array();
61 61 $html = '';
62 - $no_feed_html = '<div>' . $no_feed_text . '</div>';
62 + $no_feed_html = '<div>' . wp_kses_post( $no_feed_text ) . '</div>';
63 63
64 64 $classes = array( 'srr-wrap', 'srr-style-' . $color_theme );
65 65 if( $display_type == 'vertical_ticker' ) array_push( $classes, 'srr-vticker' );
66 66 $class = implode( ' ', $classes );
@@ -67,14 +67,20 @@
67 67
68 68 // Fetch the feed
69 69 for( $i=0; $i < $url_count; $i++ ){
70 70 $feed_url = trim( $urls[$i] );
71 +
72 + // Skip if the RSS feed URL is same as the site URL
73 + if ( in_array( untrailingslashit( $feed_url ), array( site_url(), home_url() ), true ) ) {
74 + continue;
75 + }
76 +
71 77 $feed = fetch_feed( $feed_url );
72 78
73 79 if( is_wp_error( $feed ) ){
74 - $feed_title = 'Error';
80 + $feed_title = __( 'Error' );
75 81 }else{
76 - $feed_title = ( isset( $tab_titles[$i] ) && !empty( $tab_titles[$i] ) ) ? $tab_titles[$i] : esc_attr( strip_tags( $feed->get_title() ) );
82 + $feed_title = ( isset( $tab_titles[$i] ) && !empty( $tab_titles[$i] ) ) ? $tab_titles[$i] : strip_tags( $feed->get_title() );
77 83 }
78 84
79 85 $feeds[ $feed_url ] = array(
80 86 'id' => rand( 100, 999 ),
@@ -84,17 +90,13 @@
84 90 }
85 91
86 92 // Generate tabs
87 93 if( $url_count > 1 ){
88 - $html .= '<ul class="srr-tab-wrap srr-tab-style-' . $color_theme . ' srr-clearfix">';
94 + $html .= '<ul class="srr-tab-wrap srr-tab-style-' . esc_attr( $color_theme ) . ' srr-clearfix">';
89 95 foreach( $feeds as $url => $data ){
90 96 $id = $data[ 'id' ];
91 97 $feed = $data[ 'feed' ];
92 - if( is_wp_error( $feed ) ){
93 - $html .= '<li data-tab="srr-tab-' . $id . '">Error</li>';
94 - }else{
95 - $html .= '<li data-tab="srr-tab-' . $id . '">' . $data[ 'title' ] . '</li>';
96 - }
98 + $html .= '<li data-tab="srr-tab-' . esc_attr( $id ) . '">' . wp_kses_post( $data[ 'title' ] ) . '</li>';
97 99 }
98 100 $html .= '</ul>';
99 101 }
100 102
@@ -105,9 +107,9 @@
105 107 $feed = $data[ 'feed' ];
106 108
107 109 // Check for feed errors
108 110 if ( is_wp_error( $feed ) ){
109 - $html .= '<div class="srr-wrap srr-style-' . $color_theme .'" data-id="srr-tab-' . $id . '"><p>RSS Error: ' . $feed->get_error_message() . '</p></div>';
111 + $html .= '<div class="srr-wrap srr-style-' . esc_attr( $color_theme ) .'" data-id="srr-tab-' . esc_attr( $id ) . '"><p>RSS Error: ' . wp_kses_post( $feed->get_error_message() ) . '</p></div>';
110 112 continue;
111 113 }
112 114
113 115 if( method_exists( $feed, 'enable_order_by_date' ) ){
@@ -118,9 +120,9 @@
118 120 }
119 121 }
120 122
121 123 // Outer wrap start
122 - $html .= '<div class="' . $class . '" data-visible="' . $visible_items . '" data-speed="' . $ticker_speed . '" data-id="srr-tab-' . $id . '">';
124 + $html .= '<div class="' . esc_attr( $class ) . '" data-visible="' . esc_attr( $visible_items ) . '" data-speed="' . esc_attr( $ticker_speed ) . '" data-id="srr-tab-' . esc_attr( $id ) . '">';
123 125 $html .= '<div>';
124 126
125 127 $max_items = $feed->get_item_quantity();
126 128
@@ -138,12 +140,12 @@
138 140
139 141 // Link
140 142 $link = $item->get_link();
141 143 while ( stristr( $link, 'http' ) != $link ){ $link = substr( $link, 1 ); }
142 - $link = esc_url( strip_tags($link) );
144 + $link = strip_tags($link);
143 145
144 146 // Title
145 - $title = esc_attr( strip_tags( $item->get_title() ) );
147 + $title = strip_tags( $item->get_title() );
146 148 $title_full = $title;
147 149
148 150 if ( empty( $title ) ){
149 151 $title = __( 'No Title', 'super-rss-reader' );
@@ -165,9 +167,9 @@
165 167 }
166 168
167 169 // Date
168 170 $date = '';
169 - $date_full = esc_attr( $item->get_date() );
171 + $date_full = strip_tags( $item->get_date() );
170 172
171 173 if( strtolower( $date_format ) == 'relative' ){
172 174 $item_date = $item->get_date( 'U' );
173 175 if( $item_date ){
@@ -192,9 +194,9 @@
192 194 $thumb_style = '';
193 195 foreach( $thumb_styles as $prop => $val ){
194 196 $thumb_style .= "$prop:$val;";
195 197 }
196 - $thumb = '<a href="' . $link . '" class="srr-thumb srr-thumb-' . $thumbnail_position . '" style="' . $thumb_style . '" ' . $new_tab . $no_follow . '><img src="' . $thumb_url . '" alt="' . $title_full . '" align="left" /></a>';
198 + $thumb = '<a href="' . esc_url( $link ) . '" class="srr-thumb srr-thumb-' . esc_attr( $thumbnail_position ) . '" style="' . esc_attr( $thumb_style ) . '" ' . $new_tab . $no_follow . '><img src="' . esc_url( $thumb_url ) . '" alt="' . esc_attr( $title_full ) . '" align="left"' . ( wp_lazy_loading_enabled( 'img', 'srr-thumbnail' ) ? ' loading="lazy"' : '' ) . ' /></a>';
197 199 }
198 200 }
199 201
200 202 // Description
@@ -201,29 +203,24 @@
201 203 $desc = '';
202 204 if( $show_desc ){
203 205 $desc_content = ( $desc_type == 'summary' ) ? $item->get_description() : $item->get_content();
204 206 if( $rich_desc ){
205 - $desc = strip_tags( $desc_content, '<p><a><img><em><strong><font><strike><s><u><i><br>' );
207 + $desc = wp_kses_post( strip_tags( $desc_content, '<p><a><img><em><strong><font><strike><s><u><i><br>' ) );
206 208 }else{
209 + $desc = str_replace( array( "\n", "\r" ), ' ', strip_tags( @html_entity_decode( $desc_content, ENT_QUOTES, get_option('blog_charset') ) ) );
207 210
208 - $desc = str_replace( array( "\n", "\r" ), ' ', esc_attr( strip_tags( @html_entity_decode( $desc_content, ENT_QUOTES, get_option('blog_charset') ) ) ) );
209 - $read_more_link = '';
210 -
211 211 if( $strip_desc != 0 ){
212 212 $desc = wp_trim_words( $desc, $strip_desc );
213 - $read_more_link = !empty( $read_more ) ? ' <a href="' . $link . '" title="' . __( 'Read more', 'super-rss-reader' ) . '"' . $new_tab . $no_follow . ' class="srr-read-more">' . $read_more . '</a>' : '';
214 -
215 213 if ( '[...]' == substr( $desc, -5 ) ){
216 214 $desc = substr( $desc, 0, -5 );
217 215 }elseif ( '[&hellip;]' != substr( $desc, -10 ) ){
218 216 $desc .= '';
219 217 }
220 -
221 - $desc = esc_html( $desc );
222 218 }
223 219
224 - $desc = trim( $desc );
220 + $desc = trim( esc_html( $desc ) );
225 221 if( !empty( $desc ) ){
222 + $read_more_link = !empty( $read_more ) ? ' <a href="' . esc_url( $link ) . '" title="' . esc_attr__( 'Read more', 'super-rss-reader' ) . '"' . $new_tab . $no_follow . ' class="srr-read-more">' . esc_html( $read_more ) . '</a>' : '';
226 223 $desc = $desc . $read_more_link;
227 224 }
228 225
229 226 }
@@ -229,12 +226,14 @@
229 226 }
230 227 }
231 228
232 229 // Author
233 - $author = $item->get_author();
234 - if ( is_object( $author ) ) {
235 - $author = $author->get_name();
236 - $author = esc_html( strip_tags( $author ) );
230 + $author = '';
231 + if( $show_author ){
232 + $author = $item->get_author();
233 + if ( is_object( $author ) ) {
234 + $author = strip_tags( $author->get_name() );
235 + }
237 236 }
238 237
239 238 $t_title = '';
240 239 $t_meta = '';
@@ -240,19 +239,19 @@
240 239 $t_meta = '';
241 240 $t_thumb = '';
242 241 $t_desc = '';
243 242
244 - $t_title .= '<div class="srr-title"><a href="' . $link . '"' . $new_tab . $no_follow . ' title="' . $title_full . '">' . $title . '</a></div>';
243 + $t_title .= '<div class="srr-title"><a href="' . esc_url( $link ) . '"' . $new_tab . $no_follow . ' title="' . esc_attr( $title_full ) . '">' . esc_html( $title ) . '</a></div>';
245 244
246 245 // Metadata
247 246 if( $show_date || $show_author ){
248 247 $t_meta .= '<div class="srr-meta">';
249 248 if( $show_date && !empty( $date ) ){
250 - $t_meta .= '<time class="srr-date" title="' . $date_full . ' UTC">' . $date . '</time>';
249 + $t_meta .= '<time class="srr-date" title="' . esc_attr( $date_full ) . ' UTC">' . esc_html( $date ) . '</time>';
251 250 }
252 251
253 252 if( $show_author && !empty( $author ) ){
254 - $t_meta .= ' - <cite class="srr-author">' . $author . '</cite>';
253 + $t_meta .= ' - <cite class="srr-author">' . esc_html( $author ) . '</cite>';
255 254 }
256 255 $t_meta .= '</div>'; // End meta
257 256 }
258 257