83% clone-guard-security-scanning

Code Review | CloneGuard Security Scanning

WordPress plugin CloneGuard Security Scanning scored83%from 54 tests.

About plugin

  • Plugin page: clone-guard-secur...
  • Plugin version: 2.4
  • PHP compatiblity: 5.6+
  • PHP version: 7.4.16
  • WordPress compatibility: 4.0-6.1.1
  • WordPress version: 6.3.1
  • First release: Dec 18, 2020
  • Latest release: Nov 29, 2022
  • Number of updates: 22
  • Update frequency: every 32.4 days
  • Top authors: clonesupport (100%)

Code review

54 tests

User reviews

7 reviews

Install metrics

40+ active /169,587 total downloads

Benchmarks

Plugin footprint 83% from 16 tests

Installer Passed 1 test

🔺 Critical test (weight: 50) | Verifying that this plugin installs correctly without errors
This plugin's installer ran successfully

Server metrics [RAM: ▲0.63MB] [CPU: ▼1.69ms] Passed 4 tests

Server-side resources used by CloneGuard Security Scanning
Normal server usage
PageMemory (MB)CPU Time (ms)
Home /4.08 ▲0.6245.81 ▼0.49
Dashboard /wp-admin3.98 ▲0.6849.03 ▼0.19
Posts /wp-admin/edit.php4.03 ▲0.6853.58 ▲3.75
Add New Post /wp-admin/post-new.php6.50 ▲0.6290.75 ▼9.84
Media Library /wp-admin/upload.php3.84 ▲0.6240.29 ▲5.99
Overview /wp-admin/admin.php?page=cgss_overview3.7029.00
Options /wp-admin/admin.php?page=cgss_options3.7025.79
Reports /wp-admin/admin.php?page=cgss_reports3.7026.88
Settings /wp-admin/admin.php?page=cgss_settings3.8237.58
Scans /wp-admin/admin.php?page=cgss_scans3.7027.75
Vulnerabilities /wp-admin/admin.php?page=cgss_vulnerabilities3.7027.98

Server storage [IO: ▲2.29MB] [DB: ▲0.00MB] Passed 3 tests

Filesystem and database footprint
There were no storage issued detected upon installing this plugin
Filesystem: 65 new files
Database: no new tables, 7 new options
New WordPress options
db_upgraded
widget_recent-comments
widget_theysaidso_widget
widget_recent-posts
theysaidso_admin_options
can_compress_scripts
widget_clone_guard_widget

Browser metrics Passed 4 tests

CloneGuard Security Scanning: an overview of browser usage
Minimal impact on browser resources
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /2,843 ▲8614.80 ▲0.291.67 ▼0.7744.72 ▲4.59
Dashboard /wp-admin2,249 ▲675.90 ▲0.08100.24 ▼1.1538.79 ▼3.17
Posts /wp-admin/edit.php2,132 ▲432.05 ▲0.0241.00 ▲0.5035.86 ▼1.88
Add New Post /wp-admin/post-new.php1,567 ▲3423.23 ▼0.03638.45 ▼57.9056.55 ▲5.42
Media Library /wp-admin/upload.php1,431 ▲434.18 ▲0.0194.62 ▼14.3941.33 ▼2.13
Overview /wp-admin/admin.php?page=cgss_overview9712.2326.4441.53
Options /wp-admin/admin.php?page=cgss_options9742.0827.5937.59
Reports /wp-admin/admin.php?page=cgss_reports9712.0527.2838.78
Settings /wp-admin/admin.php?page=cgss_settings9722.0824.5737.21
Scans /wp-admin/admin.php?page=cgss_scans9742.0524.3135.42
Vulnerabilities /wp-admin/admin.php?page=cgss_vulnerabilities9712.0424.7737.42

Uninstaller [IO: ▲0.00MB] [DB: ▲0.00MB] 75% from 4 tests

🔸 Tests weight: 35 | All plugins must uninstall correctly, removing their source code and extra database tables they might have created
Please fix the following items
  • This plugin does not fully uninstall, leaving 7 options in the database
    • widget_recent-comments
    • can_compress_scripts
    • theysaidso_admin_options
    • db_upgraded
    • widget_recent-posts
    • widget_clone_guard_widget
    • widget_theysaidso_widget

Smoke tests 75% from 4 tests

Server-side errors Passed 1 test

🔹 Test weight: 20 | This is a shallow check for server-side errors
The smoke test was a success, however most plugin functionality was not tested

