]> scripts.mit.edu Git - autoinstalls/wordpress.git/blobdiff - wp-admin/includes/export.php
WordPress 4.7
[autoinstalls/wordpress.git] / wp-admin / includes / export.php
index e9c909d621ea3bfa836292a0c3b3e3fb4f2786a8..f321a56eecb38d0a5dbd815851cfc25328feebea 100644 (file)
 define( 'WXR_VERSION', '1.2' );
 
 /**
- * Generates the WXR export file for download
+ * Generates the WXR export file for download.
+ *
+ * Default behavior is to export all content, however, note that post content will only
+ * be exported for post types with the `can_export` argument enabled. Any posts with the
+ * 'auto-draft' status will be skipped.
  *
  * @since 2.1.0
  *
- * @param array $args Filters defining what should be included in the export
+ * @global wpdb    $wpdb WordPress database abstraction object.
+ * @global WP_Post $post Global `$post`.
+ *
+ * @param array $args {
+ *     Optional. Arguments for generating the WXR export file for download. Default empty array.
+ *
+ *     @type string $content        Type of content to export. If set, only the post content of this post type
+ *                                  will be exported. Accepts 'all', 'post', 'page', 'attachment', or a defined
+ *                                  custom post. If an invalid custom post type is supplied, every post type for
+ *                                  which `can_export` is enabled will be exported instead. If a valid custom post
+ *                                  type is supplied but `can_export` is disabled, then 'posts' will be exported
+ *                                  instead. When 'all' is supplied, only post types with `can_export` enabled will
+ *                                  be exported. Default 'all'.
+ *     @type string $author         Author to export content for. Only used when `$content` is 'post', 'page', or
+ *                                  'attachment'. Accepts false (all) or a specific author ID. Default false (all).
+ *     @type string $category       Category (slug) to export content for. Used only when `$content` is 'post'. If
+ *                                  set, only post content assigned to `$category will be exported. Accepts false
+ *                                  or a specific category slug. Default is false (all categories).
+ *     @type string $start_date     Start date to export content from. Expected date format is 'Y-m-d'. Used only
+ *                                  when `$content` is 'post', 'page' or 'attachment'. Default false (since the
+ *                                  beginning of time).
+ *     @type string $end_date       End date to export content to. Expected date format is 'Y-m-d'. Used only when
+ *                                  `$content` is 'post', 'page' or 'attachment'. Default false (latest publish date).
+ *     @type string $status         Post status to export posts for. Used only when `$content` is 'post' or 'page'.
+ *                                  Accepts false (all statuses except 'auto-draft'), or a specific status, i.e.
+ *                                  'publish', 'pending', 'draft', 'auto-draft', 'future', 'private', 'inherit', or
+ *                                  'trash'. Default false (all statuses except 'auto-draft').
+ * }
  */
 function export_wp( $args = array() ) {
        global $wpdb, $post;
@@ -30,11 +61,31 @@ function export_wp( $args = array() ) {
        );
        $args = wp_parse_args( $args, $defaults );
 
-       do_action( 'export_wp' );
+       /**
+        * Fires at the beginning of an export, before any headers are sent.
+        *
+        * @since 2.3.0
+        *
+        * @param array $args An array of export arguments.
+        */
+       do_action( 'export_wp', $args );
 
        $sitename = sanitize_key( get_bloginfo( 'name' ) );
-       if ( ! empty($sitename) ) $sitename .= '.';
-       $filename = $sitename . 'wordpress.' . date( 'Y-m-d' ) . '.xml';
+       if ( ! empty( $sitename ) ) {
+               $sitename .= '.';
+       }
+       $date = date( 'Y-m-d' );
+       $wp_filename = $sitename . 'wordpress.' . $date . '.xml';
+       /**
+        * Filters the export filename.
+        *
+        * @since 4.4.0
+        *
+        * @param string $wp_filename The name of the file for download.
+        * @param string $sitename    The site name.
+        * @param string $date        Today's date, formatted.
+        */
+       $filename = apply_filters( 'export_wp_filename', $wp_filename, $sitename, $date );
 
        header( 'Content-Description: File Transfer' );
        header( 'Content-Disposition: attachment; filename=' . $filename );
@@ -65,7 +116,7 @@ function export_wp( $args = array() ) {
                }
        }
 
-       if ( 'post' == $args['content'] || 'page' == $args['content'] ) {
+       if ( 'post' == $args['content'] || 'page' == $args['content'] || 'attachment' == $args['content'] ) {
                if ( $args['author'] )
                        $where .= $wpdb->prepare( " AND {$wpdb->posts}.post_author = %d", $args['author'] );
 
@@ -76,23 +127,26 @@ function export_wp( $args = array() ) {
                        $where .= $wpdb->prepare( " AND {$wpdb->posts}.post_date < %s", date( 'Y-m-d', strtotime('+1 month', strtotime($args['end_date'])) ) );
        }
 
-       // grab a snapshot of post IDs, just in case it changes during the export
+       // Grab a snapshot of post IDs, just in case it changes during the export.
        $post_ids = $wpdb->get_col( "SELECT ID FROM {$wpdb->posts} $join WHERE $where" );
 
-       // get the requested terms ready, empty unless posts filtered by category or all content
+       /*
+        * Get the requested terms ready, empty unless posts filtered by category
+        * or all content.
+        */
        $cats = $tags = $terms = array();
        if ( isset( $term ) && $term ) {
                $cat = get_term( $term['term_id'], 'category' );
                $cats = array( $cat->term_id => $cat );
                unset( $term, $cat );
-       } else if ( 'all' == $args['content'] ) {
+       } elseif ( 'all' == $args['content'] ) {
                $categories = (array) get_categories( array( 'get' => 'all' ) );
                $tags = (array) get_tags( array( 'get' => 'all' ) );
 
                $custom_taxonomies = get_taxonomies( array( '_builtin' => false ) );
                $custom_terms = (array) get_terms( $custom_taxonomies, array( 'get' => 'all' ) );
 
-               // put categories in order with no child going before its parent
+               // Put categories in order with no child going before its parent.
                while ( $cat = array_shift( $categories ) ) {
                        if ( $cat->parent == 0 || isset( $cats[$cat->parent] ) )
                                $cats[$cat->term_id] = $cat;
@@ -100,7 +154,7 @@ function export_wp( $args = array() ) {
                                $categories[] = $cat;
                }
 
-               // put terms in order with no child going before its parent
+               // Put terms in order with no child going before its parent.
                while ( $t = array_shift( $custom_terms ) ) {
                        if ( $t->parent == 0 || isset( $terms[$t->parent] ) )
                                $terms[$t->term_id] = $t;
@@ -120,9 +174,9 @@ function export_wp( $args = array() ) {
         * @return string
         */
        function wxr_cdata( $str ) {
-               if ( seems_utf8( $str ) == false )
+               if ( ! seems_utf8( $str ) ) {
                        $str = utf8_encode( $str );
-
+               }
                // $str = ent2ncr(esc_html($str));
                $str = '<![CDATA[' . str_replace( ']]>', ']]]]><![CDATA[>', $str ) . ']]>';
 
@@ -137,10 +191,10 @@ function export_wp( $args = array() ) {
         * @return string Site URL.
         */
        function wxr_site_url() {
-               // ms: the base url
+               // Multisite: the base URL.
                if ( is_multisite() )
                        return network_home_url();
-               // wp: the blog url
+               // WordPress (single site): the blog URL.
                else
                        return get_bloginfo_rss( 'url' );
        }
@@ -156,7 +210,7 @@ function export_wp( $args = array() ) {
                if ( empty( $category->name ) )
                        return;
 
-               echo '<wp:cat_name>' . wxr_cdata( $category->name ) . '</wp:cat_name>';
+               echo '<wp:cat_name>' . wxr_cdata( $category->name ) . "</wp:cat_name>\n";
        }
 
        /**
@@ -170,7 +224,7 @@ function export_wp( $args = array() ) {
                if ( empty( $category->description ) )
                        return;
 
-               echo '<wp:category_description>' . wxr_cdata( $category->description ) . '</wp:category_description>';
+               echo '<wp:category_description>' . wxr_cdata( $category->description ) . "</wp:category_description>\n";
        }
 
        /**
@@ -184,7 +238,7 @@ function export_wp( $args = array() ) {
                if ( empty( $tag->name ) )
                        return;
 
-               echo '<wp:tag_name>' . wxr_cdata( $tag->name ) . '</wp:tag_name>';
+               echo '<wp:tag_name>' . wxr_cdata( $tag->name ) . "</wp:tag_name>\n";
        }
 
        /**
@@ -198,7 +252,7 @@ function export_wp( $args = array() ) {
                if ( empty( $tag->description ) )
                        return;
 
-               echo '<wp:tag_description>' . wxr_cdata( $tag->description ) . '</wp:tag_description>';
+               echo '<wp:tag_description>' . wxr_cdata( $tag->description ) . "</wp:tag_description>\n";
        }
 
        /**
@@ -212,7 +266,7 @@ function export_wp( $args = array() ) {
                if ( empty( $term->name ) )
                        return;
 
-               echo '<wp:term_name>' . wxr_cdata( $term->name ) . '</wp:term_name>';
+               echo '<wp:term_name>' . wxr_cdata( $term->name ) . "</wp:term_name>\n";
        }
 
        /**
@@ -226,19 +280,61 @@ function export_wp( $args = array() ) {
                if ( empty( $term->description ) )
                        return;
 
-               echo '<wp:term_description>' . wxr_cdata( $term->description ) . '</wp:term_description>';
+               echo "\t\t<wp:term_description>" . wxr_cdata( $term->description ) . "</wp:term_description>\n";
+       }
+
+       /**
+        * Output term meta XML tags for a given term object.
+        *
+        * @since 4.6.0
+        *
+        * @param WP_Term $term Term object.
+        */
+       function wxr_term_meta( $term ) {
+               global $wpdb;
+
+               $termmeta = $wpdb->get_results( $wpdb->prepare( "SELECT * FROM $wpdb->termmeta WHERE term_id = %d", $term->term_id ) );
+
+               foreach ( $termmeta as $meta ) {
+                       /**
+                        * Filters whether to selectively skip term meta used for WXR exports.
+                        *
+                        * Returning a truthy value to the filter will skip the current meta
+                        * object from being exported.
+                        *
+                        * @since 4.6.0
+                        *
+                        * @param bool   $skip     Whether to skip the current piece of term meta. Default false.
+                        * @param string $meta_key Current meta key.
+                        * @param object $meta     Current meta object.
+                        */
+                       if ( ! apply_filters( 'wxr_export_skip_termmeta', false, $meta->meta_key, $meta ) ) {
+                               printf( "\t\t<wp:termmeta>\n\t\t\t<wp:meta_key>%s</wp:meta_key>\n\t\t\t<wp:meta_value>%s</wp:meta_value>\n\t\t</wp:termmeta>\n", wxr_cdata( $meta->meta_key ), wxr_cdata( $meta->meta_value ) );
+                       }
+               }
        }
 
        /**
         * Output list of authors with posts
         *
         * @since 3.1.0
+        *
+        * @global wpdb $wpdb WordPress database abstraction object.
+        *
+        * @param array $post_ids Array of post IDs to filter the query by. Optional.
         */
-       function wxr_authors_list() {
+       function wxr_authors_list( array $post_ids = null ) {
                global $wpdb;
 
+               if ( !empty( $post_ids ) ) {
+                       $post_ids = array_map( 'absint', $post_ids );
+                       $and = 'AND ID IN ( ' . implode( ', ', $post_ids ) . ')';
+               } else {
+                       $and = '';
+               }
+
                $authors = array();
-               $results = $wpdb->get_results( "SELECT DISTINCT post_author FROM $wpdb->posts" );
+               $results = $wpdb->get_results( "SELECT DISTINCT post_author FROM $wpdb->posts WHERE post_status != 'auto-draft' $and" );
                foreach ( (array) $results as $result )
                        $authors[] = get_userdata( $result->post_author );
 
@@ -246,18 +342,18 @@ function export_wp( $args = array() ) {
 
                foreach ( $authors as $author ) {
                        echo "\t<wp:author>";
-                       echo '<wp:author_id>' . $author->ID . '</wp:author_id>';
-                       echo '<wp:author_login>' . $author->user_login . '</wp:author_login>';
-                       echo '<wp:author_email>' . $author->user_email . '</wp:author_email>';
+                       echo '<wp:author_id>' . intval( $author->ID ) . '</wp:author_id>';
+                       echo '<wp:author_login>' . wxr_cdata( $author->user_login ) . '</wp:author_login>';
+                       echo '<wp:author_email>' . wxr_cdata( $author->user_email ) . '</wp:author_email>';
                        echo '<wp:author_display_name>' . wxr_cdata( $author->display_name ) . '</wp:author_display_name>';
-                       echo '<wp:author_first_name>' . wxr_cdata( $author->user_firstname ) . '</wp:author_first_name>';
-                       echo '<wp:author_last_name>' . wxr_cdata( $author->user_lastname ) . '</wp:author_last_name>';
+                       echo '<wp:author_first_name>' . wxr_cdata( $author->first_name ) . '</wp:author_first_name>';
+                       echo '<wp:author_last_name>' . wxr_cdata( $author->last_name ) . '</wp:author_last_name>';
                        echo "</wp:author>\n";
                }
        }
 
        /**
-        * Ouput all navigation menu terms
+        * Output all navigation menu terms
         *
         * @since 3.1.0
         */
@@ -267,7 +363,10 @@ function export_wp( $args = array() ) {
                        return;
 
                foreach ( $nav_menus as $menu ) {
-                       echo "\t<wp:term><wp:term_id>{$menu->term_id}</wp:term_id><wp:term_taxonomy>nav_menu</wp:term_taxonomy><wp:term_slug>{$menu->slug}</wp:term_slug>";
+                       echo "\t<wp:term>";
+                       echo '<wp:term_id>' . intval( $menu->term_id ) . '</wp:term_id>';
+                       echo '<wp:term_taxonomy>nav_menu</wp:term_taxonomy>';
+                       echo '<wp:term_slug>' . wxr_cdata( $menu->slug ) . '</wp:term_slug>';
                        wxr_term_name( $menu );
                        echo "</wp:term>\n";
                }
@@ -279,7 +378,7 @@ function export_wp( $args = array() ) {
         * @since 2.3.0
         */
        function wxr_post_taxonomy() {
-               global $post;
+               $post = get_post();
 
                $taxonomies = get_object_taxonomies( $post->post_type );
                if ( empty( $taxonomies ) )
@@ -291,6 +390,12 @@ function export_wp( $args = array() ) {
                }
        }
 
+       /**
+        *
+        * @param bool   $return_me
+        * @param string $meta_key
+        * @return bool
+        */
        function wxr_filter_postmeta( $return_me, $meta_key ) {
                if ( '_edit_lock' == $meta_key )
                        $return_me = true;
@@ -337,89 +442,169 @@ function export_wp( $args = array() ) {
        <wp:base_site_url><?php echo wxr_site_url(); ?></wp:base_site_url>
        <wp:base_blog_url><?php bloginfo_rss( 'url' ); ?></wp:base_blog_url>
 
-<?php wxr_authors_list(); ?>
+<?php wxr_authors_list( $post_ids ); ?>
 
 <?php foreach ( $cats as $c ) : ?>
-       <wp:category><wp:term_id><?php echo $c->term_id ?></wp:term_id><wp:category_nicename><?php echo $c->slug; ?></wp:category_nicename><wp:category_parent><?php echo $c->parent ? $cats[$c->parent]->slug : ''; ?></wp:category_parent><?php wxr_cat_name( $c ); ?><?php wxr_category_description( $c ); ?></wp:category>
+       <wp:category>
+               <wp:term_id><?php echo intval( $c->term_id ); ?></wp:term_id>
+               <wp:category_nicename><?php echo wxr_cdata( $c->slug ); ?></wp:category_nicename>
+               <wp:category_parent><?php echo wxr_cdata( $c->parent ? $cats[$c->parent]->slug : '' ); ?></wp:category_parent>
+               <?php wxr_cat_name( $c );
+               wxr_category_description( $c );
+               wxr_term_meta( $c ); ?>
+       </wp:category>
 <?php endforeach; ?>
 <?php foreach ( $tags as $t ) : ?>
-       <wp:tag><wp:term_id><?php echo $t->term_id ?></wp:term_id><wp:tag_slug><?php echo $t->slug; ?></wp:tag_slug><?php wxr_tag_name( $t ); ?><?php wxr_tag_description( $t ); ?></wp:tag>
+       <wp:tag>
+               <wp:term_id><?php echo intval( $t->term_id ); ?></wp:term_id>
+               <wp:tag_slug><?php echo wxr_cdata( $t->slug ); ?></wp:tag_slug>
+               <?php wxr_tag_name( $t );
+               wxr_tag_description( $t );
+               wxr_term_meta( $t ); ?>
+       </wp:tag>
 <?php endforeach; ?>
 <?php foreach ( $terms as $t ) : ?>
-       <wp:term><wp:term_id><?php echo $t->term_id ?></wp:term_id><wp:term_taxonomy><?php echo $t->taxonomy; ?></wp:term_taxonomy><wp:term_slug><?php echo $t->slug; ?></wp:term_slug><wp:term_parent><?php echo $t->parent ? $terms[$t->parent]->slug : ''; ?></wp:term_parent><?php wxr_term_name( $t ); ?><?php wxr_term_description( $t ); ?></wp:term>
+       <wp:term>
+               <wp:term_id><?php echo wxr_cdata( $t->term_id ); ?></wp:term_id>
+               <wp:term_taxonomy><?php echo wxr_cdata( $t->taxonomy ); ?></wp:term_taxonomy>
+               <wp:term_slug><?php echo wxr_cdata( $t->slug ); ?></wp:term_slug>
+               <wp:term_parent><?php echo wxr_cdata( $t->parent ? $terms[$t->parent]->slug : '' ); ?></wp:term_parent>
+               <?php wxr_term_name( $t );
+               wxr_term_description( $t );
+               wxr_term_meta( $t ); ?>
+       </wp:term>
 <?php endforeach; ?>
 <?php if ( 'all' == $args['content'] ) wxr_nav_menu_terms(); ?>
 
-       <?php do_action( 'rss2_head' ); ?>
+       <?php
+       /** This action is documented in wp-includes/feed-rss2.php */
+       do_action( 'rss2_head' );
+       ?>
 
 <?php if ( $post_ids ) {
+       /**
+        * @global WP_Query $wp_query
+        */
        global $wp_query;
-       $wp_query->in_the_loop = true; // Fake being in the loop.
 
-       // fetch 20 posts at a time rather than loading the entire table into memory
+       // Fake being in the loop.
+       $wp_query->in_the_loop = true;
+
+       // Fetch 20 posts at a time rather than loading the entire table into memory.
        while ( $next_posts = array_splice( $post_ids, 0, 20 ) ) {
        $where = 'WHERE ID IN (' . join( ',', $next_posts ) . ')';
        $posts = $wpdb->get_results( "SELECT * FROM {$wpdb->posts} $where" );
 
-       // Begin Loop
+       // Begin Loop.
        foreach ( $posts as $post ) {
                setup_postdata( $post );
                $is_sticky = is_sticky( $post->ID ) ? 1 : 0;
 ?>
        <item>
-               <title><?php echo apply_filters( 'the_title_rss', $post->post_title ); ?></title>
+               <title><?php
+                       /** This filter is documented in wp-includes/feed.php */
+                       echo apply_filters( 'the_title_rss', $post->post_title );
+               ?></title>
                <link><?php the_permalink_rss() ?></link>
                <pubDate><?php echo mysql2date( 'D, d M Y H:i:s +0000', get_post_time( 'Y-m-d H:i:s', true ), false ); ?></pubDate>
-               <dc:creator><?php echo get_the_author_meta( 'login' ); ?></dc:creator>
-               <guid isPermaLink="false"><?php esc_url( the_guid() ); ?></guid>
+               <dc:creator><?php echo wxr_cdata( get_the_author_meta( 'login' ) ); ?></dc:creator>
+               <guid isPermaLink="false"><?php the_guid(); ?></guid>
                <description></description>
-               <content:encoded><?php echo wxr_cdata( apply_filters( 'the_content_export', $post->post_content ) ); ?></content:encoded>
-               <excerpt:encoded><?php echo wxr_cdata( apply_filters( 'the_excerpt_export', $post->post_excerpt ) ); ?></excerpt:encoded>
-               <wp:post_id><?php echo $post->ID; ?></wp:post_id>
-               <wp:post_date><?php echo $post->post_date; ?></wp:post_date>
-               <wp:post_date_gmt><?php echo $post->post_date_gmt; ?></wp:post_date_gmt>
-               <wp:comment_status><?php echo $post->comment_status; ?></wp:comment_status>
-               <wp:ping_status><?php echo $post->ping_status; ?></wp:ping_status>
-               <wp:post_name><?php echo $post->post_name; ?></wp:post_name>
-               <wp:status><?php echo $post->post_status; ?></wp:status>
-               <wp:post_parent><?php echo $post->post_parent; ?></wp:post_parent>
-               <wp:menu_order><?php echo $post->menu_order; ?></wp:menu_order>
-               <wp:post_type><?php echo $post->post_type; ?></wp:post_type>
-               <wp:post_password><?php echo $post->post_password; ?></wp:post_password>
-               <wp:is_sticky><?php echo $is_sticky; ?></wp:is_sticky>
+               <content:encoded><?php
+                       /**
+                        * Filters the post content used for WXR exports.
+                        *
+                        * @since 2.5.0
+                        *
+                        * @param string $post_content Content of the current post.
+                        */
+                       echo wxr_cdata( apply_filters( 'the_content_export', $post->post_content ) );
+               ?></content:encoded>
+               <excerpt:encoded><?php
+                       /**
+                        * Filters the post excerpt used for WXR exports.
+                        *
+                        * @since 2.6.0
+                        *
+                        * @param string $post_excerpt Excerpt for the current post.
+                        */
+                       echo wxr_cdata( apply_filters( 'the_excerpt_export', $post->post_excerpt ) );
+               ?></excerpt:encoded>
+               <wp:post_id><?php echo intval( $post->ID ); ?></wp:post_id>
+               <wp:post_date><?php echo wxr_cdata( $post->post_date ); ?></wp:post_date>
+               <wp:post_date_gmt><?php echo wxr_cdata( $post->post_date_gmt ); ?></wp:post_date_gmt>
+               <wp:comment_status><?php echo wxr_cdata( $post->comment_status ); ?></wp:comment_status>
+               <wp:ping_status><?php echo wxr_cdata( $post->ping_status ); ?></wp:ping_status>
+               <wp:post_name><?php echo wxr_cdata( $post->post_name ); ?></wp:post_name>
+               <wp:status><?php echo wxr_cdata( $post->post_status ); ?></wp:status>
+               <wp:post_parent><?php echo intval( $post->post_parent ); ?></wp:post_parent>
+               <wp:menu_order><?php echo intval( $post->menu_order ); ?></wp:menu_order>
+               <wp:post_type><?php echo wxr_cdata( $post->post_type ); ?></wp:post_type>
+               <wp:post_password><?php echo wxr_cdata( $post->post_password ); ?></wp:post_password>
+               <wp:is_sticky><?php echo intval( $is_sticky ); ?></wp:is_sticky>
 <?php  if ( $post->post_type == 'attachment' ) : ?>
-               <wp:attachment_url><?php echo wp_get_attachment_url( $post->ID ); ?></wp:attachment_url>
+               <wp:attachment_url><?php echo wxr_cdata( wp_get_attachment_url( $post->ID ) ); ?></wp:attachment_url>
 <?php  endif; ?>
 <?php  wxr_post_taxonomy(); ?>
 <?php  $postmeta = $wpdb->get_results( $wpdb->prepare( "SELECT * FROM $wpdb->postmeta WHERE post_id = %d", $post->ID ) );
                foreach ( $postmeta as $meta ) :
+                       /**
+                        * Filters whether to selectively skip post meta used for WXR exports.
+                        *
+                        * Returning a truthy value to the filter will skip the current meta
+                        * object from being exported.
+                        *
