• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

bleedingdeacons / confur / 31199151521
95%

Build:
DEFAULT BRANCH: main
Ran 07 Aug 2026 04:47PM UTC
Jobs 1
Files 22
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

07 Aug 2026 04:46PM UTC coverage: 94.935% (-0.3%) from 95.194%
31199151521

push

github

web-flow
fix: close a path-traversal gap in the email template loader, raise PHPStan to level 7 (#62)

EmailService::renderTemplate() checked `$realPath === false` but not
`$emailsDir`, which realpath() can also return false for. strpos($x, false)
compares against '"'"''"'"' and returns 0, so an emails directory that failed to
resolve would have *satisfied* the containment test rather than failing it -
the traversal guard was open in exactly the case it was written for. Both
are checked now, and an unreadable file_get_contents() no longer flows on
as false.

The rest of the nineteen findings:

- file_get_contents() unguarded again in EmailTemplateAdminPage;
  file_exists() does not promise readable.
- min()/max() keyed off a count instead of the array, which does not prove
  non-emptiness.
- get_permalink() and json_encode(), string|false, passed to EmailService.
  Sends now carry an empty string rather than false; the one on the
  status screen stops instead, since a confirmation with no link is worse
  than none.
- generateUniqueSlug() returns false on failure and was going straight into
  wp_update_post as post_name. Now omitted so WordPress derives the slug.
- AcfHelper passed its int|string post id to get_post()/clean_post_cache().
  Non-numeric ids already returned false one line later; now they are
  rejected explicitly rather than cast by WordPress.
- The registered-groups lookup read ->ID off an unshaped object. Object and
  array branches are now one expression, via a cast.
- getDayName() reached $wp_locale through method_exists(), which narrows to
  class-string|object and so has no methods to call. Routed through
  is_callable() instead - the duck typing is deliberate and pinned by a
  test that passes an anonymous class, so instanceof WP_Locale was not an
  option.

23 of 33 new or added lines in 6 files covered. (69.7%)

2 existing lines in 1 file now uncovered.

2268 of 2389 relevant lines covered (94.94%)

4.08 hits per line

Uncovered Changes

Lines Coverage ∆ File
4
85.42
-2.76% src/Services/EmailService.php
3
98.87
-0.22% src/Admin/StatusAdminPage.php
2
96.77
-3.23% src/Utils/AcfHelper.php
1
96.19
-0.44% src/Admin/EmailTemplateAdminPage.php

Coverage Regressions

Lines Coverage ∆ File
2
98.87
-0.22% src/Admin/StatusAdminPage.php
Jobs
ID Job ID Ran Files Coverage
1 31199151521.1 07 Aug 2026 04:47PM UTC 22
94.94
GitHub Action Run
Source Files on build 31199151521
  • Tree
  • List 22
  • Changed 6
  • Source Changed 6
  • Coverage Changed 6
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #31199151521
  • 704616c4 on github
  • Prev Build on main (#31189846573)
  • Next Build on main (#31223883819)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc