PluginProbe
The WP Remote WordPress Plugin / 4.74
The WP Remote WordPress Plugin v4.74
6.72 6.69 6.65 6.62 6.48 6.47 4.87 4.97 5.05 5.09 5.16 5.22 5.24 5.25 5.38 5.41 5.42 5.45 5.47 5.53 5.56 5.65 5.68 5.72 5.73 All 53 releases
← All changes | wp_admin.php +54 -119 6.654.74 View file →
@@ -24,9 +24,9 @@
24 24 }
25 25 }
26 26
27 27 function removeAdminNotices() {
28 - if (WPRHelper::getRawParam('REQUEST', 'page') === $this->bvinfo->plugname) {
28 + if (array_key_exists('page', $_REQUEST) && $_REQUEST['page'] == $this->bvinfo->plugname) {
29 29 remove_all_actions('admin_notices');
30 30 remove_all_actions('all_admin_notices');
31 31 }
32 32 }
@@ -33,47 +33,41 @@
33 33
34 34 public function initHandler() {
35 35 if (!current_user_can('activate_plugins'))
36 36 return;
37 - $bvnonce = WPRHelper::getRawParam('REQUEST', 'bvnonce');
38 - $blogvaultkey = WPRHelper::getRawParam('REQUEST', 'blogvaultkey');
39 - $blogvaultkey = $blogvaultkey ? WPRAccount::sanitizeKey($blogvaultkey) : "";
40 37
41 - if ($bvnonce && wp_verify_nonce($bvnonce, "bvnonce") &&
42 - $blogvaultkey && strlen($blogvaultkey) == 64 &&
43 - (WPRHelper::getRawParam('REQUEST', 'page') === $this->bvinfo->plugname)) {
44 - $keys = str_split($blogvaultkey, 32);
38 + if (array_key_exists('bvnonce', $_REQUEST) &&
39 + wp_verify_nonce($_REQUEST['bvnonce'], "bvnonce") &&
40 + array_key_exists('blogvaultkey', $_REQUEST) &&
41 + (strlen($_REQUEST['blogvaultkey']) == 64) &&
42 + (array_key_exists('page', $_REQUEST) &&
43 + $_REQUEST['page'] == $this->bvinfo->plugname)) {
44 + $keys = str_split($_REQUEST['blogvaultkey'], 32);
45 45 WPRAccount::addAccount($this->settings, $keys[0], $keys[1]);
46 -
47 - $location = WPRHelper::getStringParamSanitized('REQUEST', 'redirect', 'url');
48 - if ($location) {
46 + if (array_key_exists('redirect', $_REQUEST)) {
47 + $location = $_REQUEST['redirect'];
49 48 wp_redirect($this->bvinfo->appUrl()."/dash/redir?q=".urlencode($location));
50 49 exit();
51 50 }
52 51 }
53 -
54 52 if ($this->bvinfo->isActivateRedirectSet()) {
55 53 $this->settings->updateOption($this->bvinfo->plug_redirect, 'no');
56 54 ##ACTIVATEREDIRECTCODE##
57 - if (!wp_doing_ajax()) {
58 - wp_redirect($this->mainUrl());
59 - }
55 + wp_redirect($this->mainUrl());
60 56 }
61 57 }
62 58
63 59 public function wprsecAdminMenu($hook) {
64 - if ($hook === 'toplevel_page_wpremote' || WPRHelper::safePregMatch("/wpr_add_account$/", $hook) || WPRHelper::safePregMatch("/wpr_account_details$/", $hook)) {
65 - wp_enqueue_style( 'bootstrap', plugins_url('css/bootstrap.min.css', __FILE__), array(), $this->bvinfo->version);
66 - wp_enqueue_style( 'bvplugin', plugins_url('css/bvplugin.min.css', __FILE__), array(), $this->bvinfo->version);
67 - wp_enqueue_script( 'wpr-connection-key', plugins_url('js/connection-key.js', __FILE__), array(), $this->bvinfo->version, true);
60 + if ($hook === 'toplevel_page_wpremote' || preg_match("/wpr_add_account$/", $hook) || preg_match("/wpr_account_details$/", $hook)) {
61 + wp_enqueue_style( 'bvsurface', plugins_url('css/bvmui.min.css', __FILE__));
62 + wp_enqueue_style( 'bootstrap', plugins_url('css/bootstrap.min.css', __FILE__));
63 + wp_enqueue_style( 'bvplugin', plugins_url('css/bvplugin.min.css', __FILE__));
68 64 }
69 65 }
70 66
71 67 public function menu() {
72 - $brand = $this->bvinfo->getPluginWhitelabelInfo();
73 - $can_whitelabel = $this->bvinfo->canWhiteLabel();
74 - $hide_from_menu = array_key_exists('hide', $brand) || array_key_exists('hide_from_menu', $brand);
75 - if (!$can_whitelabel || !$hide_from_menu) {
68 + $brand = $this->bvinfo->getBrandInfo();
69 + if (!$brand || (!array_key_exists('hide', $brand) && !array_key_exists('hide_from_menu', $brand))) {
76 70 $bname = $this->bvinfo->getBrandName();
77 71 $icon = $this->bvinfo->getBrandIcon();
78 72 add_menu_page($bname, $bname, 'manage_options', $this->bvinfo->plugname,
79 73 array($this, 'adminPage'), plugins_url($icon, __FILE__ ));
@@ -79,32 +73,15 @@
79 73 array($this, 'adminPage'), plugins_url($icon, __FILE__ ));
80 74 }
81 75 }
82 76
83 - public function hidePluginUpdate($plugins) {
84 - if (!$this->bvinfo->canWhiteLabel()) {
85 - return $plugins;
86 - }
87 - $whitelabel_infos = $this->bvinfo->getPluginsWhitelabelInfos();
88 - foreach ($whitelabel_infos as $slug => $brand) {
89 - if ($this->bvinfo->canWhiteLabel($slug) && isset($plugins->response[$slug]) && is_array($brand)) {
90 - if (array_key_exists('hide_from_menu', $brand) || array_key_exists('hide', $brand)) {
91 - unset($plugins->response[$slug]);
92 - }
93 - }
94 - }
95 - return $plugins;
96 - }
77 + public function hidePluginDetails($plugin_metas, $slug) {
78 + $brand = $this->bvinfo->getBrandInfo();
79 + $bvslug = $this->bvinfo->slug;
97 80
98 - public function hidePluginDetails($plugin_metas, $slug) {
99 - if (!is_array($plugin_metas) || !$this->bvinfo->canWhiteLabel($slug)) {
100 - return $plugin_metas;
101 - }
102 - $whitelabel_info = $this->bvinfo->getPluginWhitelabelInfo($slug);
103 - if (array_key_exists('hide_plugin_details', $whitelabel_info)) {
81 + if ($slug === $bvslug && $brand && array_key_exists('hide_plugin_details', $brand)){
104 82 foreach ($plugin_metas as $pluginKey => $pluginValue) {
105 - // phpcs:ignore WordPress.WP.I18n.MissingArgDomain
106 - if (strpos($pluginValue, sprintf('>%s<', __('View details')))) {
83 + if (strpos($pluginValue, sprintf('>%s<', translate('View details')))) {
107 84 unset($plugin_metas[$pluginKey]);
108 85 break;
109 86 }
110 87 }
@@ -111,46 +88,14 @@
111 88 }
112 89 return $plugin_metas;
113 90 }
114 91
115 - public function handlePluginHealthInfo($plugins) {
116 - if (!isset($plugins["wp-plugins-active"]) ||
117 - !isset($plugins["wp-plugins-active"]["fields"]) || !$this->bvinfo->canWhiteLabel()) {
118 - return $plugins;
119 - }
120 -
121 - $whitelabel_infos_by_title = $this->bvinfo->getPluginsWhitelabelInfoByTitle();
122 -
123 - foreach ($whitelabel_infos_by_title as $title => $brand) {
124 - if (is_array($brand) && array_key_exists('slug', $brand) && $this->bvinfo->canWhiteLabel($brand["slug"])) {
125 - if (array_key_exists('hide', $brand)) {
126 - unset($plugins["wp-plugins-active"]["fields"][$title]);
127 - } else {
128 - $plugin = $plugins["wp-plugins-active"]["fields"][$title];
129 - $author = $brand['default_author'];
130 - if (array_key_exists('name', $brand)) {
131 - $plugin["label"] = $brand['name'];
132 - }
133 - if (array_key_exists('author', $brand)) {
134 - $plugin["value"] = str_replace($author, $brand['author'], $plugin["value"]);
135 - }
136 - if (array_key_exists('description', $brand)) {
137 - $plugin["debug"] = str_replace($author, $brand['author'], $plugin["debug"]);
138 - }
