78% access-watch

Code Review | Access Watch: Security and Traffic Insights

WordPress plugin Access Watch: Security and Traffic Insights scored 78% from 54 tests.

About plugin

  • Plugin page: access-watch
  • Plugin version: 2.0.0-end-of-life...
  • PHP version: 7.4.16
  • WordPress compatibility: 4.0-4.9.1
  • WordPress version: 6.3.1
  • First release: Feb 8, 2016
  • Latest release: Nov 26, 2018
  • Number of updates: 273
  • Update frequency: every 3.7 days
  • Top authors: znarfor (100%)

Code review

54 tests

User reviews

12 reviews

Install metrics

90+ active / 11,536 total downloads

Benchmarks

Plugin footprint 83% from 16 tests

Installer Passed 1 test

🔺 Critical test (weight: 50) | The install procedure must perform silently
Install script ran successfully

Server metrics [RAM: ▲0.03MB] [CPU: ▼4.95ms] Passed 4 tests

Server-side resources used by Access Watch: Security and Traffic Insights
This plugin has minimal impact on server resources
PageMemory (MB)CPU Time (ms)
Home /3.49 ▲0.0343.51 ▲5.03
Dashboard /wp-admin3.33 ▲0.0348.01 ▼6.03
Posts /wp-admin/edit.php3.38 ▲0.0346.48 ▼0.10
Add New Post /wp-admin/post-new.php5.91 ▲0.0382.89 ▼16.61
Media Library /wp-admin/upload.php3.25 ▲0.0335.22 ▲2.95
About /wp-admin/admin.php?page=access-watch-about3.2231.87
Access Watch /wp-admin/admin.php?page=access-watch-dashboard3.2232.03

Server storage [IO: ▲3.03MB] [DB: ▲0.00MB] Passed 3 tests

Analyzing filesystem and database footprints of this plugin
The plugin installed successfully
Filesystem: 400 new files
Database: no new tables, 7 new options
New WordPress options
access_watch_api_key_registered
widget_theysaidso_widget
widget_recent-comments
theysaidso_admin_options
can_compress_scripts
widget_recent-posts
db_upgraded

Browser metrics Passed 4 tests

Checking browser requirements for Access Watch: Security and Traffic Insights
This plugin has a minimal impact on browser resources
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /2,852 ▲9513.13 ▼1.251.99 ▲0.1045.14 ▲2.17
Dashboard /wp-admin2,230 ▲424.84 ▼1.04113.01 ▲5.9642.35 ▲0.33
Posts /wp-admin/edit.php2,119 ▲302.02 ▲0.0035.21 ▼6.5332.98 ▼2.79
Add New Post /wp-admin/post-new.php1,536 ▲1617.41 ▼5.74655.83 ▼38.5953.99 ▼6.04
Media Library /wp-admin/upload.php1,418 ▲364.24 ▲0.0296.30 ▼11.2443.81 ▼5.99
About /wp-admin/admin.php?page=access-watch-about7862.1822.9424.37
Access Watch /wp-admin/admin.php?page=access-watch-dashboard7982.0623.1027.88

Uninstaller [IO: ▲0.00MB] [DB: ▲0.00MB] 75% from 4 tests

🔸 Tests weight: 35 | Checking the uninstaller removed all traces of the plugin
The following items require your attention
  • The uninstall procedure has failed, leaving 6 options in the database
    • can_compress_scripts
    • db_upgraded
    • widget_recent-comments
    • widget_recent-posts
    • theysaidso_admin_options
    • widget_theysaidso_widget

Smoke tests 50% from 4 tests

Server-side errors Passed 1 test

🔹 Test weight: 20 | Just a short smoke test targeting errors on the server (in the Apache logs)
Everything seems fine, however this is by no means an exhaustive test

