Description
Two issues in the Service Worker loader file:
-
No direct access protection. The file can be loaded directly by navigating to its URL. Add an ABSPATH check at the top of the file.
-
Using readfile() instead of WP_Filesystem. WordPress.org requires file operations to go through the WP_Filesystem API rather than raw PHP functions.
Action needed
Add at the top of the file:
if ( ! defined( 'ABSPATH' ) ) {
exit;
}
Replace readfile() on line 21 with the equivalent WP_Filesystem method.
Note: This file serves the Service Worker JS, so it may intentionally need direct access (Service Workers are fetched directly by the browser). If that's the case, document why the ABSPATH check is skipped and consider using wp_die() with a nonce check instead, or suppress the PHPCS rule with an inline comment explaining the rationale.
PHPCS rules
missing_direct_file_access_protection (ERROR)
WordPress.WP.AlternativeFunctions.file_system_operations_readfile (ERROR)
Description
Two issues in the Service Worker loader file:
No direct access protection. The file can be loaded directly by navigating to its URL. Add an ABSPATH check at the top of the file.
Using
readfile()instead ofWP_Filesystem. WordPress.org requires file operations to go through theWP_FilesystemAPI rather than raw PHP functions.Action needed
Add at the top of the file:
Replace
readfile()on line 21 with the equivalentWP_Filesystemmethod.Note: This file serves the Service Worker JS, so it may intentionally need direct access (Service Workers are fetched directly by the browser). If that's the case, document why the ABSPATH check is skipped and consider using
wp_die()with a nonce check instead, or suppress the PHPCS rule with an inline comment explaining the rationale.PHPCS rules
missing_direct_file_access_protection(ERROR)WordPress.WP.AlternativeFunctions.file_system_operations_readfile(ERROR)