PluginProbe
WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance / 4.7.0
WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance v4.7.0
4.7.0 4.6.1 4.6.0 4.5.5 4.5.4 4.5.3 4.5.2 3.2.20 3.2.21 3.2.22 3.2.3 3.2.5 3.2.6 3.2.7 3.2.9 3.3.0 3.3.1 3.3.2 3.4.0 3.4.1 3.4.2 3.5.0 3.6.0 3.7.0 3.7.1 All 111 releases
← All changes | minify/class-wp-optimize-minify-print.php +20 -18 3.4.1 → 4.7.0 View file →
@@ -16,10 +16,10 @@
16 16 */
17 17 public static function async_script($href, $print = true) {
18 18 $wpo_minify_options = wp_optimize_minify_config()->get();
19 19 $tag = '<script>' . "\n";
20 - $user_agent = isset($_SERVER['HTTP_USER_AGENT']) ? $_SERVER['HTTP_USER_AGENT'] : '';
21 - $tag .= 'var wpo_server_info_js = ' . json_encode(array("user_agent" => $user_agent)) . "\n";
20 + $user_agent = isset($_SERVER['HTTP_USER_AGENT']) ? sanitize_text_field(wp_unslash($_SERVER['HTTP_USER_AGENT'])) : '';
21 + $tag .= 'var wpo_server_info_js = ' . wp_json_encode(array("user_agent" => $user_agent)) . "\n";
22 22
23 23 $exclude_js_from_page_speed_tools = $wpo_minify_options['exclude_js_from_page_speed_tools'];
24 24 $enable_defer_js = $wpo_minify_options['enable_defer_js'];
25 25 $is_conditional_loading = $exclude_js_from_page_speed_tools && 'all' !== $enable_defer_js;
@@ -32,9 +32,9 @@
32 32 }
33 33 $tag .= '</script>' . "\n";
34 34
35 35 if ($print) {
36 - echo $tag;
36 + echo $tag; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Output is already escaped
37 37 } else {
38 38 return $tag;
39 39 }
40 40 }
@@ -46,13 +46,15 @@
46 46 * @param string $media
47 47 * @return void
48 48 */
49 49 public static function async_style($href, $media = 'all') {
50 - echo '<link rel="preload" href="'.$href.'" as="style" media="'.$media.'" onload="this.onload=null;this.rel=\'stylesheet\'">' . "\n";
50 + // phpcs:disable WordPress.WP.EnqueuedResources.NonEnqueuedStylesheet -- Not applicable for this function
51 + echo '<link rel="preload" href="'.esc_url($href).'" as="style" media="'.esc_attr($media).'" onload="this.onload=null;this.rel=\'stylesheet\'">' . "\n";
51 52 // fix for firefox not supporting preload
52 - echo '<link rel="stylesheet" href="'.$href.'" media="'.$media.'">' . "\n";
53 - echo '<noscript><link rel="stylesheet" href="'.$href.'" media="'.$media.'"></noscript>' . "\n";
54 - echo '<!--[if IE]><link rel="stylesheet" href="'.$href.'" media="'.$media.'"><![endif]-->' . "\n";
53 + echo '<link rel="stylesheet" href="'.esc_url($href).'" media="'.esc_attr($media).'">' . "\n";
54 + echo '<noscript><link rel="stylesheet" href="'.esc_url($href).'" media="'.esc_attr($media).'"></noscript>' . "\n";
55 + echo '<!--[if IE]><link rel="stylesheet" href="'.esc_url($href).'" media="'.esc_attr($media).'"><![endif]-->' . "\n";
56 + // phpcs:enable
55 57 }
56 58
57 59 /**
58 60 * Print a style that will be loaded by JS
@@ -64,10 +66,10 @@
64 66 $wpo_minify_options = wp_optimize_minify_config()->get();
65 67 // make a stylesheet, hide from PageSpeedIndex
66 68 $cssguid = 'wpo_min'.hash('adler32', $href);
67 69 $tag = '<script>' . "\n";
68 - $user_agent = isset($_SERVER['HTTP_USER_AGENT']) ? $_SERVER['HTTP_USER_AGENT'] : '';
69 - $tag .= 'var wpo_server_info_css = ' . json_encode(array("user_agent" => $user_agent)) . "\n";
70 + $user_agent = isset($_SERVER['HTTP_USER_AGENT']) ? sanitize_text_field(wp_unslash($_SERVER['HTTP_USER_AGENT'])) : '';
71 + $tag .= 'var wpo_server_info_css = ' . wp_json_encode(array("user_agent" => $user_agent)) . "\n";
70 72
71 73 $exclude_css_from_page_speed_tools = $wpo_minify_options['exclude_css_from_page_speed_tools'];
72 74 if ($exclude_css_from_page_speed_tools) {
