#11848 (THEME: discover – WordPress Themes (original) (raw)

#2 @sixhours

13 years ago

Theme Check

Required

Line 48:
Line 63:

Previous Issues

FIXED Themes are REQUIRED to use 'wp_title' filter, to filter wp_title()

Code

Required

​http://codex.wordpress.org/Theme_Review#Security_and_Privacy

Recommended

Visual

Required

Recommended

Recommendation

Thanks for your submission! This was a complete review. There are a number of Required issues that should be addressed... please fix and resubmit your theme. If you can do so in the next 2-3 days, please post a link to the new ticket here and I'll be happy to re-review.

#3 @manish_gori

13 years ago

Hello Sir,

I have fixed all points except this:


All theme options need to be properly escaped with the correct function; please see here:


If you go to folder admin/options-sanitize.php does that? Please advise?

Thanks

#4 @sixhours

13 years ago

If you go to folder admin/options-sanitize.php does that? Please advise?

The Options Framework sanitizes on input, but you still need to use esc_url, esc_textarea, esc_attr, etc. functions around the output to ensure nothing gets through via filters or injections. The general rule is, don't trust any data going into the database, and don't trust any data coming out of the database.

#6 @sixhours

13 years ago