SRP 50% from 2 tests

🔹 Tests weight: 20 | The single-responsibility principle applies for WordPress plugins as well - please make sure your PHP files perform no actions when accessed directly
Please take a closer look at the following
  • 21× PHP files trigger server-side errors or warnings when accessed directly (only 10 are shown):
    • > PHP Fatal error
      Uncaught Error: Call to undefined function esc_url() in wp-content/plugins/clone-guard-security-scanning/views/admin_vulnerabilities.php:5
    • > PHP Fatal error
      Uncaught Error: Call to undefined function esc_url() in wp-content/plugins/clone-guard-security-scanning/views/admin_vulnerability_view.php:6
    • > PHP Fatal error
      Uncaught Error: Call to undefined function esc_url() in wp-content/plugins/clone-guard-security-scanning/views/admin_settings.php:6
    • > PHP Fatal error
      Uncaught Error: Call to undefined function esc_url() in wp-content/plugins/clone-guard-security-scanning/views/admin_scan_create.php:5
    • > PHP Fatal error
      Uncaught Error: Call to undefined function esc_url() in wp-content/plugins/clone-guard-security-scanning/views/admin_overview.php:6
    • > PHP Fatal error
      Uncaught Error: Call to undefined function esc_url() in wp-content/plugins/clone-guard-security-scanning/views/admin_vulnerability_add_exception.php:5
    • > PHP Notice
      Undefined variable: action in wp-content/plugins/clone-guard-security-scanning/views/admin_overview.php on line 1
    • > PHP Fatal error
      Uncaught Error: Call to undefined function esc_url() in wp-content/plugins/clone-guard-security-scanning/views/admin_target_create.php:5
    • > PHP Fatal error
      Uncaught Error: Call to undefined function esc_url() in wp-content/plugins/clone-guard-security-scanning/views/admin_target_edit.php:5
    • > PHP Fatal error
      Uncaught Error: Call to undefined function esc_url() in wp-content/plugins/clone-guard-security-scanning/views/admin_schedule_create.php:6

User-side errors Passed 1 test

🔹 Test weight: 20 | This is a smoke test targeting browser errors/issues
There were no browser issues found

Optimizations

Plugin configuration 96% from 29 tests

readme.txt Passed 16 tests

The readme.txt file uses markdown syntax to describe your plugin to the world
10 plugin tags: penetration testing, owasp, pci scan, vulnerability scanning, pci asv...

clone-guard-security-scanning/main.php 92% from 13 tests

The principal PHP file in "CloneGuard Security Scanning" v. 2.4 is loaded by WordPress automatically on each request
The following require your attention:
  • Main file name: Even though not officially enforced, the main plugin file should be the same as the plugin slug ("clone-guard-security-scanning.php" instead of "main.php")

Code Analysis 97% from 3 tests

File types Passed 1 test

🔸 Test weight: 35 | An overview of files in this plugin; executable files are not allowed
Good job! No executable or dangerous file extensions detected7,710 lines of code in 35 files:
LanguageFilesBlank linesComment linesLines of code
PHP218431805,731
CSS103251051,211
JavaScript411628768

PHP code 50% from 2 tests

A short review of cyclomatic complexity and code structure
Please tend to the following items
  • Method cyclomatic complexity should be reduced to less than 100 (currently 104)
Cyclomatic complexity
Average complexity per logical line of code0.28
Average class complexity190.33
▷ Minimum class complexity20.00
▷ Maximum class complexity461.00
Average method complexity7.60
▷ Minimum method complexity1.00
▷ Maximum method complexity104.00
Code structure
Namespaces0
Interfaces0
Traits0
Classes3
▷ Abstract classes00.00%
▷ Concrete classes3100.00%
▷ Final classes00.00%
Methods86
▷ Static methods00.00%
▷ Public methods86100.00%
▷ Protected methods00.00%
▷ Private methods00.00%
Functions0
▷ Named functions00.00%
▷ Anonymous functions00.00%
Constants0
▷ Global constants00.00%
▷ Class constants00.00%
▷ Public constants00.00%

Plugin size 50% from 2 tests

Image compression 50% from 2 tests

Often times overlooked, PNG files can occupy unnecessary space in your plugin
28 PNG files occupy 1.73MB with 0.90MB in potential savings
Potential savings
Compression of 5 random PNG files using pngquant
FileSize - originalSize - compressedSavings
img/report-screenshot2.png252.93KB139.07KB▼ 45.02%
img/generate-seals-product3.png83.49KB27.42KB▼ 67.16%
img/pci.png3.42KB3.26KB▼ 4.49%
img/vulnerabilities/qod.png19.29KB1.77KB▼ 90.80%
img/banner-772x250.png45.18KB22.01KB▼ 51.28%