| Code | Message | Location | Category | |
|---|---|---|---|---|
| WARNING | PluginCheck.Security.DirectDB.UnescapedDBParameter | Unescaped parameter $query used in $wpdb->get_col($query)\n$query assigned unsafely at line 246:\n $query .= " AND option_name LIKE '%" . esc_sql( $search ) . "%'"\n$query assigned unsafely at line 236:\n $query = "\n\t\t\tSELECT option_name\n\t\t\tFROM {$wpdb->options}\n\t\t\tWHERE autoload IN ( '" . implode( "', '", esc_sql( \\wp_autoload_values_to_autoload() ) ) . "' )\n\t\t\tAND option_name NOT LIKE '%_transient_%'\n\t\t"\n$autoloaded_option_names assigned unsafely at line 250:\n $autoloaded_option_names = $wpdb->get_col( // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching\n\t\t\t$query // phpcs:ignore WordPress.DB.PreparedSQL.NotPrepared\n\t\t)\n$_GET['search']['value'] used without escaping. | 250:37 | Security |
| 11/13/2025, 10:31:39 PM | 9s | 99 | 0 | 1 |