78% fraudlabs-pro-sms-verification

Code Review | FraudLabs Pro SMS Verification

WordPress plugin FraudLabs Pro SMS Verification scored78%from 54 tests.

About plugin

  • Plugin page: fraudlabs-pro-sms...
  • Plugin version: 1.9.5
  • PHP version: 7.4.16
  • WordPress compatibility: 4.6-6.3
  • WordPress version: 6.3.1
  • First release: May 4, 2017
  • Latest release: Sep 5, 2023
  • Number of updates: 121
  • Update frequency: every 19.1 days
  • Top authors: fraudlabspro (100%)

Code review

54 tests

User reviews

2 reviews

Install metrics

30+ active /5,335 total downloads

Benchmarks

Plugin footprint 83% from 16 tests

Installer Passed 1 test

🔺 Critical test (weight: 50) | Verifying that this plugin installs correctly without errors
The plugin installed gracefully, with no errors

Server metrics [RAM: ▼13.51MB] [CPU: ▼2,866,808.80ms] Passed 4 tests

A check of server-side resources used by FraudLabs Pro SMS Verification
Server-side resource usage in normal parameters
PageMemory (MB)CPU Time (ms)
Home /3.86 ▼55.0448.01 ▼11,467,209.99
Dashboard /wp-admin3.69 ▲0.3055.80 ▼11.20
Posts /wp-admin/edit.php3.80 ▲0.4053.78 ▼2.17
Add New Post /wp-admin/post-new.php6.27 ▲0.3487.30 ▼11.83
Media Library /wp-admin/upload.php3.61 ▲0.3443.01 ▲5.46

Server storage [IO: ▲0.27MB] [DB: ▲0.00MB] Passed 3 tests

Filesystem and database footprint
The plugin installed successfully
Filesystem: 36 new files
Database: no new tables, 24 new options
New WordPress options
widget_theysaidso_widget
widget_recent-comments
fraudlabs_pro_sms_verification_wc_email_verify
fraudlabs_pro_sms_verification_edd_email_verify
fraudlabs_pro_sms_verification_msg_otp_success
fraudlabs_pro_sms_verification_sms_template
fraudlabs_pro_sms_verification_sms_tel_cc
fraudlabs_pro_sms_verification_api_key
fraudlabs_pro_sms_verification_wp_default_registration_form
fraudlabs_pro_sms_verification_wc_default_registration_form
...

Browser metrics Passed 4 tests

An overview of browser requirements for FraudLabs Pro SMS Verification
This plugin renders optimally with no browser resource issues detected
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /2,802 ▲3114.31 ▼0.041.82 ▼0.0444.76 ▼0.57
Dashboard /wp-admin2,208 ▲285.57 ▼0.0897.97 ▲9.6345.32 ▲2.16
Posts /wp-admin/edit.php2,110 ▲131.98 ▼0.0336.34 ▼0.0733.86 ▲0.92
Add New Post /wp-admin/post-new.php1,557 ▲3123.22 ▲0.23650.08 ▼45.7169.77 ▲14.57
Media Library /wp-admin/upload.php1,413 ▲164.20 ▼0.05109.17 ▼2.2748.98 ▲2.61

Uninstaller [IO: ▲0.00MB] [DB: ▲0.00MB] 75% from 4 tests

🔸 Tests weight: 35 | Checking the uninstaller removed all traces of the plugin
It is recommended to fix the following
  • Zombie WordPress options were found after uninstall: 6 options
    • theysaidso_admin_options
    • db_upgraded
    • widget_recent-comments
    • widget_theysaidso_widget
    • widget_recent-posts
    • can_compress_scripts

Smoke tests 50% from 4 tests

Server-side errors Passed 1 test

🔹 Test weight: 20 | A shallow check that no server-side errors were triggered
The smoke test was a success, however most plugin functionality was not tested

