| @@ -38,9 +38,9 @@ | ||
| 38 | 38 | * @return array|mixed |
| 39 | 39 | */ |
| 40 | 40 | private function get_api_biggopties_data() { |
| 41 | 41 | // API endpoint for biggopties - you can change this to your actual endpoint |
| 42 | - $api_url = 'https://api.sigmative.io/prod/store/api/biggopti/api-data-records'; | |
| 42 | + $api_url = ''; | |
| 43 | 43 | |
| 44 | 44 | $response = wp_remote_get($api_url, [ |
| 45 | 45 | 'timeout' => 30, |
| 46 | 46 | 'headers' => [ |
| @@ -203,13 +203,8 @@ | ||
| 203 | 203 | */ |
| 204 | 204 | private function render_api_biggopti($biggopti) { |
| 205 | 205 | ob_start(); |
| 206 | 206 | |
| 207 | - // Add custom CSS if provided | |
| 208 | - if (isset($biggopti->custom_css) && !empty($biggopti->custom_css)) { | |
| 209 | - echo '<style>' . wp_kses_post($biggopti->custom_css) . '</style>'; | |
| 210 | - } | |
| 211 | - | |
| 212 | 207 | // Prepare background styles |
| 213 | 208 | $background_style = ''; |
| 214 | 209 | $wrapper_classes = 'bdt-biggopti-wrapper'; |
| 215 | 210 | |
| @@ -296,9 +291,9 @@ | ||
| 296 | 291 | /** |
| 297 | 292 | * AJAX: Build and return API biggopties HTML for dynamic injection |
| 298 | 293 | */ |
| 299 | 294 | public function ajax_fetch_api_biggopties() { |
| 300 | - $nonce = isset($_POST['_wpnonce']) ? sanitize_text_field($_POST['_wpnonce']) : ''; | |
| 295 | + $nonce = isset($_POST['_wpnonce']) ? sanitize_text_field(wp_unslash($_POST['_wpnonce'])) : ''; | |
| 301 | 296 | if (!wp_verify_nonce($nonce, 'ultimate-post-kit')) { |
| 302 | 297 | wp_send_json_error([ 'message' => 'invalid_nonce' ]); |
| 303 | 298 | } |
| 304 | 299 | |
| @@ -306,9 +301,9 @@ | ||
| 306 | 301 | wp_send_json_error([ 'message' => 'forbidden' ]); |
| 307 | 302 | } |
| 308 | 303 | |
| 309 | 304 | // Don't show biggopties on plugin/theme install and upload pages |
| 310 | - $current_url = isset($_POST['current_url']) ? sanitize_text_field($_POST['current_url']) : ''; | |
| 305 | + $current_url = isset($_POST['current_url']) ? sanitize_text_field(wp_unslash($_POST['current_url'])) : ''; | |
| 311 | 306 | |
| 312 | 307 | if (!empty($current_url)) { |
| 313 | 308 | $excluded_patterns = [ |
| 314 | 309 | 'plugin-install.php', |
| @@ -363,12 +358,12 @@ | ||
| 363 | 358 | /** |
| 364 | 359 | * Dismiss Biggopti. |
| 365 | 360 | */ |
| 366 | 361 | public function dismiss() { |
| 367 | - $nonce = (isset($_POST['_wpnonce'])) ? sanitize_text_field($_POST['_wpnonce']) : ''; | |
| 368 | - $id = (isset($_POST['id'])) ? esc_attr($_POST['id']) : ''; | |
| 369 | - $time = (isset($_POST['time'])) ? esc_attr($_POST['time']) : ''; | |
| 370 | - $meta = (isset($_POST['meta'])) ? esc_attr($_POST['meta']) : ''; | |
| 362 | + $nonce = (isset($_POST['_wpnonce'])) ? sanitize_text_field(wp_unslash($_POST['_wpnonce'])) : ''; | |
| 363 | + $id = isset($_POST['id']) ? sanitize_text_field(wp_unslash($_POST['id'])) : ''; | |
| 364 | + $time = isset($_POST['time']) ? absint(wp_unslash($_POST['time'])) : 0; | |
| 365 | + $meta = isset($_POST['meta']) ? sanitize_text_field(wp_unslash($_POST['meta'])) : ''; | |
| 371 | 366 | |
| 372 | 367 | if ( ! wp_verify_nonce($nonce, 'ultimate-post-kit') ) { |
| 373 | 368 | wp_send_json_error(); |
| 374 | 369 | } |
| @@ -387,14 +382,14 @@ | ||
| 387 | 382 | } else { |
| 388 | 383 | set_transient($id, true, $time); |
| 389 | 384 | |
| 390 | 385 | // Also store in options table for persistence |
| 391 | - $dismissals_option = get_option('bdt_biggopti_dismissals', []); | |
| 386 | + $dismissals_option = get_option('bdtupk_biggopti_dismissals', []); | |
| 392 | 387 | $dismissals_option[$id] = [ |
| 393 | 388 | 'dismissed_at' => time(), |
| 394 | 389 | 'expires_at' => time() + intval($time), |
| 395 | 390 | ]; |
| 396 | - update_option('bdt_biggopti_dismissals', $dismissals_option, false); | |
| 391 | + update_option('bdtupk_biggopti_dismissals', $dismissals_option, false); | |
| 397 | 392 | } |
| 398 | 393 | |
| 399 | 394 | wp_send_json_success(); |
| 400 | 395 | } |
| @@ -466,9 +461,9 @@ | ||
| 466 | 461 | $expired = get_transient($biggopti_id); |
| 467 | 462 | |
| 468 | 463 | // If transient not found, check options table for persistent dismissal |
| 469 | 464 | if (false === $expired || empty($expired)) { |
| 470 | - $dismissals_option = get_option('bdt_biggopti_dismissals', []); | |
| 465 | + $dismissals_option = get_option('bdtupk_biggopti_dismissals', []); | |
| 471 | 466 | if (isset($dismissals_option[$biggopti_id])) { |
| 472 | 467 | $dismissal = $dismissals_option[$biggopti_id]; |
| 473 | 468 | // Check if dismissal is still valid (not expired) |
| 474 | 469 | if (isset($dismissal['expires_at']) && time() < $dismissal['expires_at']) { |
| @@ -475,9 +470,9 @@ | ||
| 475 | 470 | $expired = true; |
| 476 | 471 | } else { |
| 477 | 472 | // Clean up expired dismissal from options |
| 478 | 473 | unset($dismissals_option[$biggopti_id]); |
| 479 | - update_option('bdt_biggopti_dismissals', $dismissals_option, false); | |
| 474 | + update_option('bdtupk_biggopti_dismissals', $dismissals_option, false); | |
| 480 | 475 | } |
| 481 | 476 | } |
| 482 | 477 | } |
| 483 | 478 | } |