• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

bleedingdeacons / scrutiny
93%

Build:
DEFAULT BRANCH: main
Repo Added 21 Jul 2026 08:56PM UTC
Files 28
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

LAST BUILD ON BRANCH main
branch: SELECT
CHANGE BRANCH
x
  • No branch selected
  • audit-certification-change
  • bump-1.23.18
  • bump-1.23.19
  • chore/add-dependabot
  • chore/ci-semgrep-and-pin-actions
  • chore/declare-php-extensions
  • chore/dev-tooling-standardisation
  • chore/dynamic-phpstan-badge
  • chore/fix-github-plugin-uri
  • chore/migrate-to-wp-mocks
  • chore/phpcs-root-files
  • chore/phpstan-level-7
  • chore/phpstan-level-8
  • chore/phpstan-level6
  • chore/phpstan-level6-haslogger-types
  • chore/phpstan-level6-iterable-types
  • chore/psr12-gate
  • chore/readme-phpstan-level6
  • chore/release
  • chore/release-1.27.1
  • chore/release-v1-23-25
  • chore/release-v1.26.1
  • chore/release-v1.27.0
  • chore/release-version-bump
  • chore/scheduled-semgrep-scan
  • chore/tidy-phpstan-ignores
  • chore/use-shared-unity-doubles
  • chore/wp-mocks-2.0
  • ci/composer-audit
  • ci/release-on-merge
  • ci/validate-lock
  • dependabot/composer/dependencies-3022dae4de
  • dependabot/composer/dependencies-e9da279c12
  • dependabot/github_actions/actions-02325a8da5
  • docs/readme-refresh-test-section
  • docs/readme-testing-section
  • docs/remove-tests-badge
  • docs/tests-badge
  • feat/audit-detail-full-prose
  • feat/audit-remaining-member-fields
  • feat/audit-service-role-assignment
  • feat/gdpr-audit-history-field
  • feat/help-submenu
  • feat/php-84-wp-711
  • feat/ship-audit-logger-spy
  • feat/track-member-landline-and-preferred-contact
  • fix/audit-doc-counts
  • fix/build-eol
  • fix/docs-version-chip
  • fix/help-link-blocked-popup
  • fix/idempotent-release-job
  • fix/release-push-retry
  • fix/rest-policy-body-kses
  • main
  • protect-responder-certification
  • readme-backfill-edit-cap
  • readonly-cert-visible-disabled
  • release/v1.24.0
  • release/v1.25.0
  • release/v1.26.0
  • test/cover-src-admin
  • test/pest-5
  • tests/coverage-90
  • tests/raise-coverage-to-60

03 Oct 2026 08:59PM UTC coverage: 92.749% (+0.006%) from 92.743%
37153500180

push

github

web-flow
fix: filter the privacy-policy body through kses on the REST routes (#82)

Only the shortcode ran wp_kses_post() over the policy body. The REST
routes served get_field('gdpr-policy') as stored, and an administrator
with unfiltered_html can store anything there. Register drops that body
verbatim into its HTML acceptance email, so a javascript:, data: or
vbscript: link, a <script> block or an on* handler reached a mail
client unfiltered.

PrivacyPolicyFormatter now strips <style> and <script> blocks and runs
wp_kses_post() on the body, so every surface gets the same filtered
HTML. The shortcode's own strip moved there with it; its final kses
pass over body plus metadata stays.

The test bootstrap's wp_kses_post() stand-in is removed in favour of
wp-mocks', which also refuses disallowed URL schemes. The local one
loaded first and would have let a javascript: link through.

2200 of 2372 relevant lines covered (92.75%)

8.66 hits per line

Relevant lines Covered
Build:
Build:
2372 RELEVANT LINES 2200 COVERED LINES
8.66 HITS PER LINE
Source Files on main
  • Tree
  • List 28
  • Changed 2
  • Source Changed 0
  • Coverage Changed 2
Coverage ∆ File Lines Relevant Covered Missed Hits/Line

Recent builds

Builds Branch Commit Type Ran Committer Via Coverage
37153500180 main fix: filter the privacy-policy body through kses on the REST routes (#82) Only the shortcode ran wp_kses_post() over the policy body. The REST routes served get_field('gdpr-policy') as stored, and an administrator with unfiltered_html can store a... push 03 Oct 2026 09:03PM UTC web-flow github
92.75
37153457914 fix/rest-policy-body-kses Merge cf014988f into 5066742d7 Pull #82 03 Oct 2026 09:01PM UTC web-flow github
92.75
35945421645 main docs: remove duplicate Tests badge from README (#81) push 24 Sep 2026 02:03AM UTC web-flow github
92.74
35944962465 docs/remove-tests-badge Merge e8cb24f3c into 2edb83633 Pull #81 24 Sep 2026 01:57AM UTC web-flow github
92.74
35944469284 main docs: add Tests badge to README (#80) push 24 Sep 2026 01:51AM UTC web-flow github
92.74
35944097547 docs/tests-badge Merge 4890035ec into 53c6002fc Pull #80 24 Sep 2026 01:44AM UTC web-flow github
92.74
35696143602 main test: convert the suite to Pest 5 (#79) Every test file is now a closure-based Pest spec except two kept as PHPUnit classes: the REST_REQUEST tests must run in a separate process (a defined constant cannot be undone) and Pest refuses process isol... push 22 Sep 2026 06:46AM UTC web-flow github
92.74
35695847659 test/pest-5 Merge a526d58a0 into f8f24f003 Pull #79 22 Sep 2026 06:43AM UTC web-flow github
92.74
35543126466 main fix: declare the PHP extensions this plugin actually uses (#78) composer.json required only php, so a host without these would install the plugin happily and fail at runtime instead of at install time. Added: ext-mbstring Evidence: mb_* in src/ ... push 20 Sep 2026 11:00PM UTC web-flow github
92.91
35542180287 chore/declare-php-extensions Merge 02e1001f2 into 5cb2735b8 Pull #78 20 Sep 2026 10:38PM UTC web-flow github
92.91
See All Builds (139)
  • Repo on GitHub
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc