Skip to content

Prevent fatal error in wp_get_image_alttext() when DOM extension is missing - #13879

Open
robelsust wants to merge 2 commits into
WordPress:trunkfrom
robelsust:trac-66221
Open

robelsust wants to merge 2 commits into
WordPress:trunkfrom
robelsust:trac-66221

Conversation

@robelsust

Copy link
Copy Markdown

Trac ticket: https://core.trac.wordpress.org/ticket/66221

When uploading an image (or when reading image metadata via wp_read_image_metadata()), wp_get_image_alttext() is invoked to extract alternative text embedded in XMP metadata.

Currently, wp_get_image_alttext() instantiates new DOMDocument() and new DOMXPath() without verifying if PHP's dom extension (ext-dom) is installed or available on the host environment:

Fatal error: Uncaught Error: Class "DOMDocument" not found in .../wp-admin/includes/image.php

While PHP's dom extension is strongly recommended by WordPress hosting requirements, it is not strictly required across all minimal hosting environments. WordPress core provides guards in other areas (such as iis7_rewrite_rule_exists(), wp_oembed_get(), and WP_Widget_Text) using class_exists( 'DOMDocument', false ).

Changes Proposed

  1. Guard wp_get_image_alttext() against missing DOMDocument or DOMXPath classes early at the beginning of the function:
    if ( ! class_exists( 'DOMDocument', false ) || ! class_exists( 'DOMXPath', false ) ) {
        return $alt_text;
    }
    Checking at the start of the function rather than immediately before DOM instantiation also avoids reading large image files into memory via file_get_contents() and running string searches when the metadata cannot be parsed.
  2. Add @covers ::wp_get_image_alttext and unit tests in tests/phpunit/tests/image/meta.php:
    • test_wp_get_image_alttext(): Tests extraction with a valid IPTC/XMP test image.
    • test_wp_get_image_alttext_without_xmp(): Tests fallback with an image containing no XMP metadata.

Testing Instructions

  1. Run PHPUnit test suite:
    vendor/bin/phpunit tests/phpunit/tests/image/meta.php
  2. Verify all assertions pass.
  3. On an environment without ext-dom, verify that uploading an image or calling wp_read_image_metadata() completes without a fatal error.

AI Disclosure: Code changes and documentation were prepared with AI assistance, verified and tested manually against WordPress Core coding standards and PHPUnit test suite.

Prevents a fatal error when uploading an image or extracting alt text in environments where the DOM extension (DOMDocument or DOMXPath) is not available.

Props therssoftware.
Fixes #66221.
@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the props-bot label.

Core Committers: Use this line as a base for the props when committing in SVN:

Props therssoftware, jorbin.

To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

Test using WordPress Playground

The changes in this pull request can previewed and tested using a WordPress Playground instance.

WordPress Playground is an experimental project that creates a full WordPress instance entirely within the browser.

Some things to be aware of

  • All changes will be lost when closing a tab with a Playground instance.
  • All changes will be lost when refreshing the page.
  • A fresh instance is created each time the link below is clicked.
  • Every time this pull request is updated, a new ZIP file containing all changes is created. If changes are not reflected in the Playground instance,
    it's possible that the most recent build failed, or has not completed. Check the list of workflow runs to be sure.

For more details about these limitations and more, check out the Limitations page in the WordPress Playground documentation.

Test this pull request with WordPress Playground.

@aaronjorbin aaronjorbin left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For the tests, it would be best to be thorough. The code notes that there are three possibilities for alt text, so each of those should get tested. Additionally, the tests will return different alt text based on the site local, that functionality should be tested.

Comment thread src/wp-admin/includes/image.php Outdated
@@ -1086,7 +1086,12 @@ function wp_read_image_metadata( $file ) {
* @return string Embedded alternative text.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
* @return string Embedded alternative text.
* @return string Embedded alternative text, empty when there is no alt text or DOM extension is not installed.

I think the empty string should get noted.

Comment thread tests/phpunit/tests/image/meta.php Outdated
$this->assertSame( 'This is the Alt Text description to support accessibility in 2025.1', $out['alt'], 'Alt text does not match source.' );
}

/**

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These should go in their own test file since they are testing something else. tests/phpunit/tests/image/alttext.php feels like is a good choice

Comment thread tests/phpunit/tests/image/meta.php Outdated
*
* @covers ::wp_get_image_alttext
*/
public function test_wp_get_image_alttext() {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Since this will return an empty string when Dom is not available, it should be properly handled in the test as well.

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the thorough review and guidance, @aaronjorbin!

I have addressed all the feedback:

  1. DocBlock: Updated the @return tag description for wp_get_image_alttext() to note that an empty string is returned when alt text is absent or the DOM extension is not installed.
  2. Dedicated Test File: Moved the tests out of meta.php into a dedicated test class at tests/phpunit/tests/image/alttext.php.
  3. Thorough Test Coverage:
    • Possibility 1: Exact match on site locale (e.g. de_DE).
    • Possibility 2: Partial match on site locale (e.g. es_ES matching xml:lang="es").
    • Possibility 3: Fallback to x-default when neither exact nor partial locale matches.
    • Tested that switching site locales returns the corresponding localized alt text.
    • Tested edge cases (missing XMP, missing AltTextAccessibility node).
  4. DOM Availability: All tests verify the extracted text when DOM is present, while gracefully expecting an empty string if the DOM extension is not installed on the test environment.

… DocBlock.

- Updates the DocBlock return description in wp_get_image_alttext() to note empty string return when DOM is unavailable or alt text is missing.
- Moves alt text tests from meta.php into tests/phpunit/tests/image/alttext.php.
- Adds test cases for exact locale match, partial locale match, and x-default fallback.
- Adds test coverage for returning different alt text when switching site locales.
- Gracefully handles test assertions in environments where ext-dom is not available.

See #66221.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants