Skip to content

Fix PHP 8.5 deprecation notices - #327

Merged
Dan0sz merged 2 commits into
developfrom
fix_php85_add_query_arg
Sep 29, 2026
Merged

Dan0sz merged 2 commits into
developfrom
fix_php85_add_query_arg

Conversation

@Dan0sz

@Dan0sz Dan0sz commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

Fixes PHP 8.5 deprecation notices, reported on a site running the 2.6.2 beta:

Deprecated: Using null as an array offset is deprecated, use an empty string instead in wp-includes/functions.php on line 1194

Cause

add_query_arg( null, null ) is used to get the current request URI. Internally WordPress then does $qs[ null ] = null, which PHP 8.5 deprecates. It's called:

  • in Search::get_referrer(), on every page with a search form when Search Queries tracking is enabled;
  • in InitOptions::get_current_request(), on every page as soon as Excluded Pages are configured.

This isn't a regression in 2.6.2: 2.6.1 shows the same notice on PHP 8.5.

Changes

  • Use add_query_arg( [] ) instead. It returns the same request URI, without the null offset.

The bundled Guzzle's curl_close() deprecation on PHP 8.5 is left for a separate PR that updates Guzzle.

Testing

  • Full test suite passes on PHP 8.5 and 8.3.
  • Checked on a live site running PHP 8.5 with display_errors on:
Page with a search form Any page (Excluded Pages set)
2.6.1 notice notice
develop notice notice
this branch none none

The search_source referrer still contains the current URL (including its query string), excluded pages are still excluded, and saving the settings works.

- Use add_query_arg( [] ) instead of add_query_arg( null, null ) to get
  the current request URI. Both return the same, but the latter uses null
  as an array offset, which is deprecated since PHP 8.5 ("Using null as an
  array offset is deprecated" in wp-includes/functions.php), shown on every
  page with a search form when Search Queries tracking is enabled.
- Only call curl_close() on PHP < 8.0 in the bundled Guzzle, like Guzzle
  7.10 does: it has had no effect since PHP 8.0 and is deprecated since
  PHP 8.5, which showed on every API request.
@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 5ef88b22-08ac-405e-9b92-dbf24c5ae216

📥 Commits

Reviewing files that changed from the base of the PR and between 116d03e and f592a97.

📒 Files selected for processing (4)
  • src/Client/lib/Lib/GuzzleHttp/Handler/CurlFactory.php
  • src/Client/lib/Lib/GuzzleHttp/Handler/CurlMultiHandler.php
  • src/InitOptions.php
  • src/Integrations/Search.php

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The cURL handlers now call curl_close() only before PHP 8.0 in the affected cleanup paths. Two request URI calls now pass an empty array to add_query_arg() instead of two null arguments.

Changes

cURL handle cleanup

Layer / File(s) Summary
Versioned cURL handle cleanup
src/Client/lib/Lib/GuzzleHttp/Handler/CurlFactory.php, src/Client/lib/Lib/GuzzleHttp/Handler/CurlMultiHandler.php
The affected cleanup paths call curl_close() only before PHP 8.0. On PHP 8.0 and later, the handlers skip the explicit close.

Request URI calls

Layer / File(s) Summary
Empty-array request URI calls
src/InitOptions.php, src/Integrations/Search.php
get_current_request() and get_referrer() pass [] to add_query_arg() instead of two null arguments. The documentation notes the PHP 8.5 deprecation of the previous form.

Priority: ⬇️ Low

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 4cc39

The changes preserve request URI behavior and follow PHP-version-specific cURL cleanup; no material merge risk remains.

Security Architecture Review

Security architecture risk: 🔵 Low · up to f592a

The reviewed changes appear to preserve the existing page-exclusion, search-referrer, and request-cleanup flows without adding an exposed interface. Risk remains low rather than minimal because runtime equivalence has not been fully verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The visible effects are bounded to current-request URI consumers and cURL handle cleanup in processes running the plugin; the inspected diff adds no caller authority or external service path.

Trust Boundaries and Controls

  • observed — Excluded-page configuration and pattern matching still gate suppression of a pageview.
  • observed — The search referrer remains escaped before it is placed in the hidden search_source attribute.

Resilience and Maintainability Implications

  • inferred — On the inspected normal completion and cancellation paths, PHP 8+ cleanup continues to relinquish the handler's request references rather than retaining them through the removed explicit close call.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 60.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 5 functions across 4 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: fixing PHP 8.5 deprecation notices in the request URI handling and bundled Guzzle code.
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Sep 29, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

src/Client/lib/Lib is generated by Mozart, so hand edits are overwritten
on the next run. The curl_close() deprecation is fixed by updating Guzzle
instead, in a separate PR.
@Dan0sz
Dan0sz merged commit a7513a3 into develop Sep 29, 2026
7 checks passed
@Dan0sz
Dan0sz deleted the fix_php85_add_query_arg branch September 29, 2026 20:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant