Unescaped parameter $count_sql used in $wpdb->get_var($count_sql)\n$count_sql assigned unsafely at line 252:\n $count_sql = 'SELECT COUNT(*) FROM ' . $wpdb->prefix . self::table_name . ' WHERE current_edition IS NOT NULL AND deleted_at IS NULL AND split_test IS NULL'\n$connected used without escaping.\n$page_sql assigned unsafely at line 266:\n $page_sql .= $wpdb->prepare(" ORDER BY $column $order LIMIT %d, %d", $start, $per_page)\n$column assigned unsafely at line 248:\n $column = 'date' === $order_by ? 'updated_at' : 'name'\n$order assigned unsafely at line 242:\n $order = strtoupper($order)\n$start assigned unsafely at line 249:\n $start = ( $page - 1 ) * $per_page\n$page used without escaping.
Unescaped parameter $identifier_type used in $wpdb->get_row($wpdb->prepare(\n 'SELECT * FROM ' . $wpdb->prefix . self::table_name . " WHERE $identifier_type = %s",\n $identifier\n ))\n$identifier_type assigned unsafely at line 190:\n $identifier_type = is_int($identifier) ? 'id' : 'uuid'\n$result assigned unsafely at line 192:\n $result = $wpdb->get_row(\n $wpdb->prepare(\n // phpcs:ignore WordPress.DB.PreparedSQL.InterpolatedNotPrepared, WordPress.DB.PreparedSQL.NotPrepared\n 'SELECT * FROM ' . $wpdb->prefix . self::table_name . " WHERE $identifier_type = %s",\n $identifier\n )\n )\n$identifier used without escaping.
Affected Plugins
Plugins that have instances of this rule violation
Unescaped parameter $page_sql used in $wpdb->get_results($page_sql)\n$page_sql assigned unsafely at line 266:\n $page_sql .= $wpdb->prepare(" ORDER BY $column $order LIMIT %d, %d", $start, $per_page)\n$column assigned unsafely at line 248:\n $column = 'date' === $order_by ? 'updated_at' : 'name'\n$order assigned unsafely at line 242:\n $order = strtoupper($order)\n$start assigned unsafely at line 249:\n $start = ( $page - 1 ) * $per_page\n$page used without escaping.
Unescaped parameter $sql used in $wpdb->query($sql)\n$sql assigned unsafely at line 16:\n $sql = "DROP TABLE IF EXISTS $landing_pages_table"\n$landing_pages_table assigned unsafely at line 15:\n $landing_pages_table = $wpdb->prefix . 'lp_landingpages'