Skip to content

Tweak: Rearrange CI tests #9

Tweak: Rearrange CI tests

Tweak: Rearrange CI tests #9

Triggered via pull request August 13, 2026 13:30
@KingYesKingYes
synchronize #226
tweak/ci-env
Status Success
Total duration 24s
Artifacts

php-coding-standards.yml

on: pull_request
Lint PHP files
20s
Lint PHP files
Fit to window
Zoom out
Zoom in

Annotations

11 warnings
Lint PHP files
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809, actions/checkout@v4. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Lint PHP files: hooks/class-aal-hook-widgets.php#L27
Processing form data without nonce verification.
Lint PHP files: hooks/class-aal-hook-widgets.php#L27
Detected usage of a non-sanitized input variable: $_SERVER['REQUEST_METHOD']
Lint PHP files: hooks/class-aal-hook-widgets.php#L27
$_SERVER['REQUEST_METHOD'] not unslashed before sanitization. Use wp_unslash() or similar
Lint PHP files: hooks/class-aal-hook-widgets.php#L27
Detected usage of a possibly undefined superglobal array index: $_SERVER['REQUEST_METHOD']. Check that the array index exists before using it.
Lint PHP files: hooks/class-aal-hook-widgets.php#L15
Processing form data without nonce verification.
Lint PHP files: notifications/abstract-class-aal-notification-base.php#L78
Processing form data without nonce verification.
Lint PHP files: notifications/abstract-class-aal-notification-base.php#L78
Detected usage of a non-sanitized input variable: $_POST[$post_key]
Lint PHP files: notifications/abstract-class-aal-notification-base.php#L78
$_POST[$post_key] not unslashed before sanitization. Use wp_unslash() or similar
Lint PHP files: notifications/abstract-class-aal-notification-base.php#L75
Processing form data without nonce verification.
Lint PHP files: notifications/abstract-class-aal-notification-base.php#L43
All output should be run through an escaping function (see the Security sections in the WordPress Developer Handbooks), found '$this'.