SRP 0% from 2 tests

🔹 Tests weight: 20 | The single-responsibility principle: PHP files have to remain inert when accessed directly, throwing no errors and performing no actions
The following issues need your attention
  • 2× PHP files perform the action of outputting non-empty strings when accessed directly:
    • > /wp-content/plugins/fraudlabs-pro-sms-verification/vendor/fraudlabspro/fraudlabspro-php/tests/bootstrap.php
    • > /wp-content/plugins/fraudlabs-pro-sms-verification/vendor/fraudlabspro/fraudlabspro-php/example.php
  • 7× PHP files trigger server-side errors or warnings when accessed directly:
    • > PHP Fatal error
      Uncaught Error: Call to undefined function get_option() in wp-content/plugins/fraudlabs-pro-sms-verification/fraudlabspro-sms-verification.php:26
    • > PHP Fatal error
      Uncaught Error: Class 'WC_Integration' not found in wp-content/plugins/fraudlabs-pro-sms-verification/includes/class-wc-fraudlabspro-sms-verification.php:12
    • > PHP Fatal error
      Uncaught Error: Class 'PHPUnit\\Framework\\TestCase' not found in wp-content/plugins/fraudlabs-pro-sms-verification/vendor/fraudlabspro/fraudlabspro-php/tests/SmsVerificationTest.php:7
    • > PHP Fatal error
      require_once(): Failed opening required 'wp-content/plugins/fraudlabs-pro-sms-verification/vendor/fraudlabspro/fraudlabspro-php/vendor/autoload.php' (include_path='.:/usr/share/php') in wp-content/plugins/fraudlabs-pro-sms-verification/vendor/fraudlabspro/fraudlabspro-php/example.php on line 6
    • > PHP Fatal error
      Uncaught Error: Call to undefined function get_option() in wp-content/plugins/fraudlabs-pro-sms-verification/includes/flp-verify.php:13
    • > PHP Fatal error
      Uncaught Error: Class 'PHPUnit\\Framework\\TestCase' not found in wp-content/plugins/fraudlabs-pro-sms-verification/vendor/fraudlabspro/fraudlabspro-php/tests/FraudValidationTest.php:7
    • > PHP Warning
      require_once(wp-content/plugins/fraudlabs-pro-sms-verification/vendor/fraudlabspro/fraudlabspro-php/vendor/autoload.php): failed to open stream: No such file or directory in wp-content/plugins/fraudlabs-pro-sms-verification/vendor/fraudlabspro/fraudlabspro-php/example.php on line 6

User-side errors Passed 1 test

🔹 Test weight: 20 | Just a short smoke test targeting errors on the browser (console and network errors and warnings)
No browser issues were found

Optimizations

Plugin configuration 96% from 29 tests

readme.txt Passed 16 tests

Perhaps the most important file in your plugin readme.txt gets parsed in order to generate the public listing of your plugin
6 plugin tags: wordpress, contact form 7, sms verification, sms, woocommerce...

fraudlabs-pro-sms-verification/fraudlabspro-sms-verification.php 92% from 13 tests

The principal PHP file in "FraudLabs Pro SMS Verification" v. 1.9.5 is loaded by WordPress automatically on each request
Please take the time to fix the following:
  • Main file name: Even though not officially enforced, the main plugin file should be the same as the plugin slug ("fraudlabs-pro-sms-verification.php" instead of "fraudlabspro-sms-verification.php")

Code Analysis 97% from 3 tests

File types Passed 1 test

🔸 Test weight: 35 | There should be no dangerous file extensions present in any WordPress plugin
Good job! No executable or dangerous file extensions detected4,479 lines of code in 27 files:
LanguageFilesBlank linesComment linesLines of code
PHP195445674,078
Markdown1670189
JavaScript3270128
JSON20074
XML1007
CSS1003

PHP code 50% from 2 tests

Analyzing logical lines of code, cyclomatic complexity, and other code metrics
These items need your attention
  • Cyclomatic complexity of methods has to be reduced to less than 100 (currently 119)
Cyclomatic complexity
Average complexity per logical line of code0.45
Average class complexity50.09
▷ Minimum class complexity1.00
▷ Maximum class complexity264.00
Average method complexity6.35
▷ Minimum method complexity1.00
▷ Maximum method complexity119.00
Code structure
Namespaces2
Interfaces0
Traits0
Classes11
▷ Abstract classes00.00%
▷ Concrete classes11100.00%
▷ Final classes00.00%
Methods102
▷ Static methods32.94%
▷ Public methods7674.51%
▷ Protected methods00.00%
▷ Private methods2625.49%
Functions2
▷ Named functions150.00%
▷ Anonymous functions150.00%
Constants17
▷ Global constants211.76%
▷ Class constants1588.24%
▷ Public constants15100.00%

Plugin size Passed 2 tests

Image compression Passed 2 tests

Often times overlooked, PNG files can occupy unnecessary space in your plugin
5 PNG files occupy 0.02MB with 0.01MB in potential savings
Potential savings
Compression of 5 random PNG files using pngquant
FileSize - originalSize - compressedSavings
assets/images/flp-success-icon.png4.11KB2.06KB▼ 50.00%
assets/images/tick.png4.00KB2.50KB▼ 37.59%
assets/images/logo_200.png4.23KB2.45KB▼ 42.05%
assets/images/icon.png1.47KB0.52KB▼ 64.65%
assets/images/flp-get-otp.png6.13KB3.11KB▼ 49.24%