PHP Warning: Undefined array key “html” in EmbedPressBlockRenderer.php 1672
-
Hi,
I’m getting a recurring PHP warning from EmbedPress on a production site.
Environment
- EmbedPress 4.6.6 (free version, no Pro)
- WordPress 7.1.1
- PHP 8.3.31
- Rank Math SEO (generates the XML sitemaps)
The warning
PHP Warning: Undefined array key “html” in
/wp-content/plugins/embedpress/EmbedPress/Gutenberg/EmbedPressBlockRenderer.php on line 1672It fires about 90 times a day (373 times over the last four days). Around 97% of the
occurrences happen while Rank Math renders the XML sitemaps (/post-sitemap5.xml and
similar, requested by search engine crawlers), the rest on single blog posts that
contain Facebook and Instagram embeds.The cause
In render_displayable_content() (line 1656), $embed can be either a string or an array,
and the array is not guaranteed to contain an ‘html’ key:if (is_array($embed)) { echo $embed['html']; // line 1672 } else { echo $embed; }Two more spots in the same function make the same assumption:
- Line 1661: $embed[‘html’] .= $styling[‘custom_branding’][‘html’];
Same undefined key warning when custom branding is enabled. - Line 1668: $embed .= Helper::embed_content_share($content_id, $attributes);
This concatenates a string onto $embed without checking whether it is an array. On
PHP 8 that is a fatal TypeError (“Unsupported operand types: array . string”), not a
warning. I have not hit it, presumably because content share is disabled here, but it
looks like a crash waiting to happen for anyone who enables that option on a provider
that returns an array.
Suggested fix
Normalising $embed to a string once, at the top of the function, would fix all three:private static function render_displayable_content($embed, $content_share, $content_id, $attributes, $styling = []) { $html = is_array($embed) ? ($embed['html'] ?? '') : (string) $embed; if (!empty($styling['custom_branding']['html'])) { $html .= $styling['custom_branding']['html']; } if (!empty($content_share)) { $html .= Helper::embed_content_share($content_id, $attributes); } echo $html; }One question: is it expected for a provider to return an array without an ‘html’ key, or
does that point to an upstream problem in how the embed is fetched? If the array is
malformed, silencing the warning would only hide the real issue.I’m happy to test a patch on this site if that helps.
Thanks!
You must be logged in to reply to this topic.