Skip to content

fix: prepare database-check options query with literal placeholders (#228) - #237

Merged
pluginslab merged 1 commit into
mainfrom
fix/228-database-check-prepare
Sep 25, 2026
Merged

pluginslab merged 1 commit into
mainfrom
fix/228-database-check-prepare

Conversation

@pluginslab

Copy link
Copy Markdown
Owner

Removes the last non-inherent Plugin Check warning before the WP.org resubmission (PluginCheck.Security.DirectDB.UnescapedDBParameter at database-check.php:305).

The WHERE clause was built with implode() from fixed fragments behind a phpcs:disable block. It now writes the four LIKE %s clauses directly into the query, the same way the other checks in the file do.

Tested: with two planted options, the check returns both (same result as before). Plugin Check reports nothing for the file.

🤖 Generated with Claude Code

…228)

Plugin Check flagged the dynamically built WHERE clause as an unescaped
parameter. Write the four LIKE %s clauses into the query directly, like
the sibling checks, and drop the phpcs:disable block.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@pluginslab
pluginslab merged commit d711bdc into main Sep 25, 2026
4 checks passed
@pluginslab
pluginslab deleted the fix/228-database-check-prepare branch September 25, 2026 12:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant