Repository navigation
fix: escape custom-table names in raw SQL, add missing docblocks - #110
Merged
cport1 merged 1 commit intoOct 4, 2026
Merged
Conversation
… docblocks esc_sql() the $wpdb->prefix-derived table names used in raw SQL strings across the custom-table queries (rate limiter, blocker, detector, WooCommerce tracking, violation/referral counters, admin reporting pages). Also adds docblocks to the constructors and methods that were missing them. Not changed, and why: - includes/class-webdecoy-violation-reporter.php's remaining occurrences: this file is required standalone (no WordPress) by tests/ViolationDrainTest.php, and esc_sql() is undefined outside WordPress. Verified by trying it: the suite breaks with "Call to undefined function esc_sql()". - $where/$query/$export_query in detections-page.php and blocker.php: these are already correctly parameterized through $wpdb->prepare(); Plugin Check's static analyzer just can't trace that a few layers up. Not a real gap. - 83 DirectQuery/NoCaching and 6 error_log() warnings: left as-is per prior discussion — caching would break rate-limit correctness, and the error_log() calls are legitimate exception-catch logging.
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Plugin Check flagged 65
UnescapedDBParameterwarnings for customtable names (
$wpdb->prefix . 'webdecoy_...') interpolated into rawSQL strings. 48 are fixed here by wrapping the assignment in
esc_sql()at the point the table name is built, across the ratelimiter, IP blocker, detector, WooCommerce checkout tracking, and the
statistics/detections admin pages.
17 are deliberately left alone:
class-webdecoy-violation-reporter.php— this file is loadedstandalone (no WordPress) by
tests/ViolationDrainTest.php, andesc_sql()doesn't exist outside WordPress. Confirmed by testingit directly: the suite breaks with
Call to undefined function esc_sql().$where,$query,$export_query,$tablevia a method call) where the actual SQL is alreadycorrectly parameterized through
$wpdb->prepare(). Plugin Check'sanalyzer loses track a few layers removed from the original
assignment; it's a tool limitation, not a real gap.
Also adds missing docblocks to 5 constructors and 9 methods across
the plugin, matching the existing
/** Constructor ... */stylealready used elsewhere in the codebase. Left two methods undocumented
on purpose (
WebDecoy_Rate_Limit_Rule::getName()/evaluate()) sincesibling rule classes (
TripwireRule,FilterRule) rely on theinterface's docblock rather than repeating it — adding one here would
have been inconsistent with that existing pattern.
Test Plan
php tests/run.php— 196 passed, 0 failedvendor/bin/phpstan analyse— no errorsvendor/bin/phpcs(project's security+DB ruleset) — same baseline (2 pre-existing errors, 148 warnings; none newly introduced)includes/class-webdecoy-blocker.phpbefore/after)php -lon all 18 changed files — no syntax errors