+                        * @since 3.3.0
+                        *
+                        * @param bool   $skip     Whether to skip the current post meta. Default false.
+                        * @param string $meta_key Current meta key.
+                        * @param object $meta     Current meta object.
+                        */
                        if ( apply_filters( 'wxr_export_skip_postmeta', false, $meta->meta_key, $meta ) )
                                continue;
                ?>
                <wp:postmeta>
-                       <wp:meta_key><?php echo $meta->meta_key; ?></wp:meta_key>
+                       <wp:meta_key><?php echo wxr_cdata( $meta->meta_key ); ?></wp:meta_key>
                        <wp:meta_value><?php echo wxr_cdata( $meta->meta_value ); ?></wp:meta_value>
                </wp:postmeta>
-<?php  endforeach; ?>
-<?php  $comments = $wpdb->get_results( $wpdb->prepare( "SELECT * FROM $wpdb->comments WHERE comment_post_ID = %d AND comment_approved <> 'spam'", $post->ID ) );
+<?php  endforeach;
+
+               $_comments = $wpdb->get_results( $wpdb->prepare( "SELECT * FROM $wpdb->comments WHERE comment_post_ID = %d AND comment_approved <> 'spam'", $post->ID ) );
+               $comments = array_map( 'get_comment', $_comments );
                foreach ( $comments as $c ) : ?>
                <wp:comment>
-                       <wp:comment_id><?php echo $c->comment_ID; ?></wp:comment_id>
+                       <wp:comment_id><?php echo intval( $c->comment_ID ); ?></wp:comment_id>
                        <wp:comment_author><?php echo wxr_cdata( $c->comment_author ); ?></wp:comment_author>
-                       <wp:comment_author_email><?php echo $c->comment_author_email; ?></wp:comment_author_email>
+                       <wp:comment_author_email><?php echo wxr_cdata( $c->comment_author_email ); ?></wp:comment_author_email>
                        <wp:comment_author_url><?php echo esc_url_raw( $c->comment_author_url ); ?></wp:comment_author_url>
-                       <wp:comment_author_IP><?php echo $c->comment_author_IP; ?></wp:comment_author_IP>
-                       <wp:comment_date><?php echo $c->comment_date; ?></wp:comment_date>
-                       <wp:comment_date_gmt><?php echo $c->comment_date_gmt; ?></wp:comment_date_gmt>
+                       <wp:comment_author_IP><?php echo wxr_cdata( $c->comment_author_IP ); ?></wp:comment_author_IP>
+                       <wp:comment_date><?php echo wxr_cdata( $c->comment_date ); ?></wp:comment_date>
+                       <wp:comment_date_gmt><?php echo wxr_cdata( $c->comment_date_gmt ); ?></wp:comment_date_gmt>
                        <wp:comment_content><?php echo wxr_cdata( $c->comment_content ) ?></wp:comment_content>
-                       <wp:comment_approved><?php echo $c->comment_approved; ?></wp:comment_approved>
-                       <wp:comment_type><?php echo $c->comment_type; ?></wp:comment_type>
-                       <wp:comment_parent><?php echo $c->comment_parent; ?></wp:comment_parent>
-                       <wp:comment_user_id><?php echo $c->user_id; ?></wp:comment_user_id>
+                       <wp:comment_approved><?php echo wxr_cdata( $c->comment_approved ); ?></wp:comment_approved>
+                       <wp:comment_type><?php echo wxr_cdata( $c->comment_type ); ?></wp:comment_type>
+                       <wp:comment_parent><?php echo intval( $c->comment_parent ); ?></wp:comment_parent>
+                       <wp:comment_user_id><?php echo intval( $c->user_id ); ?></wp:comment_user_id>
 <?php          $c_meta = $wpdb->get_results( $wpdb->prepare( "SELECT * FROM $wpdb->commentmeta WHERE comment_id = %d", $c->comment_ID ) );
-                       foreach ( $c_meta as $meta ) : ?>
+                       foreach ( $c_meta as $meta ) :
+                               /**
+                                * Filters whether to selectively skip comment meta used for WXR exports.
+                                *
+                                * Returning a truthy value to the filter will skip the current meta
+                                * object from being exported.
+                                *
+                                * @since 4.0.0
+                                *
+                                * @param bool   $skip     Whether to skip the current comment meta. Default false.
+                                * @param string $meta_key Current meta key.
+                                * @param object $meta     Current meta object.
+                                */
+                               if ( apply_filters( 'wxr_export_skip_commentmeta', false, $meta->meta_key, $meta ) ) {
+                                       continue;
+                               }
+                       ?>
                        <wp:commentmeta>
-                               <wp:meta_key><?php echo $meta->meta_key; ?></wp:meta_key>
+                               <wp:meta_key><?php echo wxr_cdata( $meta->meta_key ); ?></wp:meta_key>
                                <wp:meta_value><?php echo wxr_cdata( $meta->meta_value ); ?></wp:meta_value>
                        </wp:commentmeta>
 <?php          endforeach; ?>