WordPress / WordPress/WordPress-Coding-Standards
Add `preg_quote()` to sanitizing functions ?
Open
Nobody has claimed this yet.
Focus: Security
Type: Question
- Dominant language
- PHP
- Stars
- 2.8k
- Forks
- 521
- Avg merge
- 5d 20h
- Merged PRs (30d)
- 1
Description
Just wondering if preg_quote() would be a valid sanitizing function - obviously should only be used for regex context, but in that context it might be the best way to go or would other sanitation be needed as well ?
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Review the repository's existing handling of sanitizing functions and the PHP_CodeSniffer rules that classify them. Determine whether preg_quote() is valid specifically for regex contexts, whether additional sanitation is needed, and define tests that establish the expected decision.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- php
- Domain
- tooling
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100