139 - $plugins["wp-plugins-active"]["fields"][$title] = $plugin;
140 - }
141 - }
142 - }
143 - return $plugins;
144 - }
145 -
146 92 public function settingsLink($links, $file) {
147 93 #XNOTE: Fix this
148 - if ( $file == plugin_basename( dirname(__FILE__).'/plugin.php' ) ) {
149 - $brand = $this->bvinfo->getPluginWhitelabelInfo();
150 - if (!array_key_exists('hide_plugin_details', $brand)) {
151 - // phpcs:ignore WordPress.WP.I18n.MissingArgDomain
152 - $links[] = '<a href="'.$this->mainUrl().'">'.__('Settings').'</a>';
94 + if ( $file == plugin_basename( dirname(__FILE__).'/blogvault.php' ) ) {
95 + $brand = $this->bvinfo->getBrandInfo();
96 + if (!$brand || !array_key_exists('hide_plugin_details', $brand)) {
97 + $links[] = '<a href="'.$this->mainUrl().'">'.__( 'Settings' ).'</a>';
153 98 }
154 99 }
155 100 return $links;
156 101 }
@@ -155,10 +100,10 @@
155 100 return $links;
156 101 }
157 102
158 103 public function getPluginLogo() {
159 - $brand = $this->bvinfo->getPluginWhitelabelInfo();
160 - if (array_key_exists('logo', $brand)) {
104 + $brand = $this->bvinfo->getBrandInfo();
105 + if ($brand && array_key_exists('logo', $brand)) {
161 106 return $brand['logo'];
162 107 }
163 108 return $this->bvinfo->logo;
164 109 }
@@ -163,10 +108,10 @@
163 108 return $this->bvinfo->logo;
164 109 }
165 110
166 111 public function getWebPage() {
167 - $brand = $this->bvinfo->getPluginWhitelabelInfo();
168 - if (array_key_exists('webpage', $brand)) {
112 + $brand = $this->bvinfo->getBrandInfo();
113 + if ($brand && array_key_exists('webpage', $brand)) {
169 114 return $brand['webpage'];
170 115 }
171 116 return $this->bvinfo->webpage;
172 117 }
@@ -175,23 +120,20 @@
175 120 require_once dirname( __FILE__ ) . '/recover.php';
176 121 $bvnonce = wp_create_nonce("bvnonce");
177 122 $public = WPRAccount::getApiPublicKey($this->settings);
178 123 $secret = WPRRecover::defaultSecret($this->settings);
179 - $ctag = WPRRecover::connectionTag($this->settings);
180 - $server_ip = WPRHelper::getStringParamEscaped('SERVER', 'SERVER_ADDR', 'attr');
181 - $tags = "<input type='hidden' name='url' value='".esc_attr($this->siteinfo->wpurl())."'/>\n".
182 - "<input type='hidden' name='homeurl' value='".esc_attr($this->siteinfo->homeurl())."'/>\n".
183 - "<input type='hidden' name='siteurl' value='".esc_attr($this->siteinfo->siteurl())."'/>\n".
184 - "<input type='hidden' name='dbsig' value='".esc_attr($this->siteinfo->dbsig(false))."'/>\n".
185 - "<input type='hidden' name='plug' value='".esc_attr($this->bvinfo->plugname)."'/>\n".
186 - "<input type='hidden' name='adminurl' value='".esc_attr($this->mainUrl())."'/>\n".
187 - "<input type='hidden' name='bvversion' value='".esc_attr($this->bvinfo->version)."'/>\n".
188 - "<input type='hidden' name='serverip' value='".$server_ip."'/>\n".
189 - "<input type='hidden' name='abspath' value='".esc_attr(ABSPATH)."'/>\n".
190 - "<input type='hidden' name='secret' value='".esc_attr($secret)."'/>\n".
191 - "<input type='hidden' name='bvctag' value='".esc_attr($ctag)."'/>\n".
192 - "<input type='hidden' name='public' value='".esc_attr($public)."'/>\n".
193 - "<input type='hidden' name='bvnonce' value='".esc_attr($bvnonce)."'/>\n";
124 + $tags = "<input type='hidden' name='url' value='".$this->siteinfo->wpurl()."'/>\n".
125 + "<input type='hidden' name='homeurl' value='".$this->siteinfo->homeurl()."'/>\n".
126 + "<input type='hidden' name='siteurl' value='".$this->siteinfo->siteurl()."'/>\n".
127 + "<input type='hidden' name='dbsig' value='".$this->siteinfo->dbsig(false)."'/>\n".
128 + "<input type='hidden' name='plug' value='".$this->bvinfo->plugname."'/>\n".
129 + "<input type='hidden' name='adminurl' value='".$this->mainUrl()."'/>\n".
130 + "<input type='hidden' name='bvversion' value='".$this->bvinfo->version."'/>\n".
131 + "<input type='hidden' name='serverip' value='".$_SERVER["SERVER_ADDR"]."'/>\n".
132 + "<input type='hidden' name='abspath' value='".ABSPATH."'/>\n".
133 + "<input type='hidden' name='secret' value='".$secret."'/>\n".
134 + "<input type='hidden' name='public' value='".$public."'/>\n".
135 + "<input type='hidden' name='bvnonce' value='".$bvnonce."'/>\n";
194 136 return $tags;
195 137 }
196 138
197 139 public function activateWarning() {
@@ -198,9 +140,9 @@
198 140 global $hook_suffix;
199 141 if (!WPRAccount::isConfigured($this->settings) && $hook_suffix == 'index.php' ) {
200 142 ?>
201 143 <div id="message" class="updated" style="padding: 8px; font-size: 16px; background-color: #dff0d8">
202 - <a class="button-primary" href="<?php echo esc_url($this->mainUrl()); ?>">Activate WPRemote</a>
144 + <a class="button-primary" href="<?php echo $this->mainUrl(); ?>">Activate WPRemote</a>
203 145 &nbsp;&nbsp;&nbsp;<b>Almost Done:</b> Activate your WPRemote account to backup & secure your site.
204 146 </div>
205 147 <?php
206 148 }
@@ -214,20 +156,13 @@
214 156 require_once dirname( __FILE__ ) . "/admin/account_details.php";
215 157 }
216 158
217 159 public function adminPage() {
218 - $bvnonce = WPRHelper::getRawParam('REQUEST', 'bvnonce');
219 - if ($bvnonce && wp_verify_nonce($bvnonce, 'bvnonce')) {
160 + if (isset($_REQUEST['bvnonce']) && wp_verify_nonce( $_REQUEST['bvnonce'], 'bvnonce' )) {
220 161 $info = array();
221 162 $this->siteinfo->basic($info);
222 -
223 - $pubkey = WPRHelper::getRawParam('REQUEST', 'pubkey');
224 -
225 - if (!empty($pubkey)) {
226 - $pubkey = WPRAccount::sanitizeKey($pubkey);
227 - $this->bvapi->pingbv('/bvapi/disconnect', $info, $pubkey);
228 - WPRAccount::remove($this->settings, $pubkey);
229 - }
163 + $this->bvapi->pingbv('/bvapi/disconnect', $info, $_REQUEST['pubkey']);
164 + WPRAccount::remove($this->settings, $_REQUEST['pubkey']);
230 165 }
231 166 if (WPRAccount::isConfigured($this->settings)) {
232 167 if (!isset($_REQUEST['add_account'])) {
233 168 $this->showAccountDetailsPage();
@@ -238,17 +173,17 @@
238 173 $this->showAddAccountPage();
239 174 }
240 175 }
241 176
242 - public function initWhitelabel($plugins) {
243 - if (!is_array($plugins) || !$this->bvinfo->canWhiteLabel()) {
177 + public function initBranding($plugins) {
178 + $slug = $this->bvinfo->slug;
179 +
180 + if (!is_array($plugins) || !isset($slug, $plugins)) {
244 181 return $plugins;
245 182 }
246 - $whitelabel_infos = $this->bvinfo->getPluginsWhitelabelInfos();
247 - foreach ($whitelabel_infos as $slug => $brand) {
248 - if (!isset($slug) || !$this->bvinfo->canWhiteLabel($slug) || !array_key_exists($slug, $plugins) || !is_array($brand)) {
249 - continue;
250 - }
183 +
184 + $brand = $this->bvinfo->getBrandInfo();
185 + if ($brand) {
251 186 if (array_key_exists('hide', $brand)) {
252 187 unset($plugins[$slug]);
253 188 } else {
254 189 if (array_key_exists('name', $brand)) {
@@ -276,5 +211,5 @@
276 211 }
277 212 return $plugins;
278 213 }
279 214 }
280 -endif;
215 +endif;