= 2.3.1 =
- Security: Sanitized
$_REQUESTdata withmap_deep()before dispatching to action handlers - Security: Escaped all remaining unescaped variable and option outputs across admin pages
- Security: Escaped nonce, internal ID, and admin URL outputs in setup and settings templates
- Security: Added
wp_kses_post()escaping to language selector, addon display, and notice outputs - Security: Used targeted
wp_kses()allowlist for form/page template output to preserve form structure - Fix: Setup modal no longer renders raw PHP code from
$site_accountassignment outside PHP tags - Fix: Settings save restored after
wp_kses_post()mangled form HTML in page templates