PluginProbe
The WP Remote WordPress Plugin / 4.74
The WP Remote WordPress Plugin v4.74
6.72 6.69 6.65 6.62 6.48 6.47 4.87 4.97 5.05 5.09 5.16 5.22 5.24 5.25 5.38 5.41 5.42 5.45 5.47 5.53 5.56 5.65 5.68 5.72 5.73 All 53 releases
← All changes | wp_admin.php +54 -117 6.624.74 View file →
@@ -24,9 +24,9 @@
24 24 }
25 25 }
26 26
27 27 function removeAdminNotices() {
28 - if (WPRHelper::getRawParam('REQUEST', 'page') === $this->bvinfo->plugname) {
28 + if (array_key_exists('page', $_REQUEST) && $_REQUEST['page'] == $this->bvinfo->plugname) {
29 29 remove_all_actions('admin_notices');
30 30 remove_all_actions('all_admin_notices');
31 31 }
32 32 }
@@ -33,47 +33,41 @@
33 33
34 34 public function initHandler() {
35 35 if (!current_user_can('activate_plugins'))
36 36 return;
37 - $bvnonce = WPRHelper::getRawParam('REQUEST', 'bvnonce');
38 - $blogvaultkey = WPRHelper::getRawParam('REQUEST', 'blogvaultkey');
39 - $blogvaultkey = $blogvaultkey ? WPRAccount::sanitizeKey($blogvaultkey) : "";
40 37
41 - if ($bvnonce && wp_verify_nonce($bvnonce, "bvnonce") &&
42 - $blogvaultkey && strlen($blogvaultkey) == 64 &&
43 - (WPRHelper::getRawParam('REQUEST', 'page') === $this->bvinfo->plugname)) {
44 - $keys = str_split($blogvaultkey, 32);
38 + if (array_key_exists('bvnonce', $_REQUEST) &&
39 + wp_verify_nonce($_REQUEST['bvnonce'], "bvnonce") &&
40 + array_key_exists('blogvaultkey', $_REQUEST) &&
41 + (strlen($_REQUEST['blogvaultkey']) == 64) &&
42 + (array_key_exists('page', $_REQUEST) &&
43 + $_REQUEST['page'] == $this->bvinfo->plugname)) {
44 + $keys = str_split($_REQUEST['blogvaultkey'], 32);
45 45 WPRAccount::addAccount($this->settings, $keys[0], $keys[1]);
46 -
47 - $location = WPRHelper::getStringParamSanitized('REQUEST', 'redirect', 'url');
48 - if ($location) {
46 + if (array_key_exists('redirect', $_REQUEST)) {
47 + $location = $_REQUEST['redirect'];
49 48 wp_redirect($this->bvinfo->appUrl()."/dash/redir?q=".urlencode($location));
50 49 exit();
51 50 }
52 51 }
53 -
54 52 if ($this->bvinfo->isActivateRedirectSet()) {
55 53 $this->settings->updateOption($this->bvinfo->plug_redirect, 'no');
56 54 ##ACTIVATEREDIRECTCODE##
57 - if (!wp_doing_ajax()) {
58 - wp_redirect($this->mainUrl());
59 - }
55 + wp_redirect($this->mainUrl());
60 56 }
61 57 }
62 58
63 59 public function wprsecAdminMenu($hook) {
64 - if ($hook === 'toplevel_page_wpremote' || WPRHelper::safePregMatch("/wpr_add_account$/", $hook) || WPRHelper::safePregMatch("/wpr_account_details$/", $hook)) {
65 - wp_enqueue_style( 'bootstrap', plugins_url('css/bootstrap.min.css', __FILE__), array(), $this->bvinfo->version);
66 - wp_enqueue_style( 'bvplugin', plugins_url('css/bvplugin.min.css', __FILE__), array(), $this->bvinfo->version);
67 - wp_enqueue_script( 'wpr-connection-key', plugins_url('js/connection-key.js', __FILE__), array(), $this->bvinfo->version, true);
60 + if ($hook === 'toplevel_page_wpremote' || preg_match("/wpr_add_account$/", $hook) || preg_match("/wpr_account_details$/", $hook)) {
61 + wp_enqueue_style( 'bvsurface', plugins_url('css/bvmui.min.css', __FILE__));
62 + wp_enqueue_style( 'bootstrap', plugins_url('css/bootstrap.min.css', __FILE__));
63 + wp_enqueue_style( 'bvplugin', plugins_url('css/bvplugin.min.css', __FILE__));
68 64 }
69 65 }
70 66
71 67 public function menu() {
72 - $brand = $this->bvinfo->getPluginWhitelabelInfo();
73 - $can_whitelabel = $this->bvinfo->canWhiteLabel();
74 - $hide_from_menu = array_key_exists('hide', $brand) || array_key_exists('hide_from_menu', $brand);
75 - if (!$can_whitelabel || !$hide_from_menu) {
68 + $brand = $this->bvinfo->getBrandInfo();
69 + if (!$brand || (!array_key_exists('hide', $brand) && !array_key_exists('hide_from_menu', $brand))) {
76 70 $bname = $this->bvinfo->getBrandName();
77 71 $icon = $this->bvinfo->getBrandIcon();
78 72 add_menu_page($bname, $bname, 'manage_options', $this->bvinfo->plugname,
79 73 array($this, 'adminPage'), plugins_url($icon, __FILE__ ));
@@ -79,32 +73,15 @@
79 73 array($this, 'adminPage'), plugins_url($icon, __FILE__ ));
80 74 }
81 75 }
82 76
83 - public function hidePluginUpdate($plugins) {
84 - if (!$this->bvinfo->canWhiteLabel()) {
85 - return $plugins;
86 - }
87 - $whitelabel_infos = $this->bvinfo->getPluginsWhitelabelInfos();
88 - foreach ($whitelabel_infos as $slug => $brand) {
89 - if ($this->bvinfo->canWhiteLabel($slug) && isset($plugins->response[$slug]) && is_array($brand)) {
90 - if (array_key_exists('hide_from_menu', $brand) || array_key_exists('hide', $brand)) {
91 - unset($plugins->response[$slug]);
92 - }
93 - }
94 - }
95 - return $plugins;
96 - }
77 + public function hidePluginDetails($plugin_metas, $slug) {
78 + $brand = $this->bvinfo->getBrandInfo();
79 + $bvslug = $this->bvinfo->slug;
97 80
98 - public function hidePluginDetails($plugin_metas, $slug) {
99 - if (!is_array($plugin_metas) || !$this->bvinfo->canWhiteLabel($slug)) {
100 - return $plugin_metas;
101 - }
102 - $whitelabel_info = $this->bvinfo->getPluginWhitelabelInfo($slug);
103 - if (array_key_exists('hide_plugin_details', $whitelabel_info)) {
81 + if ($slug === $bvslug && $brand && array_key_exists('hide_plugin_details', $brand)){
104 82 foreach ($plugin_metas as $pluginKey => $pluginValue) {
105 - // phpcs:ignore WordPress.WP.I18n.MissingArgDomain
106 - if (strpos($pluginValue, sprintf('>%s<', __('View details')))) {
83 + if (strpos($pluginValue, sprintf('>%s<', translate('View details')))) {
107 84 unset($plugin_metas[$pluginKey]);
108 85 break;
109 86 }
110 87 }
@@ -111,46 +88,14 @@
111 88 }
112 89 return $plugin_metas;
113 90 }
114 91
115 - public function handlePluginHealthInfo($plugins) {
116 - if (!isset($plugins["wp-plugins-active"]) ||
117 - !isset($plugins["wp-plugins-active"]["fields"]) || !$this->bvinfo->canWhiteLabel()) {
118 - return $plugins;
119 - }
120 -
121 - $whitelabel_infos_by_title = $this->bvinfo->getPluginsWhitelabelInfoByTitle();
122 -
123 - foreach ($whitelabel_infos_by_title as $title => $brand) {
124 - if (is_array($brand) && array_key_exists('slug', $brand) && $this->bvinfo->canWhiteLabel($brand["slug"])) {
125 - if (array_key_exists('hide', $brand)) {
126 - unset($plugins["wp-plugins-active"]["fields"][$title]);
127 - } else {
128 - $plugin = $plugins["wp-plugins-active"]["fields"][$title];
129 - $author = $brand['default_author'];
130 - if (array_key_exists('name', $brand)) {
131 - $plugin["label"] = $brand['name'];
132 - }
133 - if (array_key_exists('author', $brand)) {
134 - $plugin["value"] = str_replace($author, $brand['author'], $plugin["value"]);
135 - }
136 - if (array_key_exists('description', $brand)) {
137 - $plugin["debug"] = str_replace($author, $brand['author'], $plugin["debug"]);
138 - }
139 - $plugins["wp-plugins-active"]["fields"][$title] = $plugin;
140 - }
141 - }
142 - }
143 - return $plugins;
144 - }
145 -
146 92 public function settingsLink($links, $file) {
147 93 #XNOTE: Fix this
148 - if ( $file == plugin_basename( dirname(__FILE__).'/plugin.php' ) ) {
149 - $brand = $this->bvinfo->getPluginWhitelabelInfo();
150 - if (!array_key_exists('hide_plugin_details', $brand)) {
151 - // phpcs:ignore WordPress.WP.I18n.MissingArgDomain
152 - $links[] = '<a href="'.$this->mainUrl().'">'.__('Settings').'</a>';
94 + if ( $file == plugin_basename( dirname(__FILE__).'/blogvault.php' ) ) {
95 + $brand = $this->bvinfo->getBrandInfo();
96 + if (!$brand || !array_key_exists('hide_plugin_details', $brand)) {
97 + $links[] = '<a href="'.$this->mainUrl().'">'.__( 'Settings' ).'</a>';
153 98 }
154 99 }
155 100 return $links;
156 101 }
@@ -155,10 +100,10 @@
155 100 return $links;
156 101 }
157 102
158 103 public function getPluginLogo() {
159 - $brand = $this->bvinfo->getPluginWhitelabelInfo();
160 - if (array_key_exists('logo', $brand)) {
104 + $brand = $this->bvinfo->getBrandInfo();
105 + if ($brand && array_key_exists('logo', $brand)) {
161 106 return $brand['logo'];
162 107 }
163 108 return $this->bvinfo->logo;
164 109 }
@@ -163,10 +108,10 @@
163 108 return $this->bvinfo->logo;
164 109 }
165 110
166 111 public function getWebPage() {
167 - $brand = $this->bvinfo->getPluginWhitelabelInfo();
168 - if (array_key_exists('webpage', $brand)) {
112 + $brand = $this->bvinfo->getBrandInfo();
113 + if ($brand && array_key_exists('webpage', $brand)) {
169 114 return $brand['webpage'];
170 115 }
171 116 return $this->bvinfo->webpage;
172 117 }
@@ -175,21 +120,20 @@
175 120 require_once dirname( __FILE__ ) . '/recover.php';
176 121 $bvnonce = wp_create_nonce("bvnonce");
177 122 $public = WPRAccount::getApiPublicKey($this->settings);
178 123 $secret = WPRRecover::defaultSecret($this->settings);
179 - $server_ip = WPRHelper::getStringParamEscaped('SERVER', 'SERVER_ADDR', 'attr');
180 - $tags = "<input type='hidden' name='url' value='".esc_attr($this->siteinfo->wpurl())."'/>\n".
181 - "<input type='hidden' name='homeurl' value='".esc_attr($this->siteinfo->homeurl())."'/>\n".
182 - "<input type='hidden' name='siteurl' value='".esc_attr($this->siteinfo->siteurl())."'/>\n".
183 - "<input type='hidden' name='dbsig' value='".esc_attr($this->siteinfo->dbsig(false))."'/>\n".
184 - "<input type='hidden' name='plug' value='".esc_attr($this->bvinfo->plugname)."'/>\n".
185 - "<input type='hidden' name='adminurl' value='".esc_attr($this->mainUrl())."'/>\n".
186 - "<input type='hidden' name='bvversion' value='".esc_attr($this->bvinfo->version)."'/>\n".
187 - "<input type='hidden' name='serverip' value='".$server_ip."'/>\n".
188 - "<input type='hidden' name='abspath' value='".esc_attr(ABSPATH)."'/>\n".
189 - "<input type='hidden' name='secret' value='".esc_attr($secret)."'/>\n".
190 - "<input type='hidden' name='public' value='".esc_attr($public)."'/>\n".
191 - "<input type='hidden' name='bvnonce' value='".esc_attr($bvnonce)."'/>\n";
124 + $tags = "<input type='hidden' name='url' value='".$this->siteinfo->wpurl()."'/>\n".
125 + "<input type='hidden' name='homeurl' value='".$this->siteinfo->homeurl()."'/>\n".
126 + "<input type='hidden' name='siteurl' value='".$this->siteinfo->siteurl()."'/>\n".
127 + "<input type='hidden' name='dbsig' value='".$this->siteinfo->dbsig(false)."'/>\n".
128 + "<input type='hidden' name='plug' value='".$this->bvinfo->plugname."'/>\n".
129 + "<input type='hidden' name='adminurl' value='".$this->mainUrl()."'/>\n".
130 + "<input type='hidden' name='bvversion' value='".$this->bvinfo->version."'/>\n".
131 + "<input type='hidden' name='serverip' value='".$_SERVER["SERVER_ADDR"]."'/>\n".
132 + "<input type='hidden' name='abspath' value='".ABSPATH."'/>\n".
133 + "<input type='hidden' name='secret' value='".$secret."'/>\n".
134 + "<input type='hidden' name='public' value='".$public."'/>\n".
135 + "<input type='hidden' name='bvnonce' value='".$bvnonce."'/>\n";
192 136 return $tags;
193 137 }
194 138
195 139 public function activateWarning() {
@@ -196,9 +140,9 @@
196 140 global $hook_suffix;
197 141 if (!WPRAccount::isConfigured($this->settings) && $hook_suffix == 'index.php' ) {
198 142 ?>
199 143 <div id="message" class="updated" style="padding: 8px; font-size: 16px; background-color: #dff0d8">
200 - <a class="button-primary" href="<?php echo esc_url($this->mainUrl()); ?>">Activate WPRemote</a>
144 + <a class="button-primary" href="<?php echo $this->mainUrl(); ?>">Activate WPRemote</a>
201 145 &nbsp;&nbsp;&nbsp;<b>Almost Done:</b> Activate your WPRemote account to backup & secure your site.
202 146 </div>
203 147 <?php
204 148 }
@@ -212,20 +156,13 @@
212 156 require_once dirname( __FILE__ ) . "/admin/account_details.php";
213 157 }
214 158
215 159 public function adminPage() {
216 - $bvnonce = WPRHelper::getRawParam('REQUEST', 'bvnonce');
217 - if ($bvnonce && wp_verify_nonce($bvnonce, 'bvnonce')) {
160 + if (isset($_REQUEST['bvnonce']) && wp_verify_nonce( $_REQUEST['bvnonce'], 'bvnonce' )) {
218 161 $info = array();
219 162 $this->siteinfo->basic($info);
220 -
221 - $pubkey = WPRHelper::getRawParam('REQUEST', 'pubkey');
222 -
223 - if (!empty($pubkey)) {
224 - $pubkey = WPRAccount::sanitizeKey($pubkey);
225 - $this->bvapi->pingbv('/bvapi/disconnect', $info, $pubkey);
226 - WPRAccount::remove($this->settings, $pubkey);
227 - }
163 + $this->bvapi->pingbv('/bvapi/disconnect', $info, $_REQUEST['pubkey']);
164 + WPRAccount::remove($this->settings, $_REQUEST['pubkey']);
228 165 }
229 166 if (WPRAccount::isConfigured($this->settings)) {
230 167 if (!isset($_REQUEST['add_account'])) {
231 168 $this->showAccountDetailsPage();
@@ -236,17 +173,17 @@
236 173 $this->showAddAccountPage();
237 174 }
238 175 }
239 176
240 - public function initWhitelabel($plugins) {
241 - if (!is_array($plugins) || !$this->bvinfo->canWhiteLabel()) {
177 + public function initBranding($plugins) {
178 + $slug = $this->bvinfo->slug;
179 +
180 + if (!is_array($plugins) || !isset($slug, $plugins)) {
242 181 return $plugins;
243 182 }
244 - $whitelabel_infos = $this->bvinfo->getPluginsWhitelabelInfos();
245 - foreach ($whitelabel_infos as $slug => $brand) {
246 - if (!isset($slug) || !$this->bvinfo->canWhiteLabel($slug) || !array_key_exists($slug, $plugins) || !is_array($brand)) {
247 - continue;
248 - }
183 +
184 + $brand = $this->bvinfo->getBrandInfo();
185 + if ($brand) {
249 186 if (array_key_exists('hide', $brand)) {
250 187 unset($plugins[$slug]);
251 188 } else {
252 189 if (array_key_exists('name', $brand)) {
@@ -274,5 +211,5 @@
274 211 }
275 212 return $plugins;
276 213 }
277 214 }
278 -endif;
215 +endif;