Download the PHP package pinkcrab/wp-nonce without Composer

On this page you can find all versions of the php package pinkcrab/wp-nonce. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package wp-nonce

Nonce

A minimal object-based wrapper around the WordPress Nonce API. Each Nonce instance holds an action and a lazily-generated token, and exposes helpers for URL decoration, form-field rendering, validation, and admin-referer checks. Instances are serialisable so you can pass them through the request lifecycle without regenerating the token.

Latest Stable Version Total Downloads License PHP Version Require GitHub contributors GitHub issues

WP 6.6 [PHP8.0-8.4] Tests WP 6.7 [PHP8.0-8.4] Tests WP 6.8 [PHP8.0-8.4] Tests WP 6.9 [PHP8.0-8.4] Tests

codecov Scrutinizer Code Quality

For more details please visit the docs site: https://perique.info/lib/WP_Nonce.html

Why?

WordPress's native nonce API is procedural — wp_create_nonce(), wp_verify_nonce(), wp_nonce_field(), check_admin_referer() — and leaves the caller to juggle the action handle alongside the token at every touch-point. In practice nonces are a single unit: one action string, one token, one lifecycle. This library wraps that unit in a small class so it can be passed around, serialised, and stored alongside whatever else needs the nonce (a form model, an AJAX endpoint spec, a REST request builder).

Install

Then include the Composer autoloader in your project:

Usage

Methods (Setters)

__construct

__construct( string $action )

@param string $action The action handle that scopes the nonce (same semantics as WordPress's wp_create_nonce($action)).

Creates a nonce instance bound to a single action handle. The token is generated lazily on first access.

Example

Methods (Getters & Helpers)

token

token(): string

@return string The nonce token string, generated via wp_create_nonce() the first time it's called.

Returns the nonce token. Matches what wp_create_nonce($action) would produce for the same action.

Example

as_url

as_url( string $url, string $arg = '_wpnonce' ): string

@param string $url The base URL to append the nonce to.
@param string $arg Query-string parameter name the nonce is appended as. Defaults to _wpnonce.
@return string The URL with ?<arg>=<token> (or &<arg>=<token>) appended.

Appends the nonce token to a URL as a query-string parameter. Handles both URLs without an existing query string and URLs that already have one.

Example

This does not use the admin-referer mechanism — for that use admin_referer() below.

nonce_field

nonce_field( string $name = '_wpnonce' ): string

@param string $name The input name/id used for the hidden field. Defaults to _wpnonce.
@return string The HTML for a hidden <input> containing the nonce token.

Returns (does not echo) the HTML for a hidden <input> carrying the nonce token. Useful for form-building code that prefers to compose output itself.

Example

The nonce field is returned, not echoed. Call echo yourself.

validate

validate( string $nonce ): bool

@param string $nonce The token string to validate against the nonce's action.
@return bool true if the token matches; false otherwise.

Validates a token string against the nonce's action. Returns true for a match, false otherwise. Wraps wp_verify_nonce() with a strict-bool return.

Example

admin_referer

admin_referer( string $name = '_wpnonce' ): bool

@param string $name The $_REQUEST key holding the nonce. Defaults to _wpnonce.
@return bool true if the admin-referer check passes.

Runs WordPress's check_admin_referer() against the token found in $_REQUEST[$name]. Returns true on success; WordPress itself will wp_die() on failure (which in tests throws WPDieException).

Example

Serialisation

Nonce implements Serializable (via PHP's magic methods), so instances can be stored alongside other request state and recovered later without regenerating the token:

Tested Against

License

MIT License

http://www.opensource.org/licenses/mit-license.html

Change Log


All versions of wp-nonce with dependencies

PHP Build Version
Package Version
Requires php Version >=8.0.0
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package pinkcrab/wp-nonce contains the following files

Loading the files please wait ...