78% beagle-security-wp-security-advanced-penetration-testing

Code Review | Beagle Security - WP Security, Advanced Penetration Testing

WordPress plugin Beagle Security - WP Security, Advanced Penetration Testing scored78%from 54 tests.

About plugin

  • Plugin page: beagle-security-w...
  • Plugin version: 1.0.8
  • PHP compatiblity: 7.2+
  • PHP version: 7.4.16
  • WordPress compatibility: 5.2-6.1
  • WordPress version: 6.3.1
  • First release: Mar 2, 2021
  • Latest release: Nov 1, 2022
  • Number of updates: 11
  • Update frequency: every 55.4 days
  • Top authors: beaglesecurity (100%)

Code review

54 tests

User reviews

3 reviews

Install metrics

200+ active /3,168 total downloads

Benchmarks

Plugin footprint 83% from 16 tests

Installer Passed 1 test

🔺 Critical test (weight: 50) | Verifying that this plugin installs correctly without errors
The plugin installed gracefully, with no errors

Server metrics [RAM: ▲0.17MB] [CPU: ▲5.64ms] Passed 4 tests

Server-side resources used by Beagle Security - WP Security, Advanced Penetration Testing
This plugin does not affect your website's performance
PageMemory (MB)CPU Time (ms)
Home /3.75 ▲0.2952.48 ▲5.81
Dashboard /wp-admin3.46 ▲0.1658.06 ▲6.15
Posts /wp-admin/edit.php3.56 ▲0.2060.98 ▲10.54
Add New Post /wp-admin/post-new.php6.04 ▲0.1698.25 ▲0.73
Media Library /wp-admin/upload.php3.39 ▲0.1646.27 ▲9.85

Server storage [IO: ▲0.37MB] [DB: ▲0.00MB] Passed 3 tests

Analyzing filesystem and database footprints of this plugin
This plugin was installed successfully
Filesystem: 19 new files
Database: 1 new table, 6 new options
New tables
wp_beagleScanData
New WordPress options
widget_theysaidso_widget
can_compress_scripts
widget_recent-posts
theysaidso_admin_options
db_upgraded
widget_recent-comments

Browser metrics Passed 4 tests

A check of browser resources used by Beagle Security - WP Security, Advanced Penetration Testing
This plugin renders optimally with no browser resource issues detected
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /2,824 ▲5313.65 ▼0.741.71 ▼0.6944.53 ▼1.29
Dashboard /wp-admin2,234 ▲494.90 ▼0.03110.35 ▲0.3239.28 ▼6.10
Posts /wp-admin/edit.php2,113 ▲212.00 ▲0.0040.47 ▲0.3636.81 ▲0.05
Add New Post /wp-admin/post-new.php1,546 ▲2623.06 ▼0.11661.53 ▼22.7152.19 ▼7.01
Media Library /wp-admin/upload.php1,412 ▲244.12 ▼0.11112.79 ▲4.9247.59 ▲0.43

Uninstaller [IO: ▲0.00MB] [DB: ▲0.00MB] 75% from 4 tests

🔸 Tests weight: 35 | Verifying that this plugin uninstalls completely without leaving any traces
These items require your attention
  • The uninstall procedure has failed, leaving 6 options in the database
    • widget_theysaidso_widget
    • can_compress_scripts
    • widget_recent-comments
    • theysaidso_admin_options
    • widget_recent-posts
    • db_upgraded

Smoke tests 50% from 4 tests

Server-side errors Passed 1 test

🔹 Test weight: 20 | Just a short smoke test targeting errors on the server (in the Apache logs)
Even though no errors were found, this is by no means an exhaustive test

SRP 0% from 2 tests

🔹 Tests weight: 20 | SRP (Single-Responsibility Principle) - PHP files must act as libraries and never output text or perform any action when accessed directly in a browser
Please take a closer look at the following
  • 4× PHP files output non-empty strings when accessed directly via GET requests:
    • > /wp-content/plugins/beagle-security-wp-security-advanced-penetration-testing/Admin/bootstrap.php
    • > /wp-content/plugins/beagle-security-wp-security-advanced-penetration-testing/wp-beagleSettings.php
    • > /wp-content/plugins/beagle-security-wp-security-advanced-penetration-testing/Admin/script.php
    • > /wp-content/plugins/beagle-security-wp-security-advanced-penetration-testing/Admin/progressRound.php
  • 10× GET requests to PHP files have triggered server-side errors or warnings:
    • > PHP Fatal error
      Uncaught Error: Call to undefined function sanitize_file_name() in wp-content/plugins/beagle-security-wp-security-advanced-penetration-testing/Admin/stopTest.php:4
    • > PHP Fatal error
      Uncaught Error: Call to undefined function sanitize_file_name() in wp-content/plugins/beagle-security-wp-security-advanced-penetration-testing/Admin/updateVerify.php:4
    • > PHP Fatal error
      Uncaught Error: Call to undefined function sanitize_file_name() in wp-content/plugins/beagle-security-wp-security-advanced-penetration-testing/Admin/verifyToken.php:5
    • > PHP Fatal error
      Uncaught Error: Call to undefined function sanitize_file_name() in wp-content/plugins/beagle-security-wp-security-advanced-penetration-testing/Admin/getStatus.php:4
    • > PHP Fatal error
      Uncaught Error: Call to undefined function sanitize_file_name() in wp-content/plugins/beagle-security-wp-security-advanced-penetration-testing/Admin/deleteTest.php:5
    • > PHP Fatal error
      Uncaught Error: Call to undefined function sanitize_file_name() in wp-content/plugins/beagle-security-wp-security-advanced-penetration-testing/Admin/insertInToTable.php:5
    • > PHP Fatal error
      Uncaught Error: Call to undefined function sanitize_file_name() in wp-content/plugins/beagle-security-wp-security-advanced-penetration-testing/Admin/autoVerifyFailed.php:5
    • > PHP Fatal error
      Uncaught Error: Call to undefined function sanitize_file_name() in wp-content/plugins/beagle-security-wp-security-advanced-penetration-testing/Admin/style.php:2
    • > PHP Fatal error
      Uncaught Error: Call to undefined function sanitize_file_name() in wp-content/plugins/beagle-security-wp-security-advanced-penetration-testing/Admin/getResultData.php:5
    • > PHP Fatal error
      Uncaught Error: Call to undefined function sanitize_file_name() in wp-content/plugins/beagle-security-wp-security-advanced-penetration-testing/Admin/startTest.php:4

User-side errors Passed 1 test

🔹 Test weight: 20 | A shallow check that no browser errors were triggered
Everything seems fine, but this is not an exhaustive test

Optimizations

Plugin configuration 90% from 29 tests

readme.txt Passed 16 tests

Don't ignore readme.txt as it is the file that instructs WordPress.org on how to present your plugin to the world
5 plugin tags: security, security plugin, security testing, wordpress security, website security

beagle-security-wp-security-advanced-penetration-testing/wp-beagleSettings.php 77% from 13 tests

The main PHP script in "Beagle Security - WP Security, Advanced Penetration Testing" version 1.0.8 is automatically included on every request by WordPress
You should first fix the following items:
  • Text Domain: The text domain name should consist of only dashes and lowercase characters
  • Domain Path: The domain path is invalid: folder "/languages" does not exist
  • Main file name: It is recommended to name the main PHP file as the plugin slug ("beagle-security-wp-security-advanced-penetration-testing.php" instead of "wp-beagleSettings.php")

Code Analysis Passed 3 tests

File types Passed 1 test

🔸 Test weight: 35 | A short check of programming languages and file extensions; no executable files are allowed
No dangerous file extensions were detected3,815 lines of code in 16 files:
LanguageFilesBlank linesComment linesLines of code
PHP163631183,815

PHP code Passed 2 tests

An short overview of logical lines of code, cyclomatic complexity, and other code metrics
There were no cyclomatic complexity issued detected
Cyclomatic complexity
Average complexity per logical line of code0.36
Average class complexity1.00
▷ Minimum class complexity1.00
▷ Maximum class complexity1.00
Average method complexity1.00
▷ Minimum method complexity1.00
▷ Maximum method complexity1.00
Code structure
Namespaces0
Interfaces0
Traits0
Classes1
▷ Abstract classes00.00%
▷ Concrete classes1100.00%
▷ Final classes00.00%
Methods4
▷ Static methods00.00%
▷ Public methods4100.00%
▷ Protected methods00.00%
▷ Private methods00.00%
Functions11
▷ Named functions11100.00%
▷ Anonymous functions00.00%
Constants1
▷ Global constants1100.00%
▷ Class constants00.00%
▷ Public constants00.00%

Plugin size Passed 2 tests

Image compression Passed 2 tests

PNG files should be compressed to save space and minimize bandwidth usage
There are no PNG files in this plugin