| @@ -1,18 +1,21 @@ | ||
| 1 | 1 | <?php |
| 2 | 2 | |
| 3 | 3 | if (!defined('ABSPATH')) die('No direct access allowed'); |
| 4 | 4 | |
| 5 | -// handle better utf-8 and unicode encoding | |
| 5 | +// handle better utf-8 and Unicode encoding | |
| 6 | 6 | if (function_exists('mb_internal_encoding')) { |
| 7 | 7 | mb_internal_encoding('UTF-8'); |
| 8 | 8 | } |
| 9 | 9 | |
| 10 | 10 | // must have |
| 11 | +// phpcs:disable | |
| 12 | +// Squiz.PHP.DiscouragedFunctions.Discouraged -- Not applicable here | |
| 11 | 13 | ini_set('pcre.backtrack_limit', 5000000); |
| 12 | 14 | ini_set('pcre.recursion_limit', 5000000); |
| 15 | +// phpcs:enable | |
| 13 | 16 | |
| 14 | -use MatthiasMullie\Minify; // phpcs:ignore PHPCompatibility.Keywords.NewKeywords.t_useFound, PHPCompatibility.LanguageConstructs.NewLanguageConstructs.t_ns_separatorFound | |
| 17 | +use MatthiasMullie\Minify; | |
| 15 | 18 | |
| 16 | 19 | class WP_Optimize_Minify_Functions { |
| 17 | 20 | |
| 18 | 21 | /** |
| @@ -55,9 +58,9 @@ | ||
| 55 | 58 | $ret = false; |
| 56 | 59 | foreach ($locations as $l) { |
| 57 | 60 | $l = preg_replace('/^https?:\/\//i', '', trim($l)); |
| 58 | 61 | $l = trim(trim(preg_replace('/^www./', '', $l), '/')); |
| 59 | - if (stripos($src, $l) !== false && false === $ret) { | |
| 62 | + if (false !== stripos($src, $l) && false === $ret) { | |
| 60 | 63 | $ret = true; |
| 61 | 64 | } |
| 62 | 65 | } |
| 63 | 66 | |
| @@ -93,15 +96,15 @@ | ||
| 93 | 96 | // make sure wp_home doesn't have a forward slash |
| 94 | 97 | $wp_home = rtrim($wp_home, '/'); |
| 95 | 98 | |
| 96 | 99 | // apply some filters |
| 97 | - if (substr($hurl, 0, 2) === "//") { | |
| 100 | + if ("//" === substr($hurl, 0, 2)) { | |
| 98 | 101 | $hurl = $protocol.ltrim($hurl, "/"); |
| 99 | 102 | }//end if |
| 100 | - if (substr($hurl, 0, 4) === "http" && stripos($hurl, $wp_domain) === false) { | |
| 103 | + if ("http" === substr($hurl, 0, 4) && false === stripos($hurl, $wp_domain)) { | |
| 101 | 104 | return $hurl; |
| 102 | 105 | }//end if |
| 103 | - if (substr($hurl, 0, 4) !== "http" && stripos($hurl, $wp_domain) !== false) { | |
| 106 | + if ("http" !== substr($hurl, 0, 4) && false !== stripos($hurl, $wp_domain)) { | |
| 104 | 107 | $hurl = $wp_home.'/'.ltrim($hurl, "/"); |
| 105 | 108 | }//end if |
| 106 | 109 | |
| 107 | 110 | // prevent double forward slashes in the middle |
| @@ -122,9 +125,9 @@ | ||
| 122 | 125 | // protocol + home for relative paths |
| 123 | 126 | if ("/".WPINC === substr($hurl, 0, 12) |
| 124 | 127 | || "/wp-admin" === substr($hurl, 0, 9) |
| 125 | 128 | || "/$wp_content_folder" === substr($hurl, 0, 11) |
| 126 | - || 1 == $proceed | |
| 129 | + || 1 === $proceed | |
| 127 | 130 | ) { |
| 128 | 131 | $hurl = $wp_home.'/'.ltrim($hurl, "/"); |
| 129 | 132 | } |
| 130 | 133 | |
| @@ -131,12 +134,12 @@ | ||
| 131 | 134 | // make sure there is a protocol prefix as required |
| 132 | 135 | $hurl = $protocol.preg_replace('/^https?:\/\//i', '', $hurl); // enforce protocol |
| 133 | 136 | |
| 134 | 137 | // no query strings |
| 135 | - if (stripos($hurl, '.js?v') !== false) { | |
| 138 | + if (false !== stripos($hurl, '.js?v')) { | |
| 136 | 139 | $hurl = stristr($hurl, '.js?v', true).'.js'; |
| 137 | 140 | }//end if |
| 138 | - if (stripos($hurl, '.css?v') !== false) { | |
| 141 | + if (false !== stripos($hurl, '.css?v')) { | |
| 139 | 142 | $hurl = stristr($hurl, '.css?v', true).'.css'; |
| 140 | 143 | }//end if |
| 141 | 144 | |
| 142 | 145 | return $hurl; |
| @@ -155,18 +158,18 @@ | ||
| 155 | 158 | |
| 156 | 159 | if (substr($hurl, 0, strlen($wp_home)) === $wp_home) { |
| 157 | 160 | return true; |
| 158 | 161 | } |
| 159 | - if (stripos($hurl, $wp_home) !== false) { | |
| 162 | + if (false !== stripos($hurl, $wp_home)) { | |
| 160 | 163 | return true; |
| 161 | 164 | } |
| 162 | - if (isset($_SERVER['HTTP_HOST']) && stripos($hurl, preg_replace('/:\d+$/', '', $_SERVER['HTTP_HOST'])) !== false) { | |
| 165 | + if (isset($_SERVER['HTTP_HOST']) && false !== stripos($hurl, preg_replace('/:\d+$/', '', sanitize_text_field(wp_unslash($_SERVER['HTTP_HOST']))))) { | |
| 163 | 166 | return true; |
| 164 | 167 | } |
| 165 | - if (isset($_SERVER['SERVER_NAME']) && stripos($hurl, preg_replace('/:\d+$/', '', $_SERVER['SERVER_NAME'])) !== false) { | |
| 168 | + if (isset($_SERVER['SERVER_NAME']) && false !== stripos($hurl, preg_replace('/:\d+$/', '', sanitize_text_field(wp_unslash($_SERVER['SERVER_NAME']))))) { | |
