Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

ProperEscapingFunctionSniff doesn't catch misuse of wp_json_encode

Open
#876 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
48/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Stale
Tech stack
php
Domain
security, tooling

Research direction

Start by reading WordPressVIPMinimum/Sniffs/Security/ProperEscapingFunctionSniff.php and reproduce the minimal onerror examples from the issue. Compare how wp_json_encode is handled with esc_html; done when the misuse produces the WordPressVIPMinimum.Security.ProperEscapingFunction error in that context.

Written by the indexing model from the issue text.

Description

Bug Description

ProperEscapingFunctionSniff is a great addition to WPCS. It isn't comprehensive, though.

One specific example that I ran into is that it won't catch improper use of wp_json_encode() like it does with other functions.

Minimal Code Snippet

<!-- correctly flags esc_html as the wrong escaping function in this context -->
<img src=a onerror="<?php echo esc_html( $foo ); ?>" />

<!-- fails to catch that this is the wrong escaping function -->
<img src=a onerror="<?php echo wp_json_encode( $foo ); ?>" />

Error Code

WordPressVIPMinimum.Security.ProperEscapingFunction

Dominant language
PHP
Stars
261
Forks
44
PR merge metrics
No merged PRs in 30d

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from Automattic/VIP-Coding-Standards

All issues in Automattic/VIP-Coding-Standards

Similar issues

More PHP issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.