PluginProbe
ThinkRank AI SEO – AI SEO Plugin for WordPress: Schema, XML Sitemaps, Meta Tags, Search Console & Local SEO / 2.14.2
ThinkRank AI SEO – AI SEO Plugin for WordPress: Schema, XML Sitemaps, Meta Tags, Search Console & Local SEO v2.14.2
2.14.2 2.14.1 2.14.0 2.13.0 2.12.0 2.11.0 2.10.0 2.9.0 2.8.0 2.7.0 2.6.0 2.5.0 2.4.0 2.3.0 2.2.0 2.1.1 2.1.0 2.0.2 2.0.1 2.0.0 1.32.0 1.31.0 1.30.0 1.29.0 1.28.0 All 57 releases
← All changes | includes/seo/class-site-identity-manager.php +315 -36 2.10.0 → 2.14.2 View file →
@@ -318,8 +318,36 @@
318 318 * @var bool
319 319 */
320 320 private static bool $icon_sizes_listener_registered = false;
321 321
322 + /**
323 + * Whether the robots.txt resync listener is registered for this request.
324 + *
325 + * @since 2.14.0
326 + * @var bool
327 + */
328 + private static bool $robots_sync_listener_registered = false;
329 +
330 + /**
331 + * Flag set when a plugin change may have altered the sitemap set.
332 + *
333 + * @since 2.14.0
334 + * @var string
335 + */
336 + public const ROBOTS_RESYNC_OPTION = 'thinkrank_robots_txt_resync_pending';
337 +
338 + /**
339 + * Flag set when a plugin change may have altered the sitemap index.
340 + *
341 + * Separate from ROBOTS_RESYNC_OPTION because the two files exist
342 + * independently: that flag is only set when a physical robots.txt exists,
343 + * and the sitemap index needs rebuilding whether or not it does.
344 + *
345 + * @since 2.15.0
346 + * @var string
347 + */
348 + public const SITEMAP_RESYNC_OPTION = 'thinkrank_sitemap_contributors_changed';
349 +
322 350 public function __construct() {
323 351 parent::__construct('site_identity');
324 352
325 353 if (!self::$icon_sizes_listener_registered) {
@@ -328,11 +356,130 @@
328 356 // Admin only: resizing is not front-end work, and admin traffic is
329 357 // enough to run a one-time backfill promptly.
330 358 add_action('admin_init', [self::class, 'maybe_backfill_icon_sizes']);
331 359 }
360 +
361 + if (!self::$robots_sync_listener_registered) {
362 + self::$robots_sync_listener_registered = true;
363 +
364 + // A physical robots.txt bypasses PHP entirely, so composing the
365 + // Sitemap block at render time fixes the served output only on
366 + // sites with no file. Activating or deactivating a sitemap
367 + // contributor changes the set, and until #835 nothing rewrote the
368 + // file: the deactivated plugin's sitemap stayed advertised, serving
369 + // HTML to anything that followed it.
370 + add_action('activated_plugin', [self::class, 'flag_robots_txt_resync']);
371 + add_action('deactivated_plugin', [self::class, 'flag_robots_txt_resync']);
372 + add_action('init', [self::class, 'maybe_resync_robots_txt'], 99);
373 +
374 + // The sitemap index is a second static file listing the same
375 + // contributors, with its own rebuild path. #835 / #859 resynced
376 + // robots.txt only, so after Pro was deactivated the index kept
377 + // advertising news-sitemap.xml, which then served the home page
378 + // as HTML (#920).
379 + add_action('activated_plugin', [self::class, 'flag_sitemap_resync']);
380 + add_action('deactivated_plugin', [self::class, 'flag_sitemap_resync']);
381 + add_action('init', [self::class, 'maybe_resync_sitemap'], 99);
382 + }
332 383 }
333 384
334 385 /**
386 + * Note that the set of sitemap contributors may have changed.
387 + *
388 + * Deliberately unconditional about which plugin: a contributor is anything
389 + * hooking `thinkrank_additional_sitemaps`, which is resolved at runtime and
390 + * cannot be inspected for a plugin that is on its way out.
391 + *
392 + * The rewrite is not done here. `deactivated_plugin` fires inside the
393 + * request that deactivated it, while that plugin's filters are still
394 + * attached, so rendering now still sees the sitemap that is going away —
395 + * measured, not assumed: the first version of this fix wrote the
396 + * deactivated plugin's sitemap straight back into the file. The next
397 + * request has the real plugin set loaded, so the work waits for it.
398 + *
399 + * @since 2.14.0
400 + * @return void
401 + */
402 + public static function flag_robots_txt_resync(): void {
403 + if (!file_exists(ABSPATH . 'robots.txt')) {
404 + return;
405 + }
406 +
407 + update_option(self::ROBOTS_RESYNC_OPTION, 1, false);
408 + }
409 +
410 + /**
411 + * Rewrite the physical robots.txt once, on the request after a change.
412 + *
413 + * @since 2.14.0
414 + * @return void
415 + */
416 + public static function maybe_resync_robots_txt(): void {
417 + if (!get_option(self::ROBOTS_RESYNC_OPTION)) {
418 + return;
419 + }
420 +
421 + // Cleared first, so a render that fatals cannot retry on every request
422 + // for the rest of the site's life.
423 + delete_option(self::ROBOTS_RESYNC_OPTION);
424 +
425 + if (!file_exists(ABSPATH . 'robots.txt')) {
426 + return;
427 + }
428 +
429 + (new self())->sync_robots_txt_file();
430 + }
431 +
432 + /**
433 + * Note that the set of sitemap contributors may have changed.
434 + *
435 + * Unconditional, unlike flag_robots_txt_resync(): the sitemap files exist
436 + * whether or not robots.txt does. The rebuild waits for the next request
437 + * for the same reason as the robots.txt one, since `deactivated_plugin`
438 + * still runs with the outgoing plugin's `thinkrank_additional_sitemaps`
439 + * callback attached.
440 + *
441 + * @since 2.15.0
442 + * @return void
443 + */
444 + public static function flag_sitemap_resync(): void {
445 + update_option(self::SITEMAP_RESYNC_OPTION, 1, false);
446 + }
447 +
448 + /**
449 + * Queue a sitemap rebuild once, on the request after a contributor change.
450 + *
451 + * Goes through schedule_regeneration(), the debounced and lock-protected
452 + * path a sitemap settings save uses, so a burst of plugin changes (a bulk
453 + * deactivate, say) still produces one rebuild. That path also drops the
454 + * cached dynamic documents, so sites serving the sitemap from PHP drop the
455 + * entry as well.
456 + *
457 + * @since 2.15.0
458 + * @return void
459 + */
460 + public static function maybe_resync_sitemap(): void {
461 + if (!get_option(self::SITEMAP_RESYNC_OPTION)) {
462 + return;
463 + }
464 +
465 + // Cleared first, so a rebuild that fatals cannot be retried on every
466 + // request for the rest of the site's life.
467 + delete_option(self::SITEMAP_RESYNC_OPTION);
468 +
469 + $generator = new Sitemap_Generator(false);
470 + $settings = $generator->get_settings('site');
471 +
472 + // A disabled sitemap has no files to correct. Enabling it later builds
473 + // from the contributors present at that time.
474 + if (empty($settings['enabled'])) {
475 + return;
476 + }
477 +
478 + $generator->schedule_regeneration();
479 + }
480 +
481 + /**
335 482 * Save settings, then refresh what a new canonical scheme invalidates.
336 483 *
337 484 * The static sitemap files are written with the scheme in force when they
338 485 * were built, and nothing else rebuilds them until a post or term changes.
@@ -508,11 +655,12 @@
508 655 * Attachment ID behind a configured icon URL, or 0 when it is not ours.
509 656 *
510 657 * attachment_url_to_postid() matches _wp_attached_file, which holds the
511 658 * ORIGINAL upload path, so the URL of a generated derivative
512 - * (`logo-512.png`) returns 0 — and that is exactly what the media picker
513 - * hands back when the user chooses a size. Strip the dimension suffix and
514 - * try the original once.
659 + * (`logo-512x512.png`) returns 0 — and that is exactly what the media
660 + * picker hands back when the user chooses a size. Attachment_Lookup falls
661 + * back to the original behind it; the fallback started here and moved
662 + * there when every other image lookup turned out to need it (#847).
515 663 *
516 664 * Shared with SEO_Manager's site-icon filter so both sides of the feature
517 665 * agree on which attachment a configured URL means.
518 666 *
@@ -521,21 +669,9 @@
521 669 * @param string $url Configured icon URL.
522 670 * @return int Attachment ID, or 0.
523 671 */
524 672 public static function icon_attachment_id(string $url): int {
525 - $attachment_id = (int) attachment_url_to_postid($url);
526 -
527 - if ($attachment_id) {
528 - return $attachment_id;
529 - }
530 -
531 - $original = preg_replace('/-\d+x\d+(?=\.[a-zA-Z0-9]+$)/', '', $url);
532 -
533 - if (is_string($original) && $original !== $url) {
534 - return (int) attachment_url_to_postid($original);
535 - }
536 -
537 - return 0;
673 + return Attachment_Lookup::id_from_url($url);
538 674 }
539 675
540 676 /**
541 677 * Which ICON_SIZES derivatives this attachment still needs.
@@ -825,9 +961,20 @@
825 961 // here rather than stored: the textarea holds the user's body, with
826 962 // the fenced block stripped out of every read and re-applied on every
827 963 // render. A site-wide block already disallows everyone, so adding the
828 964 // per-agent group there would be noise restating the same refusal.
965 + // Composed here rather than read from storage, for the same reason as
966 + // the AI block below: the set of sitemaps an install publishes is a
967 + // runtime fact. `robots_txt_content` is a snapshot of it taken at the
968 + // last save, and nothing invalidated that snapshot, so deactivating a
969 + // sitemap provider left its URL advertised and serving HTML (#835).
970 + // Composing it on every render means the advertisement agrees with what
971 + // the install publishes, in both directions, with no cache to expire.
829 972 if (!$fully_blocked) {
973 + $body = $this->apply_sitemap_block($body);
974 + }
975 +
976 + if (!$fully_blocked) {
830 977 $body = $this->apply_ai_crawler_block($body, $settings);
831 978 }
832 979
833 980 if ($body === '') {
@@ -837,8 +984,87 @@
837 984 return $this->robots_txt_header() . $body . "\n";
838 985 }
839 986
840 987 /**
988 + * Replace the generated Sitemap block with the one this install publishes.
989 + *
990 + * @since 2.14.0
991 + * @param string $body Robots.txt body, without the header.
992 + * @return string
993 + */
994 + private function apply_sitemap_block(string $body): string {
995 + $stripped = $this->strip_generated_sitemap_block($body);
996 + $urls = $this->get_sitemap_urls_for_robots();
997 +
998 + if (empty($urls)) {
999 + return $stripped;
1000 + }
1001 +
1002 + $block = '';
1003 + foreach ($urls as $url) {
1004 + $block .= 'Sitemap: ' . $url . "\n";
1005 + }
1006 +
1007 + if ('' === trim($stripped)) {
1008 + return trim($block);
1009 + }
1010 +
1011 + // The grammar build_robots_txt_content() writes: one blank line before
1012 + // the block, none inside it. A blank line terminates a record in the
1013 + // robots.txt grammar, so a line between every directive is invalid.
1014 + return rtrim($stripped) . "\n\n" . trim($block);
1015 + }
1016 +
1017 + /**
1018 + * Remove the plugin-written Sitemap block from a stored body.
1019 + *
1020 + * Only the trailing run of `Sitemap:` lines is removed, which is the exact
1021 + * shape `build_robots_txt_content()` writes: a blank line, then nothing but
1022 + * `Sitemap:` lines to the end of the body. A `Sitemap:` line anywhere else
1023 + * was typed by the site owner and is left exactly where they put it, which
1024 + * is why this cannot simply strip every matching line.
1025 + *
1026 + * @since 2.14.0
1027 + * @param string $body Robots.txt body.
1028 + * @return string
1029 + */
1030 + private function strip_generated_sitemap_block(string $body): string {
1031 + $lines = preg_split('/\R/', $body);
1032 +
1033 + if (!is_array($lines)) {
1034 + return $body;
1035 + }
1036 +
1037 + $cut = count($lines);
1038 +
1039 + // Walk back over the trailing block: sitemap lines, and the blank lines
1040 + // that separate or pad it. Anything else ends the block.
1041 + for ($i = count($lines) - 1; $i >= 0; $i--) {
1042 + $line = trim($lines[$i]);
1043 +
1044 + if ('' === $line) {
1045 + $cut = $i;
1046 + continue;
1047 + }
1048 +
1049 + if (0 === stripos($line, 'sitemap:')) {
1050 + $cut = $i;
1051 + continue;
1052 + }
1053 +
1054 + break;
1055 + }
1056 +
1057 + if ($cut >= count($lines)) {
1058 + return $body;
1059 + }
1060 +
1061 + // Nothing but sitemap lines in the whole body means there is no owner
1062 + // content to keep.
1063 + return rtrim(implode("\n", array_slice($lines, 0, $cut)));
1064 + }
1065 +
1066 + /**
841 1067 * Resolve the robots.txt actually served to crawlers, with its origin.
842 1068 *
843 1069 * Lets an API/MCP consumer see the effective output without crawling the
844 1070 * URL. Mirrors serving precedence: a physical robots.txt in the web root is
@@ -1410,9 +1636,9 @@
1410 1636 $optimization['suggestions'][] = 'Add a site logo for better branding and professional appearance';
1411 1637 $optimization['score'] -= 20;
1412 1638 } else {
1413 1639 // Validate logo URL and dimensions
1414 - if (!filter_var($logo_url, FILTER_VALIDATE_URL)) {
1640 + if (!\ThinkRank\Core\Url_Validator::is_http_url($logo_url)) {
1415 1641 $optimization['warnings'][] = 'Logo URL format is invalid';
1416 1642 $optimization['score'] -= 15;
1417 1643 }
1418 1644 }
@@ -1431,14 +1657,17 @@
1431 1657 $optimization['score'] -= 10;
1432 1658 }
1433 1659
1434 1660 // Additional logo analysis for local images
1435 - if (!empty($logo_url) && filter_var($logo_url, FILTER_VALIDATE_URL)) {
1436 - $attachment_id = attachment_url_to_postid($logo_url);
1661 + if (!empty($logo_url) && \ThinkRank\Core\Url_Validator::is_http_url($logo_url)) {
1662 + $attachment_id = Attachment_Lookup::id_from_url($logo_url);
1437 1663 if ($attachment_id) {
1438 1664 $image_meta = wp_get_attachment_metadata($attachment_id);
1439 - $width = isset($image_meta['width']) ? (int) $image_meta['width'] : 0;
1440 - $height = isset($image_meta['height']) ? (int) $image_meta['height'] : 0;
1665 + // The configured file's own size — a logo picked at a generated
1666 + // size is not as large as the upload behind it.
1667 + $logo_file = Attachment_Lookup::describe($attachment_id, $logo_url);
1668 + $width = $logo_file['width'];
1669 + $height = $logo_file['height'];
1441 1670
1442 1671 // SVG logos store 0x0 metadata — no dimension/ratio analysis
1443 1672 // is possible (and dividing by 0 is fatal).
1444 1673 if ($image_meta && $width > 0 && $height > 0) {
@@ -1916,12 +2145,37 @@
1916 2145 $validation['suggestions'][] = 'Consider making site description longer (120-160 characters)';
1917 2146 }
1918 2147 }
1919 2148
1920 - // Validate logo URL
1921 - if (isset($settings['logo_url']) && !empty($settings['logo_url'])) {
1922 - if (!filter_var($settings['logo_url'], FILTER_VALIDATE_URL)) {
1923 - $validation['errors'][] = 'Logo URL must be a valid URL';
2149 + // Image and link URLs. These are written into src and href
2150 + // attributes (the schema logo, the admin previews, the hero section),
2151 + // so only web URLs are accepted. is_valid() takes any scheme, and
2152 + // "javascript://%0Aalert(1)" passed it and was stored as
2153 + // "javascript://alert(1)" once sanitize_text_field() dropped the %0A.
2154 + // The logo and default social image must be absolute: they are
2155 + // published in schema and Open Graph, which require it. The others
2156 + // may also be a path on this site.
2157 + $url_fields = [
2158 + 'logo_url' => ['Logo URL', false],
2159 + 'default_social_image' => ['Default social image URL', false],
2160 + 'favicon_url' => ['Favicon URL', true],
2161 + 'apple_touch_icon_url' => ['Apple touch icon URL', true],
2162 + 'hero_background_image' => ['Hero background image URL', true],
2163 + 'hero_cta_url' => ['Call-to-action URL', true],
2164 + ];
2165 + foreach ($url_fields as $key => [$label, $allow_path]) {
2166 + if (!isset($settings[$key]) || '' === $settings[$key] || null === $settings[$key]) {
2167 + continue;
2168 + }
2169 +
2170 + $ok = $allow_path
2171 + ? \ThinkRank\Core\Url_Validator::is_http_url_or_path($settings[$key])
2172 + : \ThinkRank\Core\Url_Validator::is_http_url($settings[$key]);
2173 +
2174 + if (!$ok) {
2175 + $validation['errors'][] = $allow_path
2176 + ? sprintf('%s must be an http or https URL, or a path starting with /', $label)
2177 + : sprintf('%s must be an http or https URL', $label);
1924 2178 $validation['valid'] = false;
1925 2179 }
1926 2180 }
1927 2181
@@ -2359,9 +2613,9 @@
2359 2613 }
2360 2614
2361 2615 // CTA URL validation
2362 2616 if (!empty($settings['hero_cta_url'])) {
2363 - if (filter_var($settings['hero_cta_url'], FILTER_VALIDATE_URL) || strpos($settings['hero_cta_url'], '/') === 0) {
2617 + if (\ThinkRank\Core\Url_Validator::is_http_url_or_path($settings['hero_cta_url'])) {
2364 2618 $field_details[] = [
2365 2619 'field' => 'hero_cta_url',
2366 2620 'label' => 'Call-to-action URL is properly configured.',
2367 2621 'status' => 'valid',
@@ -2402,9 +2656,9 @@
2402 2656 }
2403 2657
2404 2658 // Site Logo validation (from Site Assets section)
2405 2659 if (!empty($settings['logo_url'])) {
2406 - if (filter_var($settings['logo_url'], FILTER_VALIDATE_URL)) {
2660 + if (\ThinkRank\Core\Url_Validator::is_http_url($settings['logo_url'])) {
2407 2661 $field_details[] = [
2408 2662 'field' => 'logo_url',
2409 2663 'label' => 'Site logo is properly configured.',
2410 2664 'status' => 'valid',
@@ -2914,8 +3168,10 @@
2914 3168 return [
2915 3169 // Title formats, one per context.
2916 3170 'homepage_title', 'post_title', 'page_title', 'category_title',
2917 3171 'tag_title', 'author_title', 'search_title', 'archive_title',
3172 + // The blog-index homepage's meta description (#897).
3173 + 'homepage_description',
2918 3174 // Breadcrumbs.
2919 3175 'breadcrumb_prefix', 'show_current_page', 'breadcrumb_use_seo_title',
2920 3176 // Identity, as written by the setup wizard and the importers.
