72% all-in-one-wp-security-and-firewall

Code Review | All-In-One Security (AIOS) – Security and Firewall

WordPress plugin All-In-One Security (AIOS) – Security and Firewall scored72%from 54 tests.

About plugin

  • Plugin page: all-in-one-wp-sec...
  • Plugin version: 5.2.5
  • PHP compatiblity: 5.6+
  • PHP version: 7.4.16
  • WordPress compatibility: 5.0-6.3
  • WordPress version: 6.3.1
  • First release: Jun 3, 2013
  • Latest release: Oct 25, 2023
  • Number of updates: 266
  • Update frequency: every 14.3 days
  • Top authors: mra13 (76.32%)DavidAnderson (16.92%)wpsolutions (7.52%)

Code review

54 tests

User reviews

1472 reviews

Install metrics

1,000,000+ active /24,393,951 total downloads

Benchmarks

Plugin footprint 82% from 16 tests

Installer Passed 1 test

🔺 Critical test (weight: 50) | The install procedure must perform silently
This plugin's installer ran successfully

Server metrics [RAM: ▲2.97MB] [CPU: ▲20.22ms] Passed 4 tests

Server-side resources used by All-In-One Security (AIOS) – Security and Firewall
This plugin does not affect your website's performance
PageMemory (MB)CPU Time (ms)
Home /6.40 ▲2.9363.87 ▲23.24
Dashboard /wp-admin6.34 ▲3.0471.96 ▲23.67
Posts /wp-admin/edit.php6.38 ▲3.0260.60 ▲13.92
Add New Post /wp-admin/post-new.php8.85 ▲2.96103.18 ▲20.03
Media Library /wp-admin/upload.php6.19 ▲2.9660.32 ▲25.59
Database Security /wp-admin/admin.php?page=aiowpsec_database6.3657.49
Spam Prevention /wp-admin/admin.php?page=aiowpsec_spam6.3054.40
Firewall /wp-admin/admin.php?page=aiowpsec_firewall6.3753.52
Tools /wp-admin/admin.php?page=aiowpsec_tools6.2852.36
User Security /wp-admin/admin.php?page=aiowpsec_usersec6.4159.14
Scanner /wp-admin/admin.php?page=aiowpsec_filescan6.2851.82
Brute Force /wp-admin/admin.php?page=aiowpsec_brute_force6.3755.37
Premium Upgrade /wp-admin/admin.php?page=aiowpsec&tab=premium-upgrade6.4653.02
Settings /wp-admin/admin.php?page=aiowpsec_settings6.3850.74
Blacklist Manager /wp-admin/admin.php?page=aiowpsec_blacklist6.2851.75

Server storage [IO: ▲4.43MB] [DB: ▲0.02MB] 67% from 3 tests

A short overview of filesystem and database impact
Please try to fix the following items
  • The plugin illegally modified 4 files (1.05KB) outside of "wp-content/plugins/all-in-one-wp-security-and-firewall/" and "wp-content/uploads/"
    • (new file) wp-content/aiowps_backups/index.html
    • (new file) wp-content/aiowps_backups/.htaccess
    • (new file) wp-content/aiowps_backups/.htaccess.backup
    • (modified) .htaccess
Filesystem: 338 new files
Database: 8 new tables, 9 new options
New tables
wp_aiowps_events
wp_aiowps_permanent_block
wp_aiowps_login_lockdown
wp_aiowps_message_store
wp_aiowps_debug_log
wp_aiowps_logged_in_users
wp_aiowps_audit_log
wp_aiowps_global_meta
New WordPress options
theysaidso_admin_options
aiowpsec_db_version
db_upgraded
widget_recent-comments
aio_wp_security_configs
widget_recent-posts
widget_theysaidso_widget
aiowpsec_firewall_version
can_compress_scripts

Browser metrics Passed 4 tests

Checking browser requirements for All-In-One Security (AIOS) – Security and Firewall
There were no issues detected in relation to browser resource usage
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /2,923 ▲16214.35 ▼0.001.75 ▼0.0142.00 ▼2.78
Dashboard /wp-admin2,317 ▲1435.56 ▲0.0497.71 ▲8.4672.56 ▲33.60
Posts /wp-admin/edit.php2,156 ▲562.00 ▼0.0335.59 ▼4.0729.94 ▼11.79
Add New Post /wp-admin/post-new.php1,618 ▲9017.94 ▼5.07629.30 ▼50.4688.59 ▲22.89
Media Library /wp-admin/upload.php1,474 ▲744.19 ▼0.0492.56 ▼0.6771.75 ▲27.23
Database Security /wp-admin/admin.php?page=aiowpsec_database1,1684.5742.4839.43
Spam Prevention /wp-admin/admin.php?page=aiowpsec_spam1,2384.6643.3371.76
Firewall /wp-admin/admin.php?page=aiowpsec_firewall1,3564.5641.4755.78
Tools /wp-admin/admin.php?page=aiowpsec_tools1,0954.8142.9769.45
User Security /wp-admin/admin.php?page=aiowpsec_usersec1,1424.7742.2772.31
Scanner /wp-admin/admin.php?page=aiowpsec_filescan1,3264.6142.5472.35
Brute Force /wp-admin/admin.php?page=aiowpsec_brute_force1,1514.5543.3071.16
Premium Upgrade /wp-admin/admin.php?page=aiowpsec&tab=premium-upgrade1,9834.5645.0377.93
Settings /wp-admin/admin.php?page=aiowpsec_settings1,2524.6743.3662.58
Blacklist Manager /wp-admin/admin.php?page=aiowpsec_blacklist1,2274.6455.9465.23

Uninstaller [IO: ▲0.00MB] [DB: ▲0.00MB] 75% from 4 tests

🔸 Tests weight: 35 | Verifying that this plugin uninstalls completely without leaving any traces
Please fix the following items
  • Zombie WordPress options were found after uninstall: 6 options
    • can_compress_scripts
    • widget_recent-posts
    • theysaidso_admin_options
    • widget_theysaidso_widget
    • db_upgraded
    • widget_recent-comments

Smoke tests 25% from 4 tests

Server-side errors 0% from 1 test

🔹 Test weight: 20 | Just a short smoke test targeting errors on the server (in the Apache logs)
Please fix the following server-side errors
    • > GET request to /wp-admin/admin.php?page=aiowpsec_filescan
    • > Notice in wp-content/plugins/all-in-one-wp-security-and-firewall/classes/wp-security-file-scan.php+191
    fread(): read of 8192 bytes failed with errno=21 Is a directory

SRP 0% from 2 tests

🔹 Tests weight: 20 | SRP (Single-Responsibility Principle) - PHP files must act as libraries and never output text or perform any action when accessed directly in a browser
Almost there! Just fix the following items
  • 109× PHP files output text when accessed directly (only 10 are shown):
    • > /wp-content/plugins/all-in-one-wp-security-and-firewall/templates/wp-admin/settings/wp-config-file-operations.php
    • > /wp-content/plugins/all-in-one-wp-security-and-firewall/templates/wp-admin/filesystem-security/partials/wp-file-access.php
    • > /wp-content/plugins/all-in-one-wp-security-and-firewall/templates/wp-admin/database-security/database-prefix.php
    • > /wp-content/plugins/all-in-one-wp-security-and-firewall/includes/simba-tfa/templates/shortcode-tfa-user-settings.php
    • > /wp-content/plugins/all-in-one-wp-security-and-firewall/templates/wp-admin/firewall/6g.php
    • > /wp-content/plugins/all-in-one-wp-security-and-firewall/templates/wp-admin/firewall/partials/xmlrpc-warning-notice.php
    • > /wp-content/plugins/all-in-one-wp-security-and-firewall/templates/wp-admin/user-security/logged-in-users.php
    • > /wp-content/plugins/all-in-one-wp-security-and-firewall/templates/wp-admin/dashboard/debug-logs.php
    • > /wp-content/plugins/all-in-one-wp-security-and-firewall/templates/wp-admin/user-security/manual-approval.php
    • > /wp-content/plugins/all-in-one-wp-security-and-firewall/classes/wp-security-notices.php
  • 45× GET requests to PHP files trigger server-side errors or Error 500 responses (only 10 are shown):
    • > PHP Fatal error
      Uncaught Error: Class 'AIOWPS\\Firewall\\Rule' not found in wp-content/plugins/all-in-one-wp-security-and-firewall/classes/firewall/rule/rules/blacklist/rule-ips-blacklist.php:7
    • > PHP Notice
      Undefined property: HOTPResult::$hex in wp-content/plugins/all-in-one-wp-security-and-firewall/includes/simba-tfa/providers/totp/hotp-php-master/hotp.php on line 128
    • > PHP Fatal error
      Uncaught Error: Class 'AIOWPS\\Firewall\\Rule' not found in wp-content/plugins/all-in-one-wp-security-and-firewall/classes/firewall/rule/rules/6g/rule-request-method-6g.php:7
    • > PHP Fatal error
      Uncaught Error: Call to undefined function is_admin() in wp-content/plugins/all-in-one-wp-security-and-firewall/other-includes/wp-security-stop-users-enumeration.php:6
    • > PHP Fatal error
      Uncaught Error: Class 'AIOWPS\\Firewall\\Rule' not found in wp-content/plugins/all-in-one-wp-security-and-firewall/classes/firewall/rule/rules/blacklist/rule-user-agent-blacklist.php:7
    • > PHP Fatal error
      Uncaught Error: Class 'AIOWPS\\Firewall\\Rule' not found in wp-content/plugins/all-in-one-wp-security-and-firewall/classes/firewall/rule/rules/general/rule-proxy-comment-posting.php:7
    • > PHP Fatal error
      Uncaught Error: Class 'IPLib\\Range\\AbstractRange' not found in wp-content/plugins/all-in-one-wp-security-and-firewall/vendor/mlocati/ip-lib/src/Range/Subnet.php:17
    • > PHP Fatal error
      Uncaught Error: Call to undefined function force_ssl_admin() in wp-content/plugins/all-in-one-wp-security-and-firewall/other-includes/wp-security-rename-login-feature.php:16
    • > PHP Fatal error
      Uncaught Error: Class 'AIOWPS\\Firewall\\Rule' not found in wp-content/plugins/all-in-one-wp-security-and-firewall/classes/firewall/rule/rules/6g/rule-block-query-strings-6g.php:7
    • > PHP Notice
      Undefined property: HOTPResult::$hex in wp-content/plugins/all-in-one-wp-security-and-firewall/includes/simba-tfa/providers/totp/hotp-php-master/hotp.php on line 128

User-side errors Passed 1 test

🔹 Test weight: 20 | This is a shallow check for browser errors
Everything seems fine, but this is not an exhaustive test

Optimizations

Plugin configuration 96% from 29 tests

readme.txt Passed 16 tests

Often overlooked, readme.txt is one of the most important files in your plugin
5 plugin tags: firewall, malware scanning, two factor authentication, login security, security

all-in-one-wp-security-and-firewall/wp-security.php 92% from 13 tests

The principal PHP file in "All-In-One Security (AIOS) – Security and Firewall" v. 5.2.5 is loaded by WordPress automatically on each request
The following require your attention:
  • Main file name: Please rename the main PHP file in this plugin to the plugin slug ("all-in-one-wp-security-and-firewall.php" instead of "wp-security.php")

Code Analysis Passed 3 tests

File types Passed 1 test

🔸 Test weight: 35 | There should be no dangerous file extensions present in any WordPress plugin
There were no executable files found in this plugin57,901 lines of code in 285 files:
LanguageFilesBlank linesComment linesLines of code
PHP2516,09911,80328,501
PO File79,88412,61219,892
JavaScript121,9368177,505
CSS6218101,295
Markdown42310494
JSON300197
XML201217

PHP code Passed 2 tests

This is a very shot review of cyclomatic complexity and code structure
Great job! No cyclomatic complexity issues were detected in this plugin
Cyclomatic complexity
Average complexity per logical line of code0.38
Average class complexity26.11
▷ Minimum class complexity1.00
▷ Maximum class complexity286.00
Average method complexity3.59
▷ Minimum method complexity1.00
▷ Maximum method complexity58.00
Code structure
Namespaces7
Interfaces2
Traits10
Classes138
▷ Abstract classes85.80%
▷ Concrete classes13094.20%
▷ Final classes00.00%
Methods1,451
▷ Static methods34924.05%
▷ Public methods1,13578.22%
▷ Protected methods1459.99%
▷ Private methods17111.78%
Functions40
▷ Named functions1845.00%
▷ Anonymous functions2255.00%
Constants90
▷ Global constants5055.56%
▷ Class constants4044.44%
▷ Public constants40100.00%

Plugin size Passed 2 tests

Image compression Passed 2 tests

Using a strong compression for your PNG files is a great way to speed-up your plugin
26 PNG files occupy 0.18MB with 0.06MB in potential savings
Potential savings
Compression of 5 random PNG files using pngquant
FileSize - originalSize - compressedSavings
images/info-icon.png0.78KB0.85KB0.00%
images/plugin-logos/wp_optimize_logo.png2.49KB2.67KB0.00%
includes/simba-tfa/includes/tfa_admin_icon_16x16.png3.74KB0.98KB▼ 73.75%
images/plugin-logos/updraft-central.png5.02KB3.32KB▼ 33.86%
images/plugin-logos/easy-updates-manager-logo.png42.43KB17.05KB▼ 59.81%