Hi,
I just read the "Write your Snippets outside of MODx" and this tutorial doesn’t seem like a secure solution.
Here’s the link(scroll to Write your Snippets outside of MODx):
http://rtfm.modx.com/display/revolution20/Snippets
I think that if do it like this, than someone might guess your snippet location and run the php code by pointing the browser to your code.
A safer solution is to create a snippet and use a code like this:
<?php
include_once $modx->getOption(’assets_path’).’snippets/getEventsMenu.php’;
return getEventsMenu($categId);
?>
This way the php file contains only a php function and guessing the path to php file will output nothing.
I never tried the solution above as I have my own method but maybe the docs can be updated if this is considered to be a problem.
Thanks