Unescaped parameter $base_sql used in $wpdb->get_results($wpdb->prepare($base_sql, ...$args))\n$base_sql assigned unsafely at line 174:\n $base_sql .= " LIMIT %d OFFSET %d"\n$args[] used without escaping.
Unescaped parameter $ignored_where used in $wpdb->get_var($wpdb->prepare(\n\t\t\t\t\t\t\t\t"SELECT count(*) FROM {$wpdb->prefix}accessibility_checker $ignored_where",\n\t\t\t\t$ignored_parameters\n\t\t\t))\n$ignored_where assigned unsafely at line 200:\n $ignored_where .= ' and rule != %s'\n$ignored_where assigned unsafely at line 197:\n $ignored_where = 'WHERE siteid = %d and postid = %d and ignre = %d'\n$ignored_count assigned unsafely at line 204:\n $ignored_count = $wpdb->get_var(\n\t\t\t$wpdb->prepare(\n\t\t\t\t// phpcs:ignore WordPress.DB.PreparedSQL.InterpolatedNotPrepared , WordPress.DB.PreparedSQLPlaceholders.UnfinishedPrepare\n\t\t\t\t"SELECT count(*) FROM {$wpdb->prefix}accessibility_checker $ignored_where",\n\t\t\t\t$ignored_parameters\n\t\t\t)\n\t\t)\n$ignored_parameters assigned unsafely at line 196:\n $ignored_parameters = [ get_current_blog_id(), $this->post_id, 1 ]
Unescaped parameter $posts_without_issues used in $wpdb->get_var($posts_without_issues)\n$posts_without_issues assigned unsafely at line 255:\n $posts_without_issues = "\n\t\t\t\tSELECT COUNT({$wpdb->posts}.ID) FROM {$wpdb->posts}\n\t\t\t\tLEFT JOIN " . $wpdb->prefix . "accessibility_checker ON {$wpdb->posts}.ID = " .\n\t\t\t\t$wpdb->prefix . 'accessibility_checker.postid WHERE ' .\n\t\t\t\t$wpdb->prefix . 'accessibility_checker.postid IS NULL\n\t\t\t\tAND post_type IN(' .\n\t\t\t\t\tHelpers::array_to_sql_safe_list(\n\t\t\t\t\t\tSettings::get_scannable_post_types()\n\t\t\t\t\t) . ')\n\t\t\t\tAND post_status IN(' .\n\t\t\t\t\tHelpers::array_to_sql_safe_list(\n\t\t\t\t\t\tSettings::get_scannable_post_statuses()\n\t\t\t\t\t) . ')'
Affected Plugins
Plugins that have instances of this rule violation
Unescaped parameter $sql used in $wpdb->get_results($sql)\n$sql assigned unsafely at line 222:\n $sql = $this->get_sql()
Unescaped parameter $sql used in $wpdb->get_var($sql)\n$sql assigned unsafely at line 149:\n $sql = 'SELECT COUNT(*) ' . $this->query['from']