| Line | Column | Type | Code | Message | Docs |
|---|
| 104 | 22 | ERROR | WordPress.Security.EscapeOutput.OutputNotEscaped | All output should be run through an escaping function (see the Security sections in the WordPress Developer Handbooks), found '$html'. | Docs |
| 108 | 129 | ERROR | WordPress.Security.EscapeOutput.OutputNotEscaped | All output should be run through an escaping function (see the Security sections in the WordPress Developer Handbooks), found 'self'. | Docs |
| 239 | 35 | WARNING | WordPress.Security.ValidatedSanitizedInput.MissingUnslash | $_POST['name'] not unslashed before sanitization. Use wp_unslash() or similar | |
| 239 | 105 | WARNING | WordPress.Security.ValidatedSanitizedInput.MissingUnslash | $_POST['phone'] not unslashed before sanitization. Use wp_unslash() or similar | |
| 239 | 187 | WARNING | WordPress.Security.ValidatedSanitizedInput.MissingUnslash | $_POST['email'] not unslashed before sanitization. Use wp_unslash() or similar | |
| 239 | 238 | WARNING | WordPress.Security.ValidatedSanitizedInput.MissingUnslash | $_POST['address'] not unslashed before sanitization. Use wp_unslash() or similar | |
| 239 | 292 | WARNING | WordPress.Security.ValidatedSanitizedInput.MissingUnslash | $_POST['note'] not unslashed before sanitization. Use wp_unslash() or similar | |
| 263 | 42 | WARNING | WordPress.Security.ValidatedSanitizedInput.MissingUnslash | $_POST['session_key'] not unslashed before sanitization. Use wp_unslash() or similar | |
| 264 | 41 | WARNING | WordPress.DB.DirectDatabaseQuery.DirectQuery | Use of a direct database call is discouraged. | |
| 264 | 41 | WARNING | WordPress.DB.DirectDatabaseQuery.NoCaching | Direct database call without caching detected. Consider using wp_cache_get() / wp_cache_set() or wp_cache_delete(). | |
| 265 | 23 | WARNING | WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedHooknameFound | Hook names invoked by a theme/plugin should start with the theme/plugin prefix. Found: "sqo_order_created". | |
| 306 | 58 | WARNING | WordPress.Security.ValidatedSanitizedInput.MissingUnslash | $_POST['phone'] not unslashed before sanitization. Use wp_unslash() or similar | |
| 307 | 73 | WARNING | WordPress.Security.ValidatedSanitizedInput.MissingUnslash | $_POST['session_key'] not unslashed before sanitization. Use wp_unslash() or similar | |
| 309 | 140 | WARNING | WordPress.Security.ValidatedSanitizedInput.MissingUnslash | $_POST['name'] not unslashed before sanitization. Use wp_unslash() or similar | |
| 309 | 200 | WARNING | WordPress.Security.ValidatedSanitizedInput.MissingUnslash | $_POST['email'] not unslashed before sanitization. Use wp_unslash() or similar | |
| 310 | 13 | WARNING | WordPress.DB.DirectDatabaseQuery.DirectQuery | Use of a direct database call is discouraged. | |
| 310 | 13 | WARNING | WordPress.DB.DirectDatabaseQuery.NoCaching | Direct database call without caching detected. Consider using wp_cache_get() / wp_cache_set() or wp_cache_delete(). | |
| 310 | 20 | WARNING | PluginCheck.Security.DirectDB.UnescapedDBParameter | Unescaped parameter $table used in $wpdb->get_var() | |
| 310 | 43 | WARNING | WordPress.DB.PreparedSQL.InterpolatedNotPrepared | Use placeholders and $wpdb->prepare(); found interpolated variable $table at "SELECT id FROM $table WHERE session_key=%s LIMIT 1" | |
| 311 | 17 | WARNING | WordPress.DB.DirectDatabaseQuery.DirectQuery | Use of a direct database call is discouraged. | |
| 311 | 17 | WARNING | WordPress.DB.DirectDatabaseQuery.NoCaching | Direct database call without caching detected. Consider using wp_cache_get() / wp_cache_set() or wp_cache_delete(). | |
| 312 | 102 | WARNING | WordPress.DB.DirectDatabaseQuery.DirectQuery | Use of a direct database call is discouraged. | |