这是从wordpress插件中提取的代码。即使未过滤变量,运行是否安全?wpdb类是否也会过滤以防止任何注入?
list($email_id, $user_id, $url, $anchor) = explode(\';\', base64_decode($_GET[\'r\']), 4);
$wpdb->insert(NEWSLETTER_STATS_TABLE,
array(
\'email_id\' => $email_id,
\'user_id\' => $user_id,
\'url\' => $url,
\'anchor\' => $anchor
)
);