| 166 | 169 | return true; |
| 167 | 170 | } |
| 168 | - if (isset($_SERVER['SERVER_ADDR']) && '::1' != $_SERVER['SERVER_ADDR'] && stripos($hurl, preg_replace('/:\d+$/', '', $_SERVER['SERVER_ADDR'])) !== false) { | |
| 171 | + if (isset($_SERVER['SERVER_ADDR']) && '::1' !== sanitize_text_field(wp_unslash($_SERVER['SERVER_ADDR'])) && false !== stripos($hurl, preg_replace('/:\d+$/', '', sanitize_text_field(wp_unslash($_SERVER['SERVER_ADDR']))))) { | |
| 169 | 172 | return true; |
| 170 | 173 | } |
| 171 | 174 | |
| 172 | 175 | // allow specific external urls to be merged |
| @@ -173,9 +176,9 @@ | ||
| 173 | 176 | if (null === $noxtra) { |
| 174 | 177 | $merge_allowed_urls = array_map('trim', explode("\n", $wpo_minify_options['merge_allowed_urls'])); |
| 175 | 178 | if (is_array($merge_allowed_urls) && strlen(implode($merge_allowed_urls)) > 0) { |
| 176 | 179 | foreach ($merge_allowed_urls as $e) { |
| 177 | - if (stripos($hurl, $e) !== false && !empty($e)) { | |
| 180 | + if (false !== stripos($hurl, $e) && !empty($e)) { | |
| 178 | 181 | return true; |
| 179 | 182 | } |
| 180 | 183 | } |
| 181 | 184 | } |
| @@ -208,9 +211,9 @@ | ||
| 208 | 211 | return false; |
| 209 | 212 | } |
| 210 | 213 | |
| 211 | 214 | /** |
| 212 | - * Check if selected url is point to already minifiled css/js file | |
| 215 | + * Check if selected url is point to already minified css/js file | |
| 213 | 216 | * |
| 214 | 217 | * @param string $url |
| 215 | 218 | * @return bool |
| 216 | 219 | */ |
| @@ -228,11 +231,11 @@ | ||
| 228 | 231 | * */ |
| 229 | 232 | private static function compat_urls($code) { |
| 230 | 233 | $wpo_minify_options = wp_optimize_minify_config()->get(); |
| 231 | 234 | $default_protocol = $wpo_minify_options['default_protocol']; |
| 232 | - if ('dynamic' == $default_protocol) { | |
| 233 | - if ((isset($_SERVER['HTTPS']) && ('on' == $_SERVER['HTTPS'] || 1 == $_SERVER['HTTPS'])) | |
| 234 | - || (isset($_SERVER['HTTP_X_FORWARDED_PROTO']) && 'https' == $_SERVER['HTTP_X_FORWARDED_PROTO']) | |
| 235 | + if ('dynamic' === $default_protocol) { | |
| 236 | + if ((isset($_SERVER['HTTPS']) && ('on' === $_SERVER['HTTPS'] || 1 === (int) $_SERVER['HTTPS'])) | |
| 237 | + || (isset($_SERVER['HTTP_X_FORWARDED_PROTO']) && 'https' === $_SERVER['HTTP_X_FORWARDED_PROTO']) | |
| 235 | 238 | ) { |
| 236 | 239 | $default_protocol = 'https://'; |
| 237 | 240 | } else { |
| 238 | 241 | $default_protocol = 'http://'; |
| @@ -275,9 +278,9 @@ | ||
| 275 | 278 | |
| 276 | 279 | // exclude minification on already minified files + jquery (because minification might break those) |
| 277 | 280 | $excl = array('jquery.js', '.min.js', '-min.js', '/uploads/fusion-scripts/', '/min/', '.packed.js', '/includes/builder/scripts/'); |
| 278 | 281 | foreach ($excl as $e) { |
| 279 | - if (stripos(basename($url), $e) !== false) { | |
| 282 | + if (false !== stripos(basename($url), $e)) { | |
| 280 | 283 | $enable_js_minification = false; |
| 281 | 284 | break; |
| 282 | 285 | } |
| 283 | 286 | } |
| @@ -300,9 +303,9 @@ | ||
| 300 | 303 | $js = preg_replace('/(\/\/\s*[#]\s*sourceMappingURL\s*[=]\s*)(.+)\s*/ui', '', $js); |
| 301 | 304 | |
| 302 | 305 | // needed when merging js files |
| 303 | 306 | $js = trim($js); |
| 304 | - if (substr($js, -1) != ';') { | |
| 307 | + if (';' !== substr($js, -1)) { | |
| 305 | 308 | $js = $js.';'; |
| 306 | 309 | } |
| 307 | 310 | if ($wpo_minify_options['debug']) { |
| 308 | 311 | $js = '/* info: ' . $url . ' */' . "\n" . $js; |
| @@ -314,9 +317,10 @@ | ||
| 314 | 317 | * @param string $js - The imported JS |
| 315 | 318 | * @param string $url - The imported url |
| 316 | 319 | * @param boolean $enable_js_minification - Whether to minify or not |
| 317 | 320 | */ |
| 318 | - return apply_filters('wpo_minify_get_js', $js . "\n", $url, $enable_js_minification); | |
| 321 | + $filtered_js = apply_filters('wpo_minify_get_js', $js . "\n", $url, $enable_js_minification); | |
| 322 | + return is_string($filtered_js) ? $filtered_js : $js; | |
| 319 | 323 | } |
| 320 | 324 | |
| 321 | 325 | /** |
| 322 | 326 | * Minify JS string with PHP Minify or YUI Compressors |
| @@ -328,9 +332,9 @@ | ||
| 328 | 332 | $js = apply_filters('wpo_minify_js_string', $js); |
| 329 | 333 | // PHP Minify from https://github.com/matthiasmullie/minify |
| 330 | 334 | $minifier = new Minify\JS($js); |
| 331 | 335 | $min = $minifier->minify(); |
| 332 | - if (false !== $min && (strlen(trim($js)) == strlen(trim($min)) || strlen(trim($min)) > 0)) { | |
| 336 | + if (false !== $min && (strlen(trim($js)) === strlen(trim($min)) || strlen(trim($min)) > 0)) { | |
| 333 | 337 | return self::compat_urls($min); |
| 334 | 338 | } |
| 335 | 339 | |
| 336 | 340 | // if we are here, something went wrong and minification didn't work |
| @@ -351,8 +355,19 @@ | ||
| 351 | 355 | return self::minify_js_string($js, true); |
| 352 | 356 | } |
| 353 | 357 | |
| 354 | 358 | /** |
| 359 | + * Check if the JS code contains import statements | |
| 360 | + * | |
| 361 | + * @param string $js | |
| 362 | + * @return boolean | |
| 363 | + */ | |
| 364 | + public static function has_js_import_statements($js) { | |
| 365 | + $js = preg_replace('/\/\/.*|\/\*[\s\S]*?\*\//', '', $js); // Remove comments to avoid false positives | |
| 366 | + return 1 === preg_match('/\bimport\b/', $js); | |
| 367 | + } | |
| 368 | + | |
| 369 | + /** | |
| 355 | 370 | * Functions, minify html |
| 356 | 371 | * |
| 357 | 372 | * @param string $html |
| 358 | 373 | * @return string |
| @@ -385,9 +400,9 @@ | ||
| 385 | 400 | * |
| 386 | 401 | * @return void |
| 387 | 402 | */ |
| 388 | 403 | public static function html_compression_start() { |
| 389 | - if (self::exclude_contents() == true) { | |
| 404 | + if (self::exclude_contents()) { | |
| 390 | 405 | return; |
| 391 | 406 | } |
| 392 | 407 | ob_start(array(__CLASS__, 'html_compression_finish')); |
| 393 | 408 | } |
| @@ -464,9 +479,10 @@ | ||
| 464 | 479 | * @param string $css - The imported CSS |
| 465 | 480 | * @param string $url - The imported url |
| 466 | 481 | * @param boolean $enable_css_minification - Whether to minify or not |
| 467 | 482 | */ |
| 468 | - return apply_filters('wpo_minify_get_css', $css, $url, $enable_css_minification); | |
| 483 | + $filtered_css = apply_filters('wpo_minify_get_css', $css, $url, $enable_css_minification); | |
| 484 | + return is_string($filtered_css) ? $filtered_css : $css; | |
| 469 | 485 | } |
| 470 | 486 | |
| 471 | 487 | /** |
| 472 | 488 | * Adds full path to relative url() rules |
| @@ -479,13 +495,13 @@ | ||
| 479 | 495 | $matches = array(); |
| 480 | 496 | preg_match_all("/url\(\s*['\"]?(?!data:)(?!http)(?![\/'\"])(.+?)['\"]?\s*\)/ui", $css, $matches); |
| 481 | 497 | foreach ($matches[1] as $a) { |
| 482 | 498 | $b = trim($a); |
| 483 | - if ($b != $a) { | |
| 499 | + if ($b !== $a) { | |
| 484 | 500 | $css = str_replace($a, $b, $css); |
| 485 | 501 | } |
| 486 | 502 | } |
| 487 | - return preg_replace("/url\(\s*['\"]?(?!data:)(?!http)(?![\/'\"])(.+?)['\"]?\s*\)/ui", "url(".dirname($url)."/$1)", $css); | |
| 503 | + return (string) preg_replace("/url\(\s*['\"]?(?!data:)(?!http)(?![\/'\"])(.+?)['\"]?\s*\)/ui", "url(".dirname($url)."/$1)", $css); | |
| 488 | 504 | } |
| 489 | 505 | |
| 490 | 506 | /** |
| 491 | 507 | * Include @import[ed] files - The @import statement can only be used at the top of a file, which breaks when merging everything. |
| @@ -510,9 +526,9 @@ | ||
| 510 | 526 | |
| 511 | 527 | // If $media_query contains print, and $remove_print_mediatypes is true, return empty string |
| 512 | 528 | if ($remove_print_mediatypes && false !== strpos($media_query, 'print') && apply_filters('wpo_minfy_remove_print_mediatypes_import', true, $url, $media_query, $matches[0], $file_url)) return ($debug ? '/*! Info: the import of "'.$url.'" was removed because the setting remove_print_mediatypes is enabled. */' : ''); |
| 513 | 529 | |
| 514 | - $purl = parse_url($url); | |
| 530 | + $purl = wp_parse_url($url); | |
| 515 | 531 | // If there's no host, the url is relative to $file_url, so prepend with the base url. |
| 516 | 532 | if (!isset($purl['host'])) { |
| 517 | 533 | $url = dirname($file_url).'/'.$url; |
| 518 | 534 | } |
| @@ -546,18 +562,20 @@ | ||
| 546 | 562 | |
| 547 | 563 | /** |
| 548 | 564 | * Download and cache css and js files |
| 549 | 565 | * |
| 550 | - * @param string $hurl | |
| 551 | - * @param string $inline | |
| 566 | + * @param ?string $hurl | |
| 567 | + * @param ?string $inline | |
| 552 | 568 | * @param boolean $enable_minification |
| 553 | 569 | * @param string $type |
| 554 | - * @param string $handle | |
| 570 | + * @param ?string $handle | |
| 571 | + * @param mixed $version | |
| 572 | + * | |
| 555 | 573 | * @return boolean|string |
| 556 | 574 | */ |