73 75 $tag .= 'if (!(navigator.userAgent + " " + wpo_server_info_css.user_agent).match(/'.implode('|', $wpo_minify_options['ualist']).'/i)){' . "\n";
@@ -76,9 +78,9 @@
76 78 if ($exclude_css_from_page_speed_tools) {
77 79 $tag .= '}';
78 80 }
79 81 $tag .= '</script>' . "\n";
80 - echo $tag;
82 + echo $tag; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Output is already escaped
81 83 }
82 84
83 85 /**
84 86 * Inline a single style
@@ -96,9 +98,9 @@
96 98 $json = WP_Optimize_Minify_Cache_Functions::get_transient($tkey);
97 99 if (false === $json) {
98 100 $json = WP_Optimize_Minify_Functions::download_and_minify($href, null, $wpo_minify_options['enable_css_minification'], 'css', $handle);
99 101 if ($wpo_minify_options['debug']) {
100 - echo "<!-- wpo_min DEBUG: Uncached file processing now for $href -->" . "\n";
102 + echo "<!-- wpo_min DEBUG: Uncached file processing now for " . esc_html($href) . " -->" . "\n";
101 103 }
102 104 WP_Optimize_Minify_Cache_Functions::set_transient($tkey, $json);
103 105 }
104 106
@@ -109,11 +111,11 @@
109 111 // https://developers.google.com/web/updates/2016/02/font-display
110 112 $res['code'] = str_ireplace('font-style:normal;', 'font-display:block;font-style:normal;', $res['code']);
111 113
112 114 // inline css or fail
113 - if (false != $res['status']) {
115 + if ($res['status']) {
114 116 echo '<style type="text/css" media="all">' . "\n";
115 - echo $res['code'] . "\n";
117 + echo $res['code'] . "\n"; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- This is already escaped
116 118 echo '</style>' . "\n";
117 119 return true;
118 120 } else {
119 121 return false;
@@ -126,9 +128,9 @@
126 128 * @param string $href
127 129 * @return void
128 130 */
129 131 public static function style($href) {
130 - echo '<link rel="stylesheet" href="'.$href.'" media="all">' . "\n";
132 + echo '<link rel="stylesheet" href="'.esc_url($href).'" media="all">' . "\n"; // phpcs:ignore WordPress.WP.EnqueuedResources.NonEnqueuedStylesheet -- Not applicable here
131 133 }
132 134
133 135 /**
134 136 * Write header
@@ -146,13 +148,13 @@
146 148 * Write CSS
147 149 *
148 150 * @param string $file
149 151 * @param string $code
150 - * @param string $log
152 + * @param array $log
151 153 * @return void
152 154 */
153 155 public static function write_combined_asset($file, $code, $log) {
154 - file_put_contents($file.'.json', json_encode($log));
156 + file_put_contents($file.'.json', wp_json_encode($log));
155 157 file_put_contents($file, $code);
156 158 // permissions
157 159 WP_Optimize_Minify_Cache_Functions::fix_permission_bits($file.'.json');
158 160 WP_Optimize_Minify_Cache_Functions::fix_permission_bits($file);
@@ -175,9 +177,9 @@
175 177 */
176 178 public static function add_load_async() {
177 179 $min_or_not_internal = WP_Optimize()->get_min_or_not_internal_string();
178 180 $contents = file_get_contents(trailingslashit(WPO_PLUGIN_MAIN_PATH) . "js/loadAsync$min_or_not_internal.js");
179 - echo "<script>$contents</script>\n";
181 + echo "<script>$contents</script>\n"; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Output is already escaped
180 182 }
181 183
182 184 /**
183 185 * Defer CSS globally from the header (order matters)
@@ -187,7 +189,7 @@
187 189 */
188 190 public static function add_load_css() {
189 191 $min_or_not_internal = WP_Optimize()->get_min_or_not_internal_string();
190 192 $contents = file_get_contents(trailingslashit(WPO_PLUGIN_MAIN_PATH) . "js/loadCSS$min_or_not_internal.js");
191 - echo "<script>$contents</script>" . "\n";
193 + echo "<script>$contents</script>" . "\n"; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- Output is already escaped
192 194 }
193 195 }