| @@ -182,9 +182,9 @@ | ||
| 182 | 182 | |
| 183 | 183 | $table_name = $wpdb->prefix . 'srfm_entries'; |
| 184 | 184 | $placeholders = implode( ',', array_fill( 0, count( $form_ids ), '%d' ) ); |
| 185 | 185 | |
| 186 | - // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching -- Batch query to avoid N+1; results are not cached as they reflect real-time entry counts. | |
| 186 | + // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, PluginCheck.Security.DirectDB.UnescapedDBParameter -- Batch query to avoid N+1; table name from $wpdb->prefix and placeholders from array_fill() (not user input); results not cached as they reflect real-time entry counts. | |
| 187 | 187 | $results = $wpdb->get_results( |
| 188 | 188 | $wpdb->prepare( |
| 189 | 189 | // phpcs:ignore WordPress.DB.PreparedSQL.InterpolatedNotPrepared, WordPress.DB.PreparedSQLPlaceholders.UnfinishedPrepare -- Table name and placeholders are constructed from $wpdb->prefix and array_fill(), not user input. |
| 190 | 190 | "SELECT form_id, COUNT(*) as cnt FROM {$table_name} WHERE form_id IN ({$placeholders}) AND status != 'trash' GROUP BY form_id", |