| 557 | 575 | public static function download_and_minify($hurl, $inline, $enable_minification, $type, $handle, $version = '') { |
| 558 | 576 | // must have |
| 559 | - if (is_null($hurl) || empty($hurl)) { | |
| 577 | + if (empty($hurl)) { | |
| 560 | 578 | return false; |
| 561 | 579 | } |
| 562 | 580 | if (!in_array($type, array('js', 'css'))) { |
| 563 | 581 | return false; |
| @@ -572,16 +590,16 @@ | ||
| 572 | 590 | 'url' => $print_url, |
| 573 | 591 | ); |
| 574 | 592 | |
| 575 | 593 | // defaults |
| 576 | - if (false != $enable_minification) { | |
| 594 | + if (false !== $enable_minification) { | |
| 577 | 595 | $enable_minification = true; |
| 578 | 596 | } |
| 579 | - if (is_null($inline) || empty($inline)) { | |
| 597 | + if (empty($inline)) { | |
| 580 | 598 | $inline = ''; |
| 581 | 599 | } |
| 582 | 600 | $print_handle = ''; |
| 583 | - if (is_null($handle) || empty($handle)) { | |
| 601 | + if (empty($handle)) { | |
| 584 | 602 | $handle = ''; |
| 585 | 603 | } else { |
| 586 | 604 | $print_handle = "[$handle]"; |
| 587 | 605 | } |
| @@ -605,12 +623,12 @@ | ||
| 605 | 623 | if ($wpo_minify_options['debug']) { |
| 606 | 624 | $log['debug'] = "$print_handle failed. Tried wp_remote_get and local file_get_contents."; |
| 607 | 625 | } |
| 608 | 626 | $return = array('request' => $dreq, 'log' => $log, 'code' => '', 'status' => false); |
| 609 | - return json_encode($return); | |
| 627 | + return wp_json_encode($return); | |
| 610 | 628 | } |
| 611 | 629 | |
| 612 | - if ('js' == $type) { | |
| 630 | + if ('js' === $type) { | |
| 613 | 631 | $code = self::get_js($hurl, $code, $enable_minification); |
| 614 | 632 | } else { |
| 615 | 633 | $code = self::get_css($hurl, $code.$inline, $enable_minification); |
| 616 | 634 | } |
| @@ -616,18 +634,18 @@ | ||
| 616 | 634 | } |
| 617 | 635 | |
| 618 | 636 | // log, save and return |
| 619 | 637 | if ($wpo_minify_options['debug']) { |
| 620 | - $version_msg = ('' != $version) ? "[Version: $version]" : ""; | |
| 638 | + $version_msg = ('' !== $version) ? "[Version: $version]" : ""; | |
| 621 | 639 | $log['debug'] = $print_handle . $version_msg . ' was '.('local' === $asset_content['method'] ? 'opened' : 'fetched').' from '.$hurl; |
| 622 | 640 | } |
| 623 | 641 | $log['success'] = true; |
| 624 | 642 | $return = array('request' => $dreq, 'log' => $log, 'code' => $code, 'status' => true); |
| 625 | - return json_encode($return); | |
| 643 | + return wp_json_encode($return); | |
| 626 | 644 | } |
| 627 | 645 | |
| 628 | 646 | /** |
| 629 | - * Get the content of an asset, wether local or remote | |
| 647 | + * Get the content of an asset, whether local or remote | |
| 630 | 648 | * |
| 631 | 649 | * @param string $url |
| 632 | 650 | * @return array |
| 633 | 651 | */ |
| @@ -633,14 +651,14 @@ | ||
| 633 | 651 | */ |
| 634 | 652 | public static function get_asset_content($url) { |
| 635 | 653 | |
| 636 | 654 | $wp_home = site_url(); |
| 637 | - $wp_domain = parse_url($wp_home, PHP_URL_HOST); | |
| 655 | + $wp_domain = wp_parse_url($wp_home, PHP_URL_HOST); | |
| 638 | 656 | // If the file is local. |
| 639 | 657 | if (false !== stripos($url, $wp_domain)) { |
| 640 | 658 | // default |
| 641 | 659 | $f = str_ireplace(rtrim($wp_home, '/'), rtrim(ABSPATH, '/'), $url); |
| 642 | - // failover when home_url != site_url | |
| 660 | + // fail over when home_url != site_url | |
| 643 | 661 | if (!file_exists($f)) { |
| 644 | 662 | $nhurl = str_ireplace(site_url(), home_url(), $url); |
| 645 | 663 | $f = str_ireplace(rtrim($wp_home, '/'), rtrim(ABSPATH, '/'), $nhurl); |
| 646 | 664 | } |
| @@ -647,9 +665,9 @@ | ||
| 647 | 665 | clearstatcache(); |
| 648 | 666 | if (file_exists($f)) { |
| 649 | 667 | $content = file_get_contents($f); |
| 650 | 668 | // check for php code, skip if found |
| 651 | - if ("<?php" != strtolower(substr($content, 0, 5)) && false === stripos($content, "<?php")) { | |
| 669 | + if ("<?php" !== strtolower(substr($content, 0, 5)) && false === stripos($content, "<?php")) { | |
| 652 | 670 | return array('content' => $content, 'method' => 'local'); |
| 653 | 671 | } |
| 654 | 672 | } |
| 655 | 673 | } |
| @@ -658,9 +676,9 @@ | ||
| 658 | 676 | // else, fallback to remote urls (or windows) |
| 659 | 677 | $content = self::download_remote($url); |
| 660 | 678 | if (false !== $content |
| 661 | 679 | && !empty($content) |
| 662 | - && strtolower(substr($content, 0, 9)) != "<!doctype" | |
