• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

bleedingdeacons / scrutiny / 37153500180
93%

Build:
DEFAULT BRANCH: main
Ran 03 Oct 2026 09:03PM UTC
Jobs 1
Files 28
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

03 Oct 2026 08:59PM UTC coverage: 92.749% (+0.006%) from 92.743%
37153500180

push

github

web-flow
fix: filter the privacy-policy body through kses on the REST routes (#82)

Only the shortcode ran wp_kses_post() over the policy body. The REST
routes served get_field('gdpr-policy') as stored, and an administrator
with unfiltered_html can store anything there. Register drops that body
verbatim into its HTML acceptance email, so a javascript:, data: or
vbscript: link, a <script> block or an on* handler reached a mail
client unfiltered.

PrivacyPolicyFormatter now strips <style> and <script> blocks and runs
wp_kses_post() on the body, so every surface gets the same filtered
HTML. The shortcode's own strip moved there with it; its final kses
pass over body plus metadata stays.

The test bootstrap's wp_kses_post() stand-in is removed in favour of
wp-mocks', which also refuses disallowed URL schemes. The local one
loaded first and would have let a javascript: link through.

2200 of 2372 relevant lines covered (92.75%)

8.66 hits per line

Jobs
ID Job ID Ran Files Coverage
1 37153500180.1 03 Oct 2026 09:03PM UTC 28
92.75
GitHub Action Run
Source Files on build 37153500180
  • Tree
  • List 28
  • Changed 2
  • Source Changed 0
  • Coverage Changed 2
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #37153500180
  • 8e812cf6 on github
  • Prev Build on main (#35945421645)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc