WordPress / WordPress/WordPress-Coding-Standards
Handbook: "Functions that update the database should expect their parameters to lack SQL slash escaping when passed."
Open
Nobody has claimed this yet.
Component: Core
Focus: DB
Type: Enhancement
- Dominant language
- PHP
- Stars
- 2.8k
- Forks
- 521
- Avg merge
- 5d 20h
- Merged PRs (30d)
- 1
Description
We could possibly verify that variables passed to $wpdb->prepare() don't have a slashing function around it ?
Could possibly be added to the WordPress.WP.PreparedSQLWordPress.WP.PreparedSQLPlaceholders sniff.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the linked WordPress PHP coding-standard guidance and the WordPress.WP.PreparedSQLPlaceholders sniff. Determine how variables passed to $wpdb->prepare() are currently checked; done means the sniff identifies slashing functions around those variables and has corresponding coverage.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- php
- Domain
- tooling
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100