| 680 | + && "<!doctype" !== strtolower(substr($content, 0, 9)) | |
| 663 | 681 | ) { |
| 664 | 682 | // check if we got HTML instead of js or css code |
| 665 | 683 | return array('content' => $content, 'method' => 'remote'); |
| 666 | 684 | } |
| @@ -666,12 +684,12 @@ | ||
| 666 | 684 | } |
| 667 | 685 | |
| 668 | 686 | |
| 669 | 687 | // fallback when home_url != site_url |
| 670 | - if (stripos($url, $wp_domain) !== false && home_url() != site_url()) { | |
| 688 | + if (false !== stripos($url, $wp_domain) && home_url() !== site_url()) { | |
| 671 | 689 | $nhurl = str_ireplace(site_url(), home_url(), $url); |
| 672 | 690 | $content = self::download_remote($nhurl); |
| 673 | - if (false !== $content && !empty($content) && '<!doctype' != strtolower(substr($content, 0, 9))) { | |
| 691 | + if (false !== $content && !empty($content) && '<!doctype' !== strtolower(substr($content, 0, 9))) { | |
| 674 | 692 | return array('content' => $content, 'method' => 'remote'); |
| 675 | 693 | } |
| 676 | 694 | } |
| 677 | 695 | |
| @@ -726,9 +744,9 @@ | ||
| 726 | 744 | * @param string $src |
| 727 | 745 | * @return string |
| 728 | 746 | */ |
| 729 | 747 | public static function remove_cssjs_ver($src) { |
| 730 | - if (stripos($src, '?ver=')) { | |
| 748 | + if (stripos($src, '?ver=') && self::is_already_minified($src)) { | |
| 731 | 749 | $src = remove_query_arg('ver', $src); |
| 732 | 750 | } |
| 733 | 751 | return $src; |
| 734 | 752 | } |
| @@ -733,8 +751,18 @@ | ||
| 733 | 751 | return $src; |
| 734 | 752 | } |
| 735 | 753 | |
| 736 | 754 | /** |
| 755 | + * Determine if the source is already minified (served from minify cache) | |
| 756 | + * | |
| 757 | + * @param string $src | |
| 758 | + * @return boolean | |
| 759 | + */ | |
| 760 | + public static function is_already_minified($src) { | |
| 761 | + return false !== strpos($src, 'cache/wpo-minify'); | |
| 762 | + } | |
| 763 | + | |
| 764 | + /** | |
| 737 | 765 | * Rewrite cache files to http, https or dynamic |
| 738 | 766 | * |
| 739 | 767 | * @param string $url |
| 740 | 768 | * @return string |
| @@ -750,12 +778,12 @@ | ||
| 750 | 778 | $cdn_url = $wpo_minify_options['cdn_url']; |
| 751 | 779 | $cdn_url = trim(trim(preg_replace('/^https?:\/\//i', '', trim($cdn_url, '/'))), '/'); |
| 752 | 780 | |
| 753 | 781 | // process cdn rewrite |
| 754 | - if (!empty($cdn_url) && self::is_local_domain($url) !== false) { | |
| 782 | + if (!empty($cdn_url) && false !== self::is_local_domain($url)) { | |
| 755 | 783 | |
| 756 | 784 | // for js files, we need to consider thew defer for insights option |
| 757 | - if (substr($url, -3) == '.js') { | |
| 785 | + if ('.js' === substr($url, -3)) { | |
| 758 | 786 | $async_using_js = 'all' === $wpo_minify_options['enable_defer_js'] && 'async_using_js' === $wpo_minify_options['defer_js_type']; |
| 759 | 787 | if (!$async_using_js |
| 760 | 788 | || $wpo_minify_options['cdn_force'] |
| 761 | 789 | ) { |
| @@ -766,11 +794,11 @@ | ||
| 766 | 794 | } |
| 767 | 795 | } |
| 768 | 796 | |
| 769 | 797 | // enforce protocol if needed |
| 770 | - if ('dynamic' == $default_protocol) { | |
| 771 | - if ((isset($_SERVER['HTTPS']) && ('on' == $_SERVER['HTTPS'] || 1 == $_SERVER['HTTPS'])) | |
| 772 | - || (isset($_SERVER['HTTP_X_FORWARDED_PROTO']) && 'https' == $_SERVER['HTTP_X_FORWARDED_PROTO']) | |
| 798 | + if ('dynamic' === $default_protocol) { | |
| 799 | + if ((isset($_SERVER['HTTPS']) && ('on' === $_SERVER['HTTPS'] || 1 === (int) $_SERVER['HTTPS'])) | |
| 800 | + || (isset($_SERVER['HTTP_X_FORWARDED_PROTO']) && 'https' === $_SERVER['HTTP_X_FORWARDED_PROTO']) | |
| 773 | 801 | ) { |
| 774 | 802 | $default_protocol = 'https://'; |
| 775 | 803 | } else { |
| 776 | 804 | $default_protocol = 'http://'; |
| @@ -792,9 +820,9 @@ | ||
| 792 | 820 | // prevent execution for specific urls |
| 793 | 821 | if (isset($_SERVER['REQUEST_URI']) && !empty($_SERVER['REQUEST_URI'])) { |
| 794 | 822 | $disable_on_url = array_filter(array_map('trim', explode("\n", get_option('wpo_min_disable_on_url', '')))); |
| 795 | 823 | foreach ($disable_on_url as $url) { |
| 796 | - if (parse_url($_SERVER['REQUEST_URI'], PHP_URL_PATH) == $url) { | |
| 824 | + if (wp_parse_url(esc_url_raw(wp_unslash($_SERVER['REQUEST_URI'])), PHP_URL_PATH) === $url) { | |
| 797 | 825 | return true; |
| 798 | 826 | } |
| 799 | 827 | } |
| 800 | 828 | } |
| @@ -799,11 +827,16 @@ | ||
