PluginProbe
Yoast SEO – Advanced SEO with real-time guidance and built-in AI / trunk
Yoast SEO – Advanced SEO with real-time guidance and built-in AI vtrunk
28.5 28.4 28.3 28.2 28.1 28.0 27.9 27.8 27.7 27.6 27.5 trunk 18.0 18.1 18.2 18.3 18.4 18.4.1 18.5 18.5.1 18.6 18.7 18.8 18.9 19.0 All 129 releases
← All changes | src/conditionals/admin/estimated-reading-time-conditional.php +14 -18 18.5.1 → trunk View file →
@@ -2,9 +2,8 @@
2 2
3 3 namespace Yoast\WP\SEO\Conditionals\Admin;
4 4
5 5 use Yoast\WP\SEO\Conditionals\Conditional;
6 -use Yoast\WP\SEO\Helpers\Input_Helper;
7 6
8 7 /**
9 8 * Conditional that is only when we want the Estimated Reading Time.
10 9 */
@@ -17,34 +16,27 @@
17 16 */
18 17 protected $post_conditional;
19 18
20 19 /**
21 - * The Input Helper.
22 - *
23 - * @var Input_Helper
24 - */
25 - protected $input_helper;
26 -
27 - /**
28 20 * Constructs the Estimated Reading Time Conditional.
29 21 *
30 22 * @param Post_Conditional $post_conditional The post conditional.
31 - * @param Input_Helper $input_helper The input helper.
32 23 */
33 - public function __construct( Post_Conditional $post_conditional, Input_Helper $input_helper ) {
24 + public function __construct( Post_Conditional $post_conditional ) {
34 25 $this->post_conditional = $post_conditional;
35 - $this->input_helper = $input_helper;
36 26 }
37 27
38 28 /**
39 - * Returns whether or not this conditional is met.
29 + * Returns whether this conditional is met.
40 30 *
41 - * @return bool Whether or not the conditional is met.
31 + * @return bool Whether the conditional is met.
42 32 */
43 33 public function is_met() {
34 + // phpcs:disable WordPress.Security.NonceVerification.Recommended,WordPress.Security.NonceVerification.Missing -- Reason: Nonce verification should not be done in a conditional but rather in the classes using the conditional.
44 35 // Check if we are in our Elementor ajax request (for saving).
45 - if ( \wp_doing_ajax() ) {
46 - $post_action = $this->input_helper->filter( \INPUT_POST, 'action', \FILTER_SANITIZE_STRING );
36 + if ( \wp_doing_ajax() && isset( $_POST['action'] ) && \is_string( $_POST['action'] ) ) {
37 + // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized -- Reason: We are only strictly comparing the variable.
38 + $post_action = \wp_unslash( $_POST['action'] );
47 39 if ( $post_action === 'wpseo_elementor_save' ) {
48 40 return true;
49 41 }
50 42 }
@@ -53,12 +45,16 @@
53 45 return false;
54 46 }
55 47
56 48 // We don't support Estimated Reading Time on the attachment post type.
57 - $post_id = (int) $this->input_helper->filter( \INPUT_GET, 'post', \FILTER_SANITIZE_NUMBER_INT );
58 - if ( \get_post_type( $post_id ) === 'attachment' ) {
59 - return false;
49 + if ( isset( $_GET['post'] ) && \is_string( $_GET['post'] ) ) {
50 + // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized -- Reason: We are casting to an integer.
51 + $post_id = (int) \wp_unslash( $_GET['post'] );
52 + if ( $post_id !== 0 && \get_post_type( $post_id ) === 'attachment' ) {
53 + return false;
54 + }
60 55 }
61 56
62 57 return true;
58 + // phpcs:enable WordPress.Security.NonceVerification.Recommended,WordPress.Security.NonceVerification.Missing
63 59 }
64 60 }