chore: add php lint, phpcs and phpstan - #4
Merged
Merged
Conversation
Signed-off-by: YvesCesar <yvesamorim73@gmail.com>
…nd php versions Signed-off-by: YvesCesar <yvesamorim73@gmail.com>
Signed-off-by: YvesCesar <yvesamorim73@gmail.com>
Signed-off-by: YvesCesar <yvesamorim73@gmail.com>
Signed-off-by: YvesCesar <yvesamorim73@gmail.com>
Signed-off-by: YvesCesar <yvesamorim73@gmail.com>
vitormattos
approved these changes
Sep 26, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The plugin had no Composer setup, no lint, no coding standard and no CI beyond DCO. This adds PHP lint, PHPCS and PHPStan, each as a Composer script and a GitHub workflow.
Tooling
composer lint,composer cs,composer stanandcomposer ci(all three, in this order).vendor-bin/project (bamarni/composer-bin-plugin), so their dependencies do not mix.php-lint.yml,phpcs.yml,phpstan.yml. The PHP versions come fromcomposer.json(>=8.3 <8.6) throughtypisttech/php-matrix-action, so the matrix is 8.3, 8.4 and 8.5.WordPress-Extra, so the diff stays reviewable. PHPStan runs at level 5 with the WordPress extension.Requires at least: 7.0andRequires PHP: 8.3, the versions the checks run against.Changes to the plugin
librecode_simple_smtp_andwpss_. They now all uselibrecode_simple_smtp_, the one thefunction_exists()guard already checks. The admin page slug, the nonce and the form field names keep their current values, so URLs and the form are unchanged. Code that unhooks the old names, such asremove_filter( 'wp_mail_from', 'wpss_change_mail_from' ), silently stops working; a GitHub code search finds no such reference outside this repository.esc_attr()/esc_html(). They are fixed strings, so the rendered page is the same.$_POSTandsanitize_text_field()keeps them, so saving the passwordpa'ssstoredpa\'ss, which breaks SMTP authentication. The value goes back into the form, so every later save added more slashes (pa\\\'ss), andO'Brieninsmtp_namereached the From header asO\'Brien. The submitted values now go throughwp_unslash()before sanitizing, which is also what PHPCS asked for.check_admin_referer()with the same nonce. PHPCS did not flag this because its nonce sniff accepts any verification earlier in the same function, including the one inside the save branch.add_submenu_page()with anullparent and a callback that was never defined. Openingwp-admin/admin.php?page=wpss-test-emailended in a fatal error (call_user_func_array(): Argument #1 ($callback) must be a valid callback). The test email form already lives on the settings page, so the hidden page was removed.Verification
composer cipasses locally.pa'ssandO'Brienunchanged (before: one more level of slashes per save); a test email post without the nonce stops atwp_die()and sends nothing, and with the nonce it is sent.wp_mail()goes out over SMTP with the configured host, port and From, and arrives in Mailpit; the settings page renders all 13 fields.