You've already forked wp-bootstrap
5th OWASP Top-10 pass: added |esc_url filter to all unescaped URL outputs across 8 Twig template partials (headers, footers, search, comments). Registered esc_html, esc_attr, esc_url as Twig filters with is_safe option. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
12 lines
463 B
Twig
12 lines
463 B
Twig
<form role="search" method="get" action="{{ site.url|esc_url }}" class="mb-4">
|
|
<div class="input-group">
|
|
<input type="search" class="form-control" name="s"
|
|
placeholder="{{ __('Search...') }}"
|
|
value="{{ search_query is defined ? search_query : '' }}"
|
|
aria-label="{{ __('Search') }}">
|
|
<button class="btn btn-primary" type="submit">
|
|
{{ __('Search') }}
|
|
</button>
|
|
</div>
|
|
</form>
|