WordPress / WordPress/WordPress-Coding-Standards

Check for ABSPATH exit

Open
#1,850 17 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
PHP
Stars
2.8k
Forks
521
Avg merge
5d 20h
Merged PRs (30d)
1

Description

Is your feature request related to a problem?

To avoid direct file access, a lot of WP files disallow access if ABSPATH is not defined.
Since this essentially useful for all files that are used in the WP ecosystem, there should be a sniff for this (& perhaps even an auto-fix)

Describe the solution you'd like

if a file does not contain:

if ( ! defined( 'ABSPATH' ) ) {
	exit; // Exit if accessed directly
}

before any other PHP code, EXCEPT if the file contains a require_once for wp-load (which would load the ABSPATH), it should give an error.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the repository's existing PHP_CodeSniffer sniff structure and tests, then compare the requested ABSPATH guard and wp-load exception with current WordPress coding rules. Done means the sniff reports files missing the guard in the stated position while allowing the documented wp-load case, with coverage for the requested behavior.

Written by the indexing model from the issue text.

Assessment

Tech stack
php
Domain
tooling
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.