wp_check_jsonp_callback( string $callback ): bool
- Since
- 4.6.0
- Source
wp-includes/functions.php:4630
Checks that a JSONP callback is a valid JavaScript callback name.
Description
Only allows alphanumeric characters and the dot character in callback function names. This helps to mitigate XSS attacks caused by directly outputting user input.
Parameters
$callbackstring- Supplied JSONP callback function name.
Return
bool- Whether the callback function name is valid.
Used by · 2
- WP_REST_Server::serve_request()Handles serving a REST API request.
- wp_is_jsonp_request()Checks whether current request is a JSONP request, or is expecting a JSONP response.
Source
function wp_check_jsonp_callback( $callback ) { if ( ! is_string( $callback ) ) { return false; } preg_replace( '/[^\w\.]/', '', $callback, -1, $illegal_char_count ); return 0 === $illegal_char_count;}History
Introduced in 4.6.0. Unchanged from 6.7.7 through 7.1.0.
Signature, return type and hooks compared across 5 parsed releases.
About this page
- Parsed data
- Generated from the wordpress-develop 6.8.8 tag, from
src/wp-includes/functions.php, and regenerated for each WordPress release so it tracks the code rather than a snapshot of it. - Corrections
- Something wrong on this page? Report it and it gets fixed in the next regeneration.