- Tested up to WordPress 7.1.
- Sanitize the setting on save. The sanitize callback was wired to the settings section instead of
register_setting(), so submitted values were stored unsanitized. - Prevent direct access to plugin PHP files.
Full Changelog: 1.2.0...1.2.1