2921 3177 'alternate_name', 'identity_type', 'represents',
@@ -3759,11 +4015,29 @@
3759 4015 }
3760 4016 }
3761 4017
3762 4018 if ($index_url !== '') {
3763 - // The index alone — it covers the children and, on a segmented
3764 - // install, the local business sitemap too.
3765 - return [$index_url];
4019 + // The index covers the children and, on a segmented install,
4020 + // the local business sitemap too.
4021 + //
4022 + // It does not cover a sitemap contributed through
4023 + // `thinkrank_additional_sitemaps`: the index is built by this
4024 + // plugin's own generator and never lists them. Returning the
4025 + // index alone therefore left a contributed sitemap with no
4026 + // discovery path at all — absent from robots.txt and absent
4027 + // from the index — so Pro's News sitemap was unreachable on any
4028 + // install with the index enabled, which is the default (#835).
4029 + $contributed = [];
4030 +
4031 + foreach (\ThinkRank\SEO\Sitemap_Generator::additional_sitemaps() as $path) {
4032 + $url = home_url($path);
4033 +
4034 + if ($url !== $index_url && !in_array($url, $contributed, true)) {
4035 + $contributed[] = $url;
4036 + }
4037 + }
4038 +
4039 + return array_merge([$index_url], $contributed);
3766 4040 }
3767 4041
3768 4042 // Fallback to default if no URLs found
3769 4043 if (empty($sitemap_urls)) {
@@ -3853,9 +4127,12 @@
3853 4127 $validation['warnings'][] = "Path '{$value}' should start with '/'";
3854 4128 }
3855 4129 break;
3856 4130 case 'sitemap':
3857 - if (!filter_var($value, FILTER_VALIDATE_URL)) {
4131 + // Url_Validator, not the raw PHP filter: on a site with an
4132 + // internationalised domain the site's own sitemap URL is
4133 + // non-ASCII and the raw filter refused it.
4134 + if (!\ThinkRank\Core\Url_Validator::is_valid($value)) {
3858 4135 $validation['errors'][] = "Invalid sitemap URL: {$value}";
3859 4136 $validation['valid'] = false;
3860 4137 }
3861 4138 break;
@@ -4254,25 +4531,27 @@
4254 4531 return $optimization;
4255 4532 }
4256 4533
4257 4534 // Validate URL
4258 - if (!filter_var($value, FILTER_VALIDATE_URL)) {
4259 - $optimization['validation']['errors'][] = "{$element} must be a valid URL";
4535 + if (!\ThinkRank\Core\Url_Validator::is_http_url($value)) {
4536 + $optimization['validation']['errors'][] = "{$element} must be an http or https URL";
4260 4537 $optimization['validation']['valid'] = false;
4261 4538 return $optimization;
4262 4539 }
4263 4540
4264 4541 // Check if it's a local image
4265 - $attachment_id = attachment_url_to_postid($value);
4542 + $attachment_id = Attachment_Lookup::id_from_url($value);
4266 4543 if ($attachment_id) {
4267 4544 $image_meta = wp_get_attachment_metadata($attachment_id);
4268 4545
4269 4546 if ($image_meta && isset($image_meta['width'], $image_meta['height'])) {
4270 - // Check recommended size
4547 + // Check recommended size, against the configured file itself
4548 + // rather than the upload it may have been generated from.
4271 4549 if (isset($config['recommended_size'])) {
4272 4550 [$rec_width, $rec_height] = explode('x', $config['recommended_size']);
4551 + $image_file = Attachment_Lookup::describe($attachment_id, $value);
4273 4552
4274 - if ((int) $image_meta['width'] !== (int) $rec_width || (int) $image_meta['height'] !== (int) $rec_height) {
4553 + if ($image_file['width'] !== (int) $rec_width || $image_file['height'] !== (int) $rec_height) {
4275 4554 $optimization['suggestions'][] = "Consider using {$config['recommended_size']} size for optimal {$element}";
4276 4555 }
4277 4556 }
4278 4557