| @@ -6,15 +6,24 @@ | ||
| 6 | 6 | if ( ! defined( 'ABSPATH' ) ) { |
| 7 | 7 | exit; |
| 8 | 8 | } |
| 9 | 9 | |
| 10 | -if ( ! function_exists( 'rc_dynamic_init' ) ) { | |
| 11 | - function rc_dynamic_init( $params ) { | |
| 10 | +if ( ! function_exists( 'ultimate_post_kit_reviews_init' ) ) { | |
| 11 | + function ultimate_post_kit_reviews_init( $params ) { | |
| 12 | 12 | |
| 13 | + // is_admin() is also true on admin-ajax.php, which fires admin_init before any | |
| 14 | + // authentication, so without this the SDK's constructor (and its option writes) | |
| 15 | + // would run for anonymous callers. Logged-in requests must still reach it during | |
| 16 | + // AJAX, because the constructor is what registers this SDK's own ajax handlers. | |
| 17 | + if ( ! is_user_logged_in() ) { | |
| 18 | + return; | |
| 19 | + } | |
| 20 | + | |
| 13 | 21 | if ( is_admin() ) : |
| 14 | 22 | |
| 15 | 23 | $menu_slug = isset( $params['menu']['slug'] ) ? $params['menu']['slug'] : false; |
| 16 | - $current_page = isset( $_GET['page'] ) ? $_GET['page'] : false; | |
| 24 | + // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- read-only check of the current admin page slug for display routing, no form data processed. | |
| 25 | + $current_page = isset( $_GET['page'] ) ? sanitize_text_field( wp_unslash( $_GET['page'] ) ) : false; | |
| 17 | 26 | |
| 18 | 27 | /** |
| 19 | 28 | * Attach SDK to current page |
| 20 | 29 | */ |
| @@ -24,11 +33,9 @@ | ||
| 24 | 33 | /** |
| 25 | 34 | * Include SDK |
| 26 | 35 | */ |
| 27 | 36 | require_once dirname( __FILE__ ) . '/notice.php'; |
| 28 | - if ( function_exists( 'rc_sdk_automate' ) ) { | |
| 29 | - rc_sdk_automate( $params ); | |
| 30 | - } | |
| 37 | + ultimate_post_kit_reviews_automate( $params ); | |
| 31 | 38 | |
| 32 | 39 | endif; |
| 33 | 40 | } |
| 34 | 41 | } |