Skip to content

v2.9.6

Latest

Choose a tag to compare

@XternalSoft XternalSoft released this 05 Sep 20:09

Release v2.9.6 - PHP 8.1+, WordPress 6.7+ Compatibility & Performance/Security Optimizations

This update brings critical compatibility fixes for recent versions of PHP (8.1+) and WordPress (6.7+), along with a major performance and security optimization to improve layout loading reliability.


🛠️ Compatibility & Deprecation Fixes

  • PHP 8.2+ Compatibility (Callable Deprecation): Resolved the deprecation warning regarding the use of "parent" in callables within SLB_Options::add(). Replaced it with the modern, native PHP 5.6+ argument unpacking
    operator (parent::add(...$args)).
  • PHP 8.1+ Compatibility (String Functions): Resolved the deprecation warning for the trim() function receiving a null value in SLB_Utilities::validate_client_object(). Added an explicit typecast to string
    ((string)) to guarantee robust behavior.
  • WordPress 6.7.0 Compatibility (Premature Translation Loading): Fixed the debug notice regarding the premature calling of the translation function __() for the plugin name in main.php (which was executed at the
    global scope before the init action). Replaced it with a static string literal.

⚡ Performance & Security Optimizations

  • Secure Local Disk Loading for Theme Layouts:
    • Original Issue: Theme HTML structures (layout.html) were historically loaded via loopback HTTP requests (wp_safe_remote_get()). These network requests often failed silently on environments with restricted loopback
      configurations or those protected by security layers like Cloudflare Zero Trust, local firewalls, or self-signed SSL certificates, preventing the lightbox modal from launching.
    • Solution: Optimized SLB_Base_Object::get_file() to prioritize reading template files directly from the local filesystem (file_get_contents()), with a safe fallback to the original HTTP request if filesystem access
      fails or for remote URIs.
    • Security Hardening (Defense-in-Depth): Integrated strict realpath() and directory boundary validations (strictly checking against ABSPATH and $plugin_dir paths) to mathematically prevent any potential directory
      traversal or local file inclusion risks.