• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

bleedingdeacons / confur / 32044877006
95%

Build:
DEFAULT BRANCH: main
Ran 17 Aug 2026 04:25PM UTC
Jobs 1
Files 22
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

17 Aug 2026 04:16PM UTC coverage: 94.887% (-0.01%) from 94.898%
32044877006

push

github

web-flow
fix: escape anchor markup and tighten the status page gate (#65)

Three security fixes on the Confur status screen, found in a suite-wide
audit.

HtmlHelper::createLink() interpolated $href, $class and $content into an
<a> tag with no escaping. Its output is echoed raw on the status page
(the phpcs:ignore there suppressed the warning that would have caught
it), and its inputs are meeting contact names, telephone numbers and
registration email addresses read from post meta. Anyone able to edit a
meeting's contact fields could therefore store script that ran in the
browser of everyone who opened that screen. Sibling createEmailAnchor()
already applied esc_attr, so this was an omission rather than a policy.

href now goes through esc_url() against an explicit four-scheme
allow-list rather than the filterable wp_allowed_protocols(), class
through esc_attr(), and content through wp_kses_post(). generatePdfLink()
and createEmailAnchor() had the same unescaped $content and are fixed
alongside. The contact name, which is concatenated outside the anchor,
is escaped at its call site. The shortcode error paths escaped nothing
either, and no longer reflect attributes raw.

The status page was gated on 'read' — held by every logged-in user,
including Subscribers — on both the menu registration and the render
method, while the rest of the class already used 'edit_answers'. That
put every meeting contact's name, phone number and email one URL away
from anyone with an account. Both now require 'edit_answers'.

Separately, debug error_log() calls were writing personal data to the
PHP error log unconditionally: whole rendered email bodies with their
recipient, registrant addresses in five places, the submitted ACF
payload, and a print_r of an array keyed by email. The log is neither
access-controlled nor the audit trail — Scrutiny is — so these now
report by field key, post ID and count only.

Tests: escaping cannot be observed through wp-mocks, which stubs
esc_attr/es... (continued)

32 of 32 new or added lines in 5 files covered. (100.0%)

2264 of 2386 relevant lines covered (94.89%)

4.1 hits per line

Jobs
ID Job ID Ran Files Coverage
1 32044877006.1 17 Aug 2026 04:25PM UTC 22
94.89
GitHub Action Run
Source Files on build 32044877006
  • Tree
  • List 22
  • Changed 8
  • Source Changed 8
  • Coverage Changed 8
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #32044877006
  • 639ff3b9 on github
  • Prev Build on main (#31332377951)
  • Next Build on main (#32052771740)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc