84% cloudflare-flexible-ssl

Code Review | Flexible SSL for CloudFlare

WordPress plugin Flexible SSL for CloudFlare scored84%from 54 tests.

About plugin

  • Plugin page: cloudflare-flexib...
  • Plugin version: 1.3.1
  • PHP compatiblity: 5.2+
  • PHP version: 7.4.16
  • WordPress compatibility: 3.2.0-6.3
  • WordPress version: 6.3.1
  • First release: Oct 7, 2014
  • Latest release: Aug 21, 2023
  • Number of updates: 40
  • Update frequency: every 81.0 days
  • Top authors: paultgoodchild (100%)

Code review

54 tests

User reviews

48 reviews

Install metrics

100,000+ active /1,045,008 total downloads

Benchmarks

Plugin footprint 83% from 16 tests

Installer Passed 1 test

🔺 Critical test (weight: 50) | Checking the installer triggered no errors
The plugin installed gracefully, with no errors

Server metrics [RAM: ▲0.00MB] [CPU: ▼5.35ms] Passed 4 tests

Analyzing server-side resources used by Flexible SSL for CloudFlare
This plugin has minimal impact on server resources
PageMemory (MB)CPU Time (ms)
Home /3.47 ▲0.0139.03 ▼2.44
Dashboard /wp-admin3.31 ▲0.0144.25 ▼7.57
Posts /wp-admin/edit.php3.36 ▲0.0048.41 ▲2.29
Add New Post /wp-admin/post-new.php5.89 ▲0.0082.04 ▼13.67
Media Library /wp-admin/upload.php3.23 ▲0.0037.21 ▲7.31

Server storage [IO: ▲0.01MB] [DB: ▲0.00MB] Passed 3 tests

A short overview of filesystem and database impact
This plugin installed successfully
Filesystem: 4 new files
Database: no new tables, 6 new options
New WordPress options
can_compress_scripts
widget_recent-posts
db_upgraded
widget_theysaidso_widget
theysaidso_admin_options
widget_recent-comments

Browser metrics Passed 4 tests

An overview of browser requirements for Flexible SSL for CloudFlare
Normal browser usage
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /2,817 ▲8213.29 ▼1.101.69 ▼0.6233.58 ▼12.09
Dashboard /wp-admin2,226 ▲384.83 ▼0.06101.88 ▼13.6344.99 ▼1.47
Posts /wp-admin/edit.php2,105 ▲132.02 ▲0.0038.67 ▲0.6741.98 ▲7.42
Add New Post /wp-admin/post-new.php1,550 ▲3623.22 ▲5.66682.01 ▲22.2252.90 ▲0.50
Media Library /wp-admin/upload.php1,405 ▲264.19 ▼0.0295.79 ▼4.4845.62 ▲3.82

Uninstaller [IO: ▲0.00MB] [DB: ▲0.00MB] 75% from 4 tests

🔸 Tests weight: 35 | Verifying that this plugin uninstalls completely without leaving any traces
The following items require your attention
  • Zombie WordPress options detected upon uninstall: 6 options
    • widget_recent-posts
    • widget_theysaidso_widget
    • can_compress_scripts
    • theysaidso_admin_options
    • widget_recent-comments
    • db_upgraded

Smoke tests 75% from 4 tests

Server-side errors Passed 1 test

🔹 Test weight: 20 | A shallow check that no server-side errors were triggered
Good news, no errors were detected

SRP 50% from 2 tests

🔹 Tests weight: 20 | It is important to ensure that your PHP files perform no action when accessed directly, respecting the single-responsibility principle
Please take a closer look at the following
  • 2× GET requests to PHP files have triggered server-side errors or warnings:
    • > PHP Fatal error
      Uncaught Error: Call to undefined function add_action() in wp-content/plugins/cloudflare-flexible-ssl/shieldprom.php:3
    • > PHP Fatal error
      Uncaught Error: Call to undefined function add_action() in wp-content/plugins/cloudflare-flexible-ssl/shieldprom.php:3

User-side errors Passed 1 test

🔹 Test weight: 20 | This is just a short smoke test looking for browser issues
Everything seems fine, but this is not an exhaustive test

Optimizations

Plugin configuration 96% from 29 tests

readme.txt Passed 16 tests

The readme.txt file describes your plugin functionality and requirements and it is parsed to prepare the your plugin's listing
7 plugin tags: flexible ssl, universal ssl, ssl, https, http_x_forwarded_proto...

cloudflare-flexible-ssl/plugin.php 92% from 13 tests

The main PHP script in "Flexible SSL for CloudFlare" version 1.3.1 is automatically included on every request by WordPress
You should first fix the following items:
  • Main file name: The principal plugin file should be the same as the plugin slug ("cloudflare-flexible-ssl.php" instead of "plugin.php")

Code Analysis Passed 3 tests

File types Passed 1 test

🔸 Test weight: 35 | Executable files are not allowed as they can serve as attack vectors
There were no executable files found in this plugin117 lines of code in 2 files:
LanguageFilesBlank linesComment linesLines of code
PHP22853117

PHP code Passed 2 tests

Analyzing cyclomatic complexity and code structure
There are no cyclomatic complexity problems detected for this plugin
Cyclomatic complexity
Average complexity per logical line of code0.53
Average class complexity18.00
▷ Minimum class complexity18.00
▷ Maximum class complexity18.00
Average method complexity3.12
▷ Minimum method complexity1.00
▷ Maximum method complexity6.00
Code structure
Namespaces0
Interfaces0
Traits0
Classes1
▷ Abstract classes00.00%
▷ Concrete classes1100.00%
▷ Final classes00.00%
Methods8
▷ Static methods00.00%
▷ Public methods337.50%
▷ Protected methods00.00%
▷ Private methods562.50%
Functions2
▷ Named functions150.00%
▷ Anonymous functions150.00%
Constants0
▷ Global constants00.00%
▷ Class constants00.00%
▷ Public constants00.00%

Plugin size Passed 2 tests

Image compression Passed 2 tests

PNG files should be compressed to save space and minimize bandwidth usage
PNG images were not found in this plugin