| 799 | 827 | } |
| 800 | 828 | } |
| 801 | 829 | |
| 802 | 830 | // for compatibility, let's always skip the checkout page |
| 803 | - if (function_exists('is_checkout') && is_checkout() === true) { | |
| 831 | + if (function_exists('is_checkout') && true === is_checkout()) { | |
| 804 | 832 | return true; |
| 805 | 833 | } |
| 834 | + | |
| 835 | + if (isset($_SERVER['REQUEST_URI'])) { | |
| 836 | + $is_txt_extension = '.txt' === strtolower(substr(esc_url_raw(wp_unslash($_SERVER['REQUEST_URI'])), -4)); | |
| 837 | + $is_xml_extension = '.xml' === strtolower(substr(esc_url_raw(wp_unslash($_SERVER['REQUEST_URI'])), -4)); | |
| 838 | + } | |
| 806 | 839 | |
| 807 | 840 | // exclude processing here |
| 808 | 841 | if (is_feed() |
| 809 | 842 | || is_admin() |
| @@ -820,14 +853,16 @@ | ||
| 820 | 853 | || (defined('XMLRPC_REQUEST') && XMLRPC_REQUEST) |
| 821 | 854 | || (defined('SHORTINIT') && SHORTINIT) |
| 822 | 855 | || (defined('REST_REQUEST') && REST_REQUEST) |
| 823 | 856 | || (isset($_SERVER['REQUEST_METHOD']) && 'POST' === $_SERVER['REQUEST_METHOD']) |
| 824 | - || (isset($_SERVER['HTTP_X_REQUESTED_WITH']) && strtolower($_SERVER['HTTP_X_REQUESTED_WITH']) == 'xmlhttprequest') | |
| 825 | - || (isset($_SERVER['REQUEST_URI']) && (strtolower(substr($_SERVER['REQUEST_URI'], -4)) == '.txt' || strtolower(substr($_SERVER['REQUEST_URI'], -4)) == '.xml')) | |
| 857 | + || (isset($_SERVER['HTTP_X_REQUESTED_WITH']) && 'xmlhttprequest' === strtolower(sanitize_text_field(wp_unslash($_SERVER['HTTP_X_REQUESTED_WITH'])))) | |
| 858 | + || (isset($_SERVER['REQUEST_URI']) && ($is_txt_extension || $is_xml_extension)) | |
| 826 | 859 | ) { |
| 827 | 860 | return true; |
| 828 | 861 | } |
| 829 | 862 | |
| 863 | + // phpcs:disable | |
| 864 | + // WordPress.Security.NonceVerification.Recommended -- Using $_GET element only to compare, returns boolean | |
| 830 | 865 | // Thrive plugins and other post_types |
| 831 | 866 | $arr = array('tve_form_type', 'tve_lead_shortcode', 'tqb_splash'); |
| 832 | 867 | foreach ($arr as $a) { |
| 833 | 868 | if (isset($_GET['post_type']) && $a === $_GET['post_type']) { |
| @@ -841,9 +876,9 @@ | ||
| 841 | 876 | |
| 842 | 877 | if (is_array($_GET)) { |
| 843 | 878 | foreach ($_GET as $k => $v) { |
| 844 | 879 | if (is_string($v) && is_string($k)) { |
| 845 | - if (stripos($k, 'elementor') !== false || stripos($v, 'elementor') !== false) { | |
| 880 | + if (false !== stripos($k, 'elementor') || false !== stripos($v, 'elementor')) { | |
| 846 | 881 | return true; |
| 847 | 882 | } |
| 848 | 883 | } |
| 849 | 884 | } |
| @@ -870,13 +905,14 @@ | ||
| 870 | 905 | 'trp-edit-translation', |
| 871 | 906 | ); |
| 872 | 907 | return (bool) count(array_intersect($excluded_params, $get_params)); |
| 873 | 908 | } |
| 909 | + // phpcs:enable | |
| 874 | 910 | |
| 875 | 911 | /** |
| 876 | - * Wether to exclude the content or not from the minifying process. | |
| 912 | + * Whether to exclude the content or not from the minifying process. | |
| 877 | 913 | */ |
| 878 | - return apply_filters('wpo_minify_exclude_contents', false); | |
| 914 | + return (bool) apply_filters('wpo_minify_exclude_contents', false); | |
| 879 | 915 | } |
| 880 | 916 | |
| 881 | 917 | /** |
| 882 | 918 | * Get the default files which are ignored / excluded from processing |
| @@ -883,15 +919,9 @@ | ||
| 883 | 919 | * |
| 884 | 920 | * @return array |
| 885 | 921 | */ |
| 886 | 922 | public static function get_default_ignore() { |
| 887 | - /** | |
| 888 | - * Filters the default exclusions | |
| 889 | - * | |
| 890 | - * @param array The exclusions | |
| 891 | - * @return array | |
| 892 | - */ | |
| 893 | - return apply_filters('wp-optimize-minify-default-exclusions', array( | |
| 923 | + $default_exclusions = array( | |
| 894 | 924 | '/genericons.css', |
| 895 | 925 | '/Avada/assets/js/main.min.js', |
| 896 | 926 | '/woocommerce-product-search/js/product-search.js', |
| 897 | 927 | '/includes/builder/scripts/frontend-builder-scripts.js', |
| @@ -905,9 +935,17 @@ | ||
| 905 | 935 | 'elementor-admin-bar', |
| 906 | 936 | 'pdfjs-dist', |
| 907 | 937 | 'wordpress-popular-posts', |
| 908 | 938 | 'uploads/bb-plugin/cache', // Beaver builder page specific pages |
| 909 | - )); | |
| 939 | + ); | |
| 940 | + /** | |
| 941 | + * Filters the default exclusions | |
| 942 | + * | |
| 943 | + * @param array The exclusions | |
| 944 | + * @return array | |
| 945 | + */ | |
| 946 | + $filtered_exclusions = apply_filters('wp-optimize-minify-default-exclusions', $default_exclusions); | |
| 947 | + return is_array($filtered_exclusions) ? $filtered_exclusions : $default_exclusions; | |
| 910 | 948 | } |
| 911 | 949 | |
| 912 | 950 | /** |
| 913 | 951 | * Know files that should always be ignored |
| @@ -932,15 +970,9 @@ | ||
| 932 | 970 | * |
| 933 | 971 | * @return array |
| 934 | 972 | */ |
| 935 | 973 | public static function get_default_ie_blacklist() { |
| 936 | - /** | |
| 937 | - * Filters the default IE specific / blacklisted items | |
| 938 | - * | |
| 939 | - * @param array The blacklist | |
| 940 | - * @return array | |
| 941 | - */ | |
| 942 | - return apply_filters('wp-optimize-minify-blacklist', array( | |
| 974 | + $default_ie_blacklist = array( | |
| 943 | 975 | '/html5shiv.js', |
| 944 | 976 | '/html5shiv-printshiv.min.js', |
| 945 | 977 | '/excanvas.js', |
| 946 | 978 | '/avada-ie9.js', |
| @@ -960,9 +992,17 @@ | ||
| 960 | 992 | '/a.optnmstr.com/app/js/api.min.js', |
| 961 | 993 | '/pixelyoursite/js/public.js', |
| 962 | 994 | '/assets/js/wcdrip-drip.js', |
| 963 | 995 | '/instantpage.js', |
| 964 | - )); | |
| 996 | + ); | |
| 997 | + /** | |
| 998 | + * Filters the default IE specific / blacklisted items | |
| 999 | + * | |
| 1000 | + * @param array The blacklist | |
| 1001 | + * @return array | |
| 1002 | + */ | |
| 1003 | + $filtered_ie_blacklist = apply_filters('wp-optimize-minify-blacklist', $default_ie_blacklist); | |
| 1004 | + return is_array($filtered_ie_blacklist) ? $filtered_ie_blacklist : $default_ie_blacklist; | |
| 965 | 1005 | } |
| 966 | 1006 | |
| 967 | 1007 | /** |
| 968 | 1008 | * Get the files excluded for IE compatibility |
| @@ -989,9 +1029,9 @@ | ||
| 989 | 1029 | $blacklist[] = '/wpo_min/cache/'; |
| 990 | 1030 | |
| 991 | 1031 | // is the url on our list and return |
| 992 | 1032 | $res = self::in_arrayi($url, $blacklist); |
| 993 | - if (true == $res) { | |
| 1033 | + if ($res) { | |
| 994 | 1034 | return true; |
| 995 | 1035 | } else { |
| 996 | 1036 | return false; |
| 997 | 1037 | } |
| @@ -1000,19 +1040,19 @@ | ||
| 1000 | 1040 | /** |
| 1001 | 1041 | * Download function with fallback |
| 1002 | 1042 | * |
| 1003 | 1043 | * @param string $url |
| 1004 | - * @return boolean | |
| 1044 | + * @return boolean|string | |
| 1005 | 1045 | */ |
| 1006 | 1046 | public static function download_remote($url) { |
| 1007 | 1047 | |
| 1008 | 1048 | $args = array( |
| 1009 | - // info (needed for google fonts woff files + hinted fonts) as well as to bypass some security filters | |
| 1010 | - 'user-agent' => 'Mozilla/5.0 (Macintosh; Intel Mac OS X 11_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.81 Safari/537.36', | |
| 1049 | + // info (needed for Google fonts woff files + hinted fonts) as well as to bypass some security filters | |
| 1050 | + 'user-agent' => WP_Optimize_Utils::get_user_agent('gfont'), | |
| 1011 | 1051 | 'timeout' => 7 |
| 1012 | 1052 | ); |
| 1013 | 1053 | |
| 1014 | - // fetch via wordpress functions | |
| 1054 | + // fetch via WordPress functions | |
| 1015 | 1055 | $response = wp_remote_get( |
| 1016 | 1056 | $url, |
| 1017 | 1057 | /** |
| 1018 | 1058 | * Filters the arguments passed to wp_remote_get when downloading the scripts. |
| @@ -1024,9 +1064,9 @@ | ||
| 1024 | 1064 | apply_filters('wpo_minify_download_request_args', $args, $url) |
| 1025 | 1065 | ); |
| 1026 | 1066 | |
| 1027 | 1067 | $res_code = wp_remote_retrieve_response_code($response); |
| 1028 | - if (200 == $res_code) { | |
| 1068 | + if (200 === $res_code) { | |
| 1029 | 1069 | $data = wp_remote_retrieve_body($response); |
| 1030 | 1070 | if (strlen($data) > 1) { |
| 1031 | 1071 | return $data; |
| 1032 | 1072 | } |
| @@ -1050,25 +1090,25 @@ | ||
| 1050 | 1090 | return $script; |
| 1051 | 1091 | } |
| 1052 | 1092 | |
| 1053 | 1093 | /** |
| 1054 | - * Checks if an URL is a font-awesome resource (checks if it contains font-awesome or fontawesome) | |
| 1094 | + * Checks if URL is a font-awesome resource (checks if it contains font-awesome or fontawesome) | |
| 1055 | 1095 | * |
| 1056 | 1096 | * @param string $href |
| 1057 | 1097 | * @return boolean |
| 1058 | 1098 | */ |
| 1059 | 1099 | public static function is_font_awesome($href) { |
| 1060 | - return (boolean) preg_match('/font[-_]?awesome/i', $href); | |
| 1100 | + return (bool) preg_match('/font[-_]?awesome/i', $href); | |
| 1061 | 1101 | } |
| 1062 | 1102 | |
| 1063 | 1103 | /** |
| 1064 | - * Checks if an URL is a google font resource | |
| 1104 | + * Checks if URL is a Google font resource | |
| 1065 | 1105 | * |
| 1066 | 1106 | * @param string $href |
| 1067 | 1107 | * @return boolean |
| 1068 | 1108 | */ |
| 1069 | 1109 | public static function is_google_font($href) { |
| 1070 | - return 'fonts.googleapis.com' === strtolower(parse_url($href, PHP_URL_HOST)); | |
| 1110 | + return 'fonts.googleapis.com' === strtolower(wp_parse_url($href, PHP_URL_HOST)); | |
| 1071 | 1111 | } |
| 1072 | 1112 | |
| 1073 | 1113 | /** |
| 1074 | 1114 | * Get the content of an asset, whether local or remote |
| @@ -1123,14 +1163,14 @@ | ||
| 1123 | 1163 | * @return int|false |
| 1124 | 1164 | */ |
| 1125 | 1165 | public static function get_remote_file_size($url) { |
| 1126 | 1166 | $args = array( |
| 1127 | - // info (needed for google fonts woff files + hinted fonts) as well as to bypass some security filters | |
| 1128 | - 'user-agent' => 'Mozilla/5.0 (Macintosh; Intel Mac OS X 11_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.81 Safari/537.36', | |
| 1167 | + // info (needed for Google fonts woff files + hinted fonts) as well as to bypass some security filters | |
| 1168 | + 'user-agent' => WP_Optimize_Utils::get_user_agent('gfont'), | |
| 1129 | 1169 | 'timeout' => 7 |
| 1130 | 1170 | ); |
| 1131 | 1171 | |
| 1132 | - // fetch via wordpress functions | |
| 1172 | + // fetch via WordPress functions | |
| 1133 | 1173 | $response = wp_remote_get($url, $args); |
| 1134 | 1174 | |
| 1135 | 1175 | if (is_wp_error($response)) return false; |
| 1136 | 1176 | |
| @@ -1160,9 +1200,9 @@ | ||
| 1160 | 1200 | * @return string Fixed google fonts url |
| 1161 | 1201 | */ |
| 1162 | 1202 | public static function fix_flatsome_google_fonts_url($href) { |
| 1163 | 1203 | // Get query from $href |
| 1164 | - $query = parse_url($href, PHP_URL_QUERY); | |
| 1204 | + $query = wp_parse_url($href, PHP_URL_QUERY); | |
| 1165 | 1205 | $query_arr = explode('&', $query); |
| 1166 | 1206 | |
| 1167 | 1207 | // Separate 'family and display' arguments in query |
| 1168 | 1208 | $family = str_replace('family=', '', $query_arr[0]); |
| @@ -1185,12 +1225,12 @@ | ||
| 1185 | 1225 | |
| 1186 | 1226 | // Remove beginning '+' |
| 1187 | 1227 | $font = str_replace(',+', ',', $font_variant[0]); |
| 1188 | 1228 | |
| 1189 | - // Replace '-' with '+ | |
| 1229 | + // Replace '-' with '+' | |
| 1190 | 1230 | $font = str_replace(array('-', ' '), '+', $font); |
| 1191 | 1231 | |
| 1192 | - // Remove '"' or '%22' | |
| 1232 | + // Remove `"` or '%22' | |
| 1193 | 1233 | $font = str_replace(array('%22', '"'), '', $font); |
| 1194 | 1234 | $font_arr = explode(',', $font); |
| 1195 | 1235 | $font_arr = array_diff($font_arr, $system_fonts); |
| 1196 | 1236 | $variant = ''; |
| @@ -1218,10 +1258,12 @@ | ||
| 1218 | 1258 | $hurl = self::get_hurl($asset_src); |
| 1219 | 1259 | $abs_file_path = WP_Optimize_Utils::get_file_path($hurl); |
| 1220 | 1260 | if (empty($abs_file_path)) return ''; |
| 1221 | 1261 | |
| 1222 | - $modification_time = @filemtime($abs_file_path); // phpcs:ignore Generic.PHP.NoSilencedErrors.Discouraged -- Suppress E-Warning on failure | |
| 1223 | - return strval($modification_time); | |
| 1262 | + $modification_time = strval(@filemtime($abs_file_path)); // phpcs:ignore Generic.PHP.NoSilencedErrors.Discouraged -- Suppress E-Warning on failure | |
| 1263 | + $filtered_modification_time = apply_filters('wpo_minify_file_modification_time', $modification_time, $abs_file_path); | |
| 1264 | + | |
| 1265 | + return is_string($filtered_modification_time) ? $filtered_modification_time : $modification_time; | |
| 1224 | 1266 | } |
| 1225 | 1267 | |
| 1226 | 1268 | /** |
| 1227 | 1269 | * When BOM removed code is null (due to unrecognised character encoding), logs error message |
| @@ -1237,8 +1279,8 @@ | ||
| 1237 | 1279 | $message = "Minify: Could not process {$url}, it contains invalid characters. "; |
| 1238 | 1280 | if (false === $encoding) { |
| 1239 | 1281 | $message .= "Could not determine its character encoding."; |
| 1240 | 1282 | } |
| 1241 | - error_log($message); | |
| 1283 | + error_log($message); // phpcs:ignore WordPress.PHP.DevelopmentFunctions.error_log_error_log -- Using for debugging purpose | |
| 1242 | 1284 | } |
| 1243 | 1285 | } |
| 1244 | 1286 | } |