SRP 0% from 2 tests

🔹 Tests weight: 20 | A shallow check of the single-responsibility principle; PHP files should perform no action - including output of placeholder text - and trigger no errors when accessed directly
Please fix the following items
  • 2× GET requests to PHP files return non-empty strings:
    • > /wp-content/plugins/access-watch/feedback.php
    • > /wp-content/plugins/access-watch/index.php
  • 262× PHP files trigger server errors when accessed directly (only 10 are shown):
    • > PHP Fatal error
      Uncaught Error: Class 'Symfony\\Component\\HttpFoundation\\HeaderBag' not found in wp-content/plugins/access-watch/vendor/symfony/http-foundation/ResponseHeaderBag.php:19
    • > PHP Fatal error
      Uncaught Error: Class 'Monolog\\Handler\\AbstractProcessingHandler' not found in wp-content/plugins/access-watch/vendor/monolog/monolog/src/Monolog/Handler/RollbarHandler.php:26
    • > PHP Fatal error
      Uncaught Error: Class 'Monolog\\Handler\\AbstractProcessingHandler' not found in wp-content/plugins/access-watch/vendor/monolog/monolog/src/Monolog/Handler/DynamoDbHandler.php:25
    • > PHP Fatal error
      Uncaught Error: Class 'Monolog\\Handler\\AbstractHandler' not found in wp-content/plugins/access-watch/vendor/monolog/monolog/src/Monolog/Handler/BufferHandler.php:24
    • > PHP Fatal error
      Uncaught Error: Class 'PHPUnit_Framework_TestCase' not found in wp-content/plugins/access-watch/vendor/bouncer/bouncer/tests/IdentityTest.php:16
    • > PHP Fatal error
      Uncaught Error: Class 'PHPUnit_Framework_TestCase' not found in wp-content/plugins/access-watch/vendor/symfony/http-foundation/Tests/Session/Storage/Proxy/NativeProxyTest.php:21
    • > PHP Fatal error
      Uncaught Error: Class 'Bouncer\\Logger\\BaseLogger' not found in wp-content/plugins/access-watch/vendor/access-watch/access-watch/src/Logger/HttpLogger.php:23
    • > PHP Fatal error
      Uncaught Error: Interface 'Symfony\\Component\\HttpFoundation\\Session\\SessionBagInterface' not found in wp-content/plugins/access-watch/vendor/symfony/http-foundation/Session/Flash/FlashBagInterface.php:21
    • > PHP Fatal error
      Uncaught Error: Class 'PHPUnit_Framework_TestCase' not found in wp-content/plugins/access-watch/vendor/symfony/http-foundation/Tests/ResponseTestCase.php:16
    • > PHP Fatal error
      Uncaught Error: Class 'Monolog\\Formatter\ormalizerFormatter' not found in wp-content/plugins/access-watch/vendor/monolog/monolog/src/Monolog/Formatter/WildfireFormatter.php:23

User-side errors Passed 1 test

🔹 Test weight: 20 | This is a shallow check for browser errors
No browser errors were detected

Optimizations

Plugin configuration 90% from 29 tests

readme.txt 94% from 16 tests

You should put a lot of thought into formatting readme.txt as it is used by WordPress.org to prepare the public listing of your plugin
These attributes need your attention: The official readme.txt is a good inspiration

access-watch/index.php 85% from 13 tests

The main PHP file in "Access Watch: Security and Traffic Insights" ver. 2.0.0-end-of-life... adds more information about the plugin and also serves as the entry point for this plugin
Please take the time to fix the following:
  • Main file name: The principal plugin file should be the same as the plugin slug ("access-watch.php" instead of "index.php")
  • Version: Use only periods and digits for the version number (ex. "1.0.3" instead of "2.0.0-end-of-life...")

Code Analysis Passed 3 tests

File types Passed 1 test

🔸 Test weight: 35 | A short check of programming languages and file extensions; no executable files are allowed
No dangerous file extensions were detected29,510 lines of code in 365 files:
LanguageFilesBlank linesComment linesLines of code
PHP3346,81413,35327,186
Markdown122970951
SVG300551
JSON700470
CSS1375230
XML48064
JavaScript10133
YAML30025

PHP code Passed 2 tests

Cyclomatic complexity and code structure are the fingerprint of this plugin
There are no cyclomatic complexity problems detected for this plugin
Cyclomatic complexity
Average complexity per logical line of code0.18
Average class complexity6.32
▷ Minimum class complexity1.00
▷ Maximum class complexity190.00
Average method complexity1.77
▷ Minimum method complexity1.00
▷ Maximum method complexity24.00
Code structure
Namespaces42
Interfaces16
Traits2
Classes328
▷ Abstract classes113.35%
▷ Concrete classes31796.65%
▷ Final classes00.00%
Methods2,479
▷ Static methods732.94%
▷ Public methods2,15386.85%
▷ Protected methods2339.40%
▷ Private methods933.75%
Functions125
▷ Named functions4132.80%
▷ Anonymous functions8467.20%
Constants148
▷ Global constants53.38%
▷ Class constants14396.62%
▷ Public constants143100.00%

Plugin size Passed 2 tests

Image compression Passed 2 tests

PNG files should be compressed to save space and minimize bandwidth usage
3 compressed PNG files occupy 0.12MB
Potential savings
Compression of 3 random PNG files using pngquant
FileSize - originalSize - compressedSavings
assets/flags2x-1defcd.png31.95KB32.11KB0.00%
assets/flags1x-0c1db6.png14.47KB14.65KB0.00%
assets/flags3x-5b66f2.png78.85KB78.96KB0.00%