Skip to content

Reduce false positives: incorrect warning about $wpdb->prepare #1333

Description

@Tsjippy

Thanks fotr this plugin, its very usefull.

I would like to point out that sometimes I get false positives. It would be great if I could exclude such from the results so that if I Check my plugin again I don't see those again.

One such false positive is

$wpdb->get_results(
   $wpdb->prepare($query, ...$args)
);

Passing the query to the prepare function leads to the following result:

ERROR | WordPress.DB.PreparedSQL.NotPrepared Use placeholders and $wpdb->prepare(); found $query
The helper function executes a passed-in query variable, which must be prepared by the caller.

Another one is this: echo $dom->saveHtml(); This does not need escaping as the html is already safe;.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions