Automattic / Automattic/VIP-Coding-Standards
Inconsistent treatment of translated strings
- Lingua principale
- PHP
- Stelle
- 261
- Fork
- 44
- Merge medio
- 19m
- PR unite (30g)
- 1
Descrizione
## Bug Description
We seem to have some inconsistencies when looking at `_e()` and `_ex()` vs `echo __()` and `echo _x()`, for example. Note that none of these functions are escaped.
When the minimal code snippet below is checked with severity 5, only 2 violations for `__()` and `__x()` appear.
When it's severity 1, then violations for all 4 lines appear.

Seems to originate from [this line](https://github.com/Automattic/VIP-Coding-Standards/blob/bfc7fc56e18bec55a3830de06d1d3be0443585dd/WordPress-VIP-Go/ruleset.xml#L222-L224) where we drop severity for some WPCS violations, as we apparently trust translations.
The [unsafe printing functions](https://github.com/WordPress/WordPress-Coding-Standards/blob/2f098354173a9e8487b0e8672fde8c526c7daf52/WordPress/Sniffs/Security/EscapeOutputSniff.php#L70-L73) are `_e()` and `_ex()` .
## Minimal Code Snippet
```php
## Tested Against `master` branch?
- [x] I have verified the issue still exists in the `master` branch of VIPCS.
- [x] I have verified the issue still exists in the `develop` branch of VIPCS.
Guida per i contributori
Apri la guida per i contributori
Direzione di ricerca
Inizia da ruleset.xml intorno alle righe 222-224 e confronta la gestione della severità con quella di WordPress/Sniffs/Security/EscapeOutputSniff.php intorno alle righe 70-73. Riproduci lo snippet PHP fornito con le severità 1 e 5, quindi verifica che i quattro casi di stringhe tradotte ricevano un trattamento coerente per i codici di errore segnalati.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- php
- Ambito
- tooling
- Tipo di issue
- Bug
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Stato di attività
- Ferma
- Chiarezza
- Abbastanza chiara
- Idoneità per principianti
- 35/100