As ever with PHP sites validation seems to be a mess. For example we've got a `escapeSupplierName` function[2] used in some places[3], but a different regex used when creating a suppier[4]. Variants of that regex also appear all over the code, why not put it in a single place?
Properly escaping SQL injection is great (and something PHP apps seem to have a continual problem with), but why did you decide to roll your own framework for doing this? Are all of the well maintained, tested and great ones already available not suitable for some reason? It's just your app turns into a hard to check, inefficient[5] sludge, full of lots of code for handling framework related things like an ORM, caching[6] (that code is practically duplicated in a lot of places[7][8][9][10]), escaping[11], mime whitelisting[12] etc and not much about a CMS. This is where security bugs appear.
1. https://github.com/paragonie/airship/blob/eb4293aee5be59e329...
2. https://github.com/paragonie/airship/blob/c4c9384d4d7860738d...
3. https://github.com/paragonie/airship/blob/c4c9384d4d7860738d...
4. https://github.com/paragonie/airship/blob/95af23ca782e8ecb10...
5. https://github.com/paragonie/airship/blob/63cf0661ba21cbb3f3...
6. https://github.com/paragonie/airship/blob/master/src/view_fu...
7. https://github.com/paragonie/airship/blob/master/src/view_fu...
8. https://github.com/paragonie/airship/blob/master/src/view_fu...
9. https://github.com/paragonie/airship/blob/63cf0661ba21cbb3f3...
10. https://github.com/paragonie/airship/blob/2a8a87934921ecda85...
11. https://github.com/paragonie/airship/blob/eb4638eb31510028f4...
12. https://github.com/paragonie/airship/blob/eb4638eb31510028f4...