78% bws-google-2-step-verification

Code Review | 2-Step Verification by BestWebSoft - WordPress Anti-spam and Anti Hacker Plugin

WordPress plugin 2-Step Verification by BestWebSoft - WordPress Anti-spam and Anti Hacker Plugin scored78%from 54 tests.

About plugin

  • Plugin page: bws-google-2-step...
  • Plugin version: 1.1.0
  • PHP version: 7.4.16
  • WordPress compatibility: 5.6-6.3
  • WordPress version: 6.3.1
  • First release: Jun 30, 2017
  • Latest release: Aug 11, 2023
  • Number of updates: 22
  • Update frequency: every 101.9 days
  • Top authors: bestwebsoft (100%)

Code review

54 tests

User reviews

2 reviews

Install metrics

300+ active /9,969 total downloads

Benchmarks

Plugin footprint 83% from 16 tests

Installer Passed 1 test

🔺 Critical test (weight: 50) | All plugins must install correctly, without throwing any errors, warnings, or notices
This plugin's installer ran successfully

Server metrics [RAM: ▲0.10MB] [CPU: ▲0.06ms] Passed 4 tests

Analyzing server-side resources used by 2-Step Verification by BestWebSoft - WordPress Anti-spam and Anti Hacker Plugin
Server-side resource usage in normal parameters
PageMemory (MB)CPU Time (ms)
Home /3.58 ▲0.1243.26 ▲4.51
Dashboard /wp-admin3.40 ▲0.0946.82 ▼3.92
Posts /wp-admin/edit.php3.51 ▲0.1647.55 ▲1.90
Add New Post /wp-admin/post-new.php6.00 ▲0.1195.18 ▼1.71
Media Library /wp-admin/upload.php3.32 ▲0.0936.81 ▲3.96

Server storage [IO: ▲5.26MB] [DB: ▲0.07MB] Passed 3 tests

Filesystem and database footprint
There were no storage issued detected upon installing this plugin
Filesystem: 131 new files
Database: no new tables, 9 new options
New WordPress options
gglstpvrfctn_options
widget_theysaidso_widget
db_upgraded
widget_recent-posts
gglstpvrfctn_key
theysaidso_admin_options
widget_recent-comments
bstwbsftwppdtplgns_options
can_compress_scripts

Browser metrics Passed 4 tests

2-Step Verification by BestWebSoft - WordPress Anti-spam and Anti Hacker Plugin: an overview of browser usage
Minimal impact on browser resources
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /2,898 ▲13713.98 ▼0.641.71 ▲0.0544.83 ▲4.07
Dashboard /wp-admin2,241 ▲615.75 ▲0.0781.60 ▼7.0739.08 ▼5.47
Posts /wp-admin/edit.php2,146 ▲462.06 ▲0.0338.38 ▲2.4340.76 ▲3.52
Add New Post /wp-admin/post-new.php1,575 ▲4918.20 ▼4.64615.52 ▼54.1470.24 ▲17.36
Media Library /wp-admin/upload.php1,449 ▲494.28 ▼0.0799.19 ▲6.6143.35 ▼1.78
BWS Panel /wp-admin/google-2-step-verification.php?page=gglstpvrfctn-bws-panel260.420.1116.26
Settings /wp-admin/google-2-step-verification.php260.420.085.41

Uninstaller [IO: ▲0.00MB] [DB: ▲0.07MB] 75% from 4 tests

🔸 Tests weight: 35 | It is important to correctly uninstall your plugin, without leaving any traces
You still need to fix the following
  • Zombie WordPress options were found after uninstall: 6 options
    • can_compress_scripts
    • db_upgraded
    • theysaidso_admin_options
    • widget_theysaidso_widget
    • widget_recent-posts
    • widget_recent-comments

Smoke tests 50% from 4 tests

Server-side errors Passed 1 test

🔹 Test weight: 20 | A smoke test targeting server-side errors
Good news, no errors were detected

SRP 50% from 2 tests

🔹 Tests weight: 20 | It is important to ensure that your PHP files perform no action when accessed directly, respecting the single-responsibility principle
Please take a closer look at the following
  • 4× GET requests to PHP files trigger server-side errors or Error 500 responses:
    • > PHP Fatal error
      Uncaught Error: Call to undefined function __() in wp-content/plugins/bws-google-2-step-verification/bws_menu/product_list.php:9
    • > PHP Fatal error
      Uncaught Error: Call to undefined function add_action() in wp-content/plugins/bws-google-2-step-verification/bws_menu/class-bws-settings.php:1452
    • > PHP Fatal error
      Uncaught Error: Call to undefined function register_activation_hook() in wp-content/plugins/bws-google-2-step-verification/bws-google-2-step-verification.php:2053
    • > PHP Fatal error
      Uncaught Error: Class 'Bws_Settings_Tabs' not found in wp-content/plugins/bws-google-2-step-verification/includes/class-gglstpvrfctn-settings.php:6

User-side errors 0% from 1 test

🔹 Test weight: 20 | Just a short smoke test targeting errors on the browser (console and network errors and warnings)
There are user-side issues you should fix
    • > GET request to /wp-admin/google-2-step-verification.php?page=gglstpvrfctn-bws-panel
    • > Network (severe)
    wp-admin/google-2-step-verification.php?page=gglstpvrfctn-bws-panel - Failed to load resource: the server responded with a status of 404 (Not Found)
    • > GET request to /wp-admin/google-2-step-verification.php
    • > Network (severe)
    wp-admin/google-2-step-verification.php - Failed to load resource: the server responded with a status of 404 (Not Found)

Optimizations

Plugin configuration 93% from 29 tests

readme.txt 88% from 16 tests

The readme.txt file uses markdown syntax to describe your plugin to the world
Attributes that need to be fixed:
  • Screenshots: These screenshots have no corresponding images in /assets: #1 (2-Step Verification on the Login page.), #2 (2-Step Verification on the profile page.), #3 (2-Step Verification settings page.), #4 (2-Step Verification settings which allow to customize email messages.), #5 (2-Step Verification on the Lost password page.), #6 (2-Step Verification on the Register page.)
  • Tags: Please reduce the number of tags, currently 12 tag instead of maximum 10
You can look at the official readme.txt

bws-google-2-step-verification/bws-google-2-step-verification.php Passed 13 tests

This is the main PHP file of "2-Step Verification by BestWebSoft - WordPress Anti-spam and Anti Hacker Plugin" version 1.1.0, providing information about the plugin in the header fields and serving as the principal entry point to the plugin's functions
108 characters long description:
Stronger security solution which protects your WordPress website from hacks and unauthorized login attempts.

Code Analysis Passed 3 tests

File types Passed 1 test

🔸 Test weight: 35 | A short review of files and their extensions; it is not recommended to include executable files
No dangerous file extensions were detected21,746 lines of code in 49 files:
LanguageFilesBlank linesComment linesLines of code
PO File113,9285,9118,569
PHP107079936,169
CSS112092805,790
JavaScript13971721,068
SVG400150

PHP code Passed 2 tests

Analyzing cyclomatic complexity and code structure
All good! No complexity issues found
Cyclomatic complexity
Average complexity per logical line of code0.57
Average class complexity64.25
▷ Minimum class complexity10.00
▷ Maximum class complexity210.00
Average method complexity8.03
▷ Minimum method complexity1.00
▷ Maximum method complexity79.00
Code structure
Namespaces0
Interfaces0
Traits0
Classes4
▷ Abstract classes00.00%
▷ Concrete classes4100.00%
▷ Final classes00.00%
Methods36
▷ Static methods00.00%
▷ Public methods2877.78%
▷ Protected methods00.00%
▷ Private methods822.22%
Functions110
▷ Named functions110100.00%
▷ Anonymous functions00.00%
Constants5
▷ Global constants240.00%
▷ Class constants360.00%
▷ Public constants3100.00%

Plugin size 50% from 2 tests

Image compression 50% from 2 tests

All PNG images should be compressed to minimize bandwidth usage for end users
65 PNG files occupy 3.29MB with 1.68MB in potential savings
Potential savings
Compression of 5 random PNG files using pngquant
FileSize - originalSize - compressedSavings
bws_menu/css/jquery-ui-styles/1.10.4/images/ui-bg_flat_0_aaaaaa_40x100.png0.26KB0.11KB▼ 56.06%
bws_menu/css/jquery-ui-styles/1.9.2/images/ui-bg_flat_75_ffffff_40x100.png0.17KB0.08KB▼ 51.12%
bws_menu/css/jquery-ui-styles/1.9.2/images/ui-bg_flat_0_aaaaaa_40x100.png0.18KB0.08KB▼ 51.67%
bws_menu/css/jquery-ui-styles/1.11.4/images/ui-bg_glass_75_dadada_1x400.png0.26KB0.16KB▼ 38.93%
bws_menu/css/jquery-ui-styles/1.11.4/images/ui-bg_glass_65_ffffff_1x400.png0.20KB0.09KB▼ 57.49%