| @@ -195,9 +195,9 @@ | ||
| 195 | 195 | $query = sprintf( |
| 196 | 196 | 'SELECT id, title FROM %s ORDER BY id ASC', |
| 197 | 197 | esc_sql( $forms_table ) |
| 198 | 198 | ); |
| 199 | - // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared | |
| 199 | + // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter -- Table names from $wpdb->prefix and IDs are int-cast/esc_sql'd; not user input. | |
| 200 | 200 | $rows = $wpdb->get_results( $query, ARRAY_A ); |
| 201 | 201 | if ( ! is_array( $rows ) ) { |
| 202 | 202 | return []; |
| 203 | 203 | } |
| @@ -346,9 +346,9 @@ | ||
| 346 | 346 | 'SELECT id, `label`, `key`, `type`, `order` FROM %s WHERE parent_id = %d ORDER BY `order` ASC', |
| 347 | 347 | esc_sql( $fields_table ), |
| 348 | 348 | (int) $form_id |
| 349 | 349 | ); |
| 350 | - // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared | |
| 350 | + // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter -- Table names from $wpdb->prefix and IDs are int-cast/esc_sql'd; not user input. | |
| 351 | 351 | $rows = $wpdb->get_results( $fields_query, ARRAY_A ); |
| 352 | 352 | if ( ! is_array( $rows ) || empty( $rows ) ) { |
| 353 | 353 | return []; |
| 354 | 354 | } |
| @@ -362,9 +362,9 @@ | ||
| 362 | 362 | 'SELECT parent_id, COALESCE(NULLIF(meta_key, \'\'), `key`) AS k, COALESCE(NULLIF(meta_value, \'\'), `value`) AS v FROM %s WHERE parent_id IN (%s)', |
| 363 | 363 | esc_sql( $field_meta_table ), |
| 364 | 364 | $ids_sql |
| 365 | 365 | ); |
| 366 | - // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared | |
| 366 | + // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter -- Table names from $wpdb->prefix and IDs are int-cast/esc_sql'd; not user input. | |
| 367 | 367 | $meta_rows = $wpdb->get_results( $meta_query, ARRAY_A ); |
| 368 | 368 | |
| 369 | 369 | $meta_by_field = []; |
| 370 | 370 | if ( is_array( $meta_rows ) ) { |
| @@ -407,9 +407,9 @@ | ||
| 407 | 407 | 'SELECT COALESCE(NULLIF(meta_key, \'\'), `key`) AS k, COALESCE(NULLIF(meta_value, \'\'), `value`) AS v FROM %s WHERE parent_id = %d', |
| 408 | 408 | esc_sql( $table ), |
| 409 | 409 | (int) $form_id |
| 410 | 410 | ); |
| 411 | - // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared | |
| 411 | + // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter -- Table names from $wpdb->prefix and IDs are int-cast/esc_sql'd; not user input. | |
| 412 | 412 | $rows = $wpdb->get_results( $query, ARRAY_A ); |
| 413 | 413 | $out = []; |
| 414 | 414 | if ( is_array( $rows ) ) { |
| 415 | 415 | foreach ( $rows as $row ) { |
| @@ -448,9 +448,9 @@ | ||
| 448 | 448 | esc_sql( $objects_table ), |
| 449 | 449 | esc_sql( $rels_table ), |
| 450 | 450 | (int) $form_id |
| 451 | 451 | ); |
| 452 | - // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared | |
| 452 | + // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter -- Table names from $wpdb->prefix and IDs are int-cast/esc_sql'd; not user input. | |
| 453 | 453 | $rows = $wpdb->get_results( $query, ARRAY_A ); |
| 454 | 454 | if ( ! is_array( $rows ) || empty( $rows ) ) { |
| 455 | 455 | $this->actions_cache = []; |
| 456 | 456 | return $this->actions_cache; |
| @@ -464,9 +464,9 @@ | ||
| 464 | 464 | 'SELECT parent_id, COALESCE(NULLIF(meta_key, \'\'), `key`) AS k, COALESCE(NULLIF(meta_value, \'\'), `value`) AS v FROM %s WHERE parent_id IN (%s)', |
| 465 | 465 | esc_sql( $meta_table ), |
| 466 | 466 | $ids_sql |
| 467 | 467 | ); |
| 468 | - // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared | |
| 468 | + // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter -- Table names from $wpdb->prefix and IDs are int-cast/esc_sql'd; not user input. | |
| 469 | 469 | $meta_rows = $wpdb->get_results( $meta_query, ARRAY_A ); |
| 470 | 470 | $by_id = []; |
| 471 | 471 | if ( is_array( $meta_rows ) ) { |
| 472 | 472 | foreach ( $meta_rows as $m ) { |