Skip to content

fix: escape custom-table names in raw SQL, add missing docblocks - #110

Merged
cport1 merged 1 commit into
WebDecoy:mainfrom
miyanialkesh7:fix/phpcs-db-escaping-and-docblocks
Oct 4, 2026
Merged

cport1 merged 1 commit into
WebDecoy:mainfrom
miyanialkesh7:fix/phpcs-db-escaping-and-docblocks

Conversation

@miyanialkesh7

Copy link
Copy Markdown
Contributor

Summary

Plugin Check flagged 65 UnescapedDBParameter warnings for custom
table names ($wpdb->prefix . 'webdecoy_...') interpolated into raw
SQL strings. 48 are fixed here by wrapping the assignment in
esc_sql() at the point the table name is built, across the rate
limiter, IP blocker, detector, WooCommerce checkout tracking, and the
statistics/detections admin pages.

17 are deliberately left alone:

  • 6 in class-webdecoy-violation-reporter.php — this file is loaded
    standalone (no WordPress) by tests/ViolationDrainTest.php, and
    esc_sql() doesn't exist outside WordPress. Confirmed by testing
    it directly: the suite breaks with Call to undefined function esc_sql().
  • 11 are derived variables ($where, $query, $export_query,
    $table via a method call) where the actual SQL is already
    correctly parameterized through $wpdb->prepare(). Plugin Check's
    analyzer loses track a few layers removed from the original
    assignment; it's a tool limitation, not a real gap.

Also adds missing docblocks to 5 constructors and 9 methods across
the plugin, matching the existing /** Constructor ... */ style
already used elsewhere in the codebase. Left two methods undocumented
on purpose (WebDecoy_Rate_Limit_Rule::getName()/evaluate()) since
sibling rule classes (TripwireRule, FilterRule) rely on the
interface's docblock rather than repeating it — adding one here would
have been inconsistent with that existing pattern.

Test Plan

  • php tests/run.php — 196 passed, 0 failed
  • vendor/bin/phpstan analyse — no errors
  • vendor/bin/phpcs (project's security+DB ruleset) — same baseline (2 pre-existing errors, 148 warnings; none newly introduced)
  • Manually verified the esc_sql() fix resolves the Plugin Check finding (tested against includes/class-webdecoy-blocker.php before/after)
  • Manually verified esc_sql() breaks standalone tests where applied incorrectly, confirming which files must be excluded (tested and reverted)
  • Activated and deactivated the plugin on a local WordPress install — no fatals
  • php -l on all 18 changed files — no syntax errors

… docblocks

esc_sql() the $wpdb->prefix-derived table names used in raw SQL
strings across the custom-table queries (rate limiter, blocker,
detector, WooCommerce tracking, violation/referral counters, admin
reporting pages). Also adds docblocks to the constructors and
methods that were missing them.

Not changed, and why:
- includes/class-webdecoy-violation-reporter.php's remaining
  occurrences: this file is required standalone (no WordPress) by
  tests/ViolationDrainTest.php, and esc_sql() is undefined outside
  WordPress. Verified by trying it: the suite breaks with
  "Call to undefined function esc_sql()".
- $where/$query/$export_query in detections-page.php and blocker.php:
  these are already correctly parameterized through $wpdb->prepare();
  Plugin Check's static analyzer just can't trace that a few layers
  up. Not a real gap.
- 83 DirectQuery/NoCaching and 6 error_log() warnings: left as-is per
  prior discussion — caching would break rate-limit correctness, and
  the error_log() calls are legitimate exception-catch logging.
@cport1
cport1 merged commit 05257c7 into WebDecoy:main Oct 4, 2026
4 checks passed
@cport1 cport1 mentioned this pull request Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants