ProperEscapingFunctionSniff doesn't catch misuse of wp_json_encode
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 48/100
Research direction
Start by reading WordPressVIPMinimum/Sniffs/Security/ProperEscapingFunctionSniff.php and reproduce the minimal onerror examples from the issue. Compare how wp_json_encode is handled with esc_html; done when the misuse produces the WordPressVIPMinimum.Security.ProperEscapingFunction error in that context.
Written by the indexing model from the issue text.
Description
Bug Description
ProperEscapingFunctionSniff is a great addition to WPCS. It isn't comprehensive, though.
One specific example that I ran into is that it won't catch improper use of wp_json_encode() like it does with other functions.
Minimal Code Snippet
<!-- correctly flags esc_html as the wrong escaping function in this context -->
<img src=a onerror="<?php echo esc_html( $foo ); ?>" />
<!-- fails to catch that this is the wrong escaping function -->
<img src=a onerror="<?php echo wp_json_encode( $foo ); ?>" />
Error Code
WordPressVIPMinimum.Security.ProperEscapingFunction
- Dominant language
- PHP
- Stars
- 261
- Forks
- 44
- PR merge metrics
- No merged PRs in 30d
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from Automattic/VIP-Coding-Standards
-
AlwaysReturnInFilter: isInsideIfConditonal() guards the conditions array after reading itPossibly taken @tomjn claimed this 5 days ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
Bug: PreGetPosts warns when the early is_main_query() return is not the first statement in its ifPossibly taken @tomjn claimed this 5 days ago. Open
Difficulty 3/5 1-2 days Newbie friendliness 76/100
-
Suppress filters in get_posts false positivePossibly taken @tomjn claimed this 6 days ago. Open
Difficulty 3/5 1-2 days Newbie friendliness 68/100
-
Breaking Change Type: Maintenance
Difficulty 4/5 3-5 days Newbie friendliness 35/100
Automattic/VIP-Coding-Standards#849 · 1 comment ·
-
Difficulty 3/5 1-2 days Newbie friendliness 45/100
All issues in Automattic/VIP-Coding-Standards
Similar issues
-
Difficulty 2/5 Under an hour Newbie friendliness 78/100
opencart/opencart#15763 · 2 comments · 1 reaction ·
Maintainers usually reply within 1 day
-
L: github:actions L: php:composer
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
dependabot/dependabot-core#16493 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
api-platform/core#8649 ·
Maintainers usually reply within 1 day
-
bug
Difficulty 1/5 Under an hour Newbie friendliness 84/100
open-telemetry/opentelemetry-php#2071 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Maintainers usually reply within 1 day