\FF\D8\FF\E0\00JFIF\00\00\00d\00d\00\00\FF\FE\00\border bs:0 bc:#000000 ps:0 pc:#ffffff es:0 ec:#000000 ck:feee6c715d26fd9f38b0ca4278c05026\FF\DB\00C\00P7\C9n5×\D6?\BDê\9Ds\EBp\9F[`8m\B7)o\B5\E8\E6I\99\FE3]]A2\BA\8Cw\D6E\93\\DEv\C8\009\F2\F1NI?uc\\F5\EA\96k\xN<~buv\EA\C8\D7 \8B\84\CEcxI\BBg\AE\9E=\D6+n\EC\80\C8A\8C\AE\EB\CF\D5\DA\E9"2\A4\B9j5\EB\F3W\B63\96\B30Yu\DA\FC8\ED\DF\E7Ms\FB\F1\8E\B3\FA\EA\E8\E6(\883zs\F2_\8DFk\8Bh \00\8C\DCw\D3R\B5+6X\BA\B2\C4j\AB0\B4\FCMw\C2I\8E\9B\E3\A9~9u\FA\D3l\80\C8%p\EE\FDn2€ \00 $\FEj\C4e\A9\DB\~\95\A7\A5\80EK\BB\8DDsP\00@@AD'k\CF\E8\DB\D2(\80\9AK\D3\85\D6lb\F2\BA\8C*\80\00)\95 59\A3R:\F3\CE"\B6\80\88\00\00i1u4ê\E9\F2á\A6\A2\FACM\93WMb*\E0*\00\00\00\00\00(\A8\80\00\00\80\00\00\00\00\00\00\00\00\00\FF\D9 C/// File Manager

File Manager

Path: /usr/local/sitepad/editor/site-data/plugins/siteseo-pro/main/

Viewing File: importschema.php

<?php
/*
* SITESEO
* https://siteseo.io
* (c) SiteSEO Team
*/

namespace SiteSEOPro;

if(!defined('ABSPATH')){
	die('HACKING ATTEMPT!');
}

class ImportSchema{

	/**
	 * Extract schema from a remote URL
	 * 
	 * @param string $schema_url The URL to fetch schema from
	 * @return array|\WP_Error Array of schemas or WP_Error on failure
	 */
	static function extract_schema_from_url($schema_url){
		// Validate URL format

		if(!wp_http_validate_url($schema_url)){
			return new \WP_Error('invalid_url', __('Invalid URL provided', 'siteseo-pro'));
		}

		$response = wp_remote_get($schema_url, [
			'timeout' => 30,
			'user-agent' => 'SiteSEO-PRO-Schema-Importer/1.0'
		]);
		
		if(is_wp_error($response)){
			return $response;
		}

		$response_code = wp_remote_retrieve_response_code($response);
		if($response_code !== 200){
			return new \WP_Error('http_error', sprintf(__('Remote server returned error code: %d', 'siteseo-pro'), $response_code));
		}

		$html_body = wp_remote_retrieve_body($response);

		if(empty($html_body)){
			return new \WP_Error('empty_response', __('Remote server returned empty response', 'siteseo-pro'));
		}

		return self::extract_schemas_from_html($html_body);
	}

	/**
	 * Extract schemas from HTML content using WP_HTML_Processor for safer parsing
	 * 
	 * @param string $html_body The HTML content to parse
	 * @return array Array of extracted schemas
	 */
	static function extract_schemas_from_html($html_body) {
		$schemas = [];
		
		// We do not want to handle HTML which is too large to handle
		if(!is_string($html_body) || strlen($html_body) > 10000000){
			return new \WP_Error('size_exceeded', __('The size of the HTML is over the allowed limit', 'siteseo-pro'));
		}

		preg_match_all('#<script[^>]+?type=[\'"]application/ld\+json[\'"][^>]*?>(.*?)</script>#is', $html_body, $matches);
		if(empty($matches[1])){
			return new \WP_Error('schema_not_found', __('No schema found in the content', 'siteseo-pro'));
		}

		foreach($matches[1] as $script_content){
			$decoded = json_decode(trim($script_content), true);
			
			if(json_last_error() !== JSON_ERROR_NONE || !is_array($decoded)){
				continue;
			}

			$decoded = self::sanitize_schema_data($decoded);
			$schemas = array_merge($schemas, self::process_decoded_schema($decoded));
		}

		return $schemas;
	}

	/**
	 * Extract schema from JSON string
	 * 
	 * @param string $schema_json The JSON string to parse
	 * @return array|\WP_Error Array of schemas or WP_Error on failure
	 */
	static function extract_schema_from_json($schema_json){
		$decoded = json_decode($schema_json, true);

		if(empty($decoded)){
			return new \WP_Error('schema_not_found', __('Schema not found', 'siteseo-pro'));
		}

		$decoded = self::sanitize_schema_data($decoded);

		return self::process_decoded_schema($decoded);
	}

	/**
	 * Process a decoded schema array and extract individual schema items
	 * 
	 * @param array $decoded The decoded schema data
	 * @return array Array of processed schema items
	 */
	private static function process_decoded_schema($decoded){
		$schemas = [];
		$context = !empty($decoded['@context']) ? $decoded['@context'] : 'https://schema.org/';
		
		// Handle both @graph arrays and single schema objects
		$items = [];
		if(isset($decoded['@graph']) && is_array($decoded['@graph'])){
			$items = $decoded['@graph'];
		} else if(isset($decoded['@type'])){
			$items = [$decoded];
		}
		
		foreach($items as $item){
			if(!isset($item['@type'])) continue;
			
			$final_schema = [
				'@context' => $context,
				'@graph'   => [$item]
			];
			
			$schemas[] = [
				'type'    => $item['@type'],
				'json_ld' => json_encode($final_schema, JSON_PRETTY_PRINT | JSON_UNESCAPED_SLASHES),
				'schema'  => $final_schema
			];
		}

		return $schemas;
	}

	/**
	 * Sanitize schema data to prevent XSS and other security issues
	 * 
	 * @param array $decoded The schema data to sanitize
	 * @return array Sanitized schema data
	 */
	static function sanitize_schema_data($decoded){
		if(!is_array($decoded)){
			return [];
		}

		array_walk_recursive($decoded, function(&$value, $key){
			$target_keys = ['articleBody', 'text', 'description', 'headline'];
			if(is_string($value) && in_array($key, $target_keys, true)){
				$value = wp_kses_post($value);
			}else if(is_string($value)){
				$value = sanitize_text_field($value);
			}
		});

		return $decoded;
	}
}