如何在WordPress Simple Job Board插件中验证求职申请表单文本字段仅含字母
Hey there! Let's tackle how to add strict alphabet-only validation (A-Z, a-z only) to text fields in the WordPress Simple Job Board plugin's application form. This will block malicious characters like |_"' $@!; and help mitigate SQL injection risks, while keeping your form data clean. Here's a step-by-step, practical approach:
Backend validation is non-negotiable because bad actors can easily skip frontend checks. We'll use the plugin's built-in sjb_validate_application_form filter hook to add our custom validation logic.
Add this code to your theme's functions.php file (or a dedicated custom plugin, if you prefer keeping your theme files clean):
add_filter('sjb_validate_application_form', 'custom_sjb_alphabet_only_validation', 10, 2); function custom_sjb_alphabet_only_validation($errors, $form_data) { // List the text fields you want to validate (replace with your actual field names) $target_fields = array('first_name', 'last_name'); foreach ($target_fields as $field) { // Check if the field exists and has content if (isset($form_data[$field]) && !empty(trim($form_data[$field]))) { // Regex to allow only uppercase/lowercase letters (no spaces, numbers, or specials) if (!preg_match('/^[A-Za-z]+$/', $form_data[$field])) { // Add error message for invalid input $errors[$field] = sprintf( __('The %s field can only contain letters (A-Z, a-z).', 'your-text-domain'), ucwords(str_replace('_', ' ', $field)) ); } } } return $errors; }
- Replace
'first_name', 'last_name'with your actual field names (find these by inspecting form inputs in your browser's dev tools). - If you need to allow spaces (e.g., for full names), modify the regex to
^[A-Za-z\s]+$.
Frontend validation gives users immediate feedback without waiting for a page reload. Let's add a lightweight JavaScript snippet to handle this:
Add this code to your theme's functions.php (or enqueue it as a separate JS file for better organization):
add_action('wp_footer', 'custom_sjb_frontend_alphabet_validation'); function custom_sjb_frontend_alphabet_validation() { // Only load this script on job post pages (where the application form lives) if (is_singular('jobpost')) { ?> <script> document.addEventListener('DOMContentLoaded', () => { const form = document.getElementById('sjb-application-form'); if (!form) return; // Match the fields you defined in the backend const targetFields = ['first_name', 'last_name']; form.addEventListener('submit', (e) => { let isFormValid = true; targetFields.forEach(fieldName => { const input = form.querySelector(`[name="${fieldName}"]`); if (!input) return; const inputValue = input.value.trim(); const validRegex = /^[A-Za-z]+$/; // Use /^[A-Za-z\s]+$/ if allowing spaces if (!validRegex.test(inputValue)) { isFormValid = false; // Customize this alert to match your theme's error styling alert(`The ${fieldName.replace('_', ' ')} field can only contain letters (A-Z, a-z).`); input.focus(); } }); if (!isFormValid) e.preventDefault(); }); }); </script> <?php } }
- The script only loads on single job post pages to avoid unnecessary code execution elsewhere.
- It blocks form submission and shows a user-friendly alert if invalid characters are detected.
Don't skip this step! Verify the validation works as expected:
- Try submitting with special characters, numbers, or spaces (if you didn't allow them) — both frontend and backend should block the submission.
- Test with valid letter-only input to ensure legitimate applications go through smoothly.
This dual-layer approach protects your form from malicious inputs while keeping the user experience seamless for genuine applicants.
内容的提问来源于stack exchange,提问作者Mamoon abuzaid

