78% hcaptcha-for-forms-and-more

Code Review | hCaptcha for WordPress

WordPress plugin hCaptcha for WordPress scored78%from 54 tests.

About plugin

  • Plugin page: hcaptcha-for-form...
  • Plugin version: 3.4.1
  • PHP compatiblity: 7.0+
  • PHP version: 7.4.16
  • WordPress compatibility: 5.0-6.4
  • WordPress version: 6.3.1
  • First release: May 2, 2019
  • Latest release: Nov 7, 2023
  • Number of updates: 113
  • Update frequency: every 14.6 days
  • Top authors: hcaptcha (100%)

Code review

54 tests

User reviews

42 reviews

Install metrics

50,000+ active /606,329 total downloads

Benchmarks

Plugin footprint 83% from 16 tests

Installer Passed 1 test

🔺 Critical test (weight: 50) | All plugins must install correctly, without throwing any errors, warnings, or notices
Installer ran successfully

Server metrics [RAM: ▲1.08MB] [CPU: ▼0.53ms] Passed 4 tests

This is a short check of server-side resources used by hCaptcha for WordPress
Normal server usage
PageMemory (MB)CPU Time (ms)
Home /4.56 ▲1.1052.35 ▲7.61
Dashboard /wp-admin4.38 ▲1.0457.32 ▼10.00
Posts /wp-admin/edit.php4.50 ▲1.1465.21 ▲12.85
Add New Post /wp-admin/post-new.php6.99 ▲1.1090.79 ▼11.19
Media Library /wp-admin/upload.php4.31 ▲1.0846.68 ▲11.46
hCaptcha /wp-admin/options-general.php?page=hcaptcha4.3542.44

Server storage [IO: ▲1.16MB] [DB: ▲0.00MB] Passed 3 tests

Analyzing filesystem and database footprints of this plugin
No storage issues were detected
Filesystem: 272 new files
Database: no new tables, 8 new options
New WordPress options
can_compress_scripts
widget_recent-comments
widget_recent-posts
widget_theysaidso_widget
theysaidso_admin_options
hcaptcha_versions
hcaptcha_settings
db_upgraded

Browser metrics Passed 4 tests

Checking browser requirements for hCaptcha for WordPress
This plugin has a minimal impact on browser resources
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /2,831 ▲8414.32 ▲0.012.11 ▼0.0443.88 ▼0.19
Dashboard /wp-admin2,208 ▲345.66 ▲0.0291.66 ▼8.6538.67 ▼8.07
Posts /wp-admin/edit.php2,113 ▲132.00 ▲0.0536.57 ▼2.2132.22 ▼2.75
Add New Post /wp-admin/post-new.php1,541 ▲1522.95 ▼0.35667.27 ▼31.1558.77 ▼0.48
Media Library /wp-admin/upload.php1,419 ▲164.22 ▲0.02100.83 ▼0.3741.57 ▼5.07
hCaptcha /wp-admin/options-general.php?page=hcaptcha1,8762.4945.9446.76

Uninstaller [IO: ▲0.00MB] [DB: ▲0.00MB] 75% from 4 tests

🔸 Tests weight: 35 | Checking the uninstaller removed all traces of the plugin
You still need to fix the following
  • This plugin does not fully uninstall, leaving 8 options in the database
    • widget_recent-posts
    • widget_theysaidso_widget
    • can_compress_scripts
    • theysaidso_admin_options
    • widget_recent-comments
    • hcaptcha_settings
    • hcaptcha_versions
    • db_upgraded

Smoke tests 50% from 4 tests

Server-side errors Passed 1 test

🔹 Test weight: 20 | A smoke test targeting server-side errors
Good news, no errors were detected

SRP 50% from 2 tests

🔹 Tests weight: 20 | A shallow check of the single-responsibility principle; PHP files should perform no action - including output of placeholder text - and trigger no errors when accessed directly
Please fix the following
  • 43× GET requests to PHP files trigger server-side errors or Error 500 responses (only 10 are shown):
    • > PHP Fatal error
      Uncaught Error: Call to undefined function add_shortcode() in wp-content/plugins/hcaptcha-for-forms-and-more/src/php/includes/functions.php:87
    • > PHP Fatal error
      Uncaught Error: Class 'HCaptcha\\UM\\Base' not found in wp-content/plugins/hcaptcha-for-forms-and-more/src/php/UM/Register.php:13
    • > PHP Fatal error
      Uncaught Error: Class 'HCaptcha\\UM\\Base' not found in wp-content/plugins/hcaptcha-for-forms-and-more/src/php/UM/LostPassword.php:13
    • > PHP Fatal error
      Uncaught Error: Class 'HCaptcha\\BBPress\\Base' not found in wp-content/plugins/hcaptcha-for-forms-and-more/src/php/BBPress/Reply.php:13
    • > PHP Fatal error
      Uncaught Error: Class 'HCaptcha\\Abstracts\\LoginBase' not found in wp-content/plugins/hcaptcha-for-forms-and-more/src/php/Divi/Login.php:18
    • > PHP Fatal error
      Uncaught Error: Class 'HCaptcha\\Asgaros\\Base' not found in wp-content/plugins/hcaptcha-for-forms-and-more/src/php/Asgaros/Form.php:14
    • > PHP Fatal error
      Uncaught Error: Class 'HCaptcha\\Abstracts\\LoginBase' not found in wp-content/plugins/hcaptcha-for-forms-and-more/src/php/UsersWP/Login.php:17
    • > PHP Fatal error
      Uncaught Error: Class 'HCaptcha\\Abstracts\\LoginBase' not found in wp-content/plugins/hcaptcha-for-forms-and-more/src/php/PaidMembershipsPro/Login.php:18
    • > PHP Fatal error
      Uncaught Error: Class 'HCaptcha\\WPForo\\Base' not found in wp-content/plugins/hcaptcha-for-forms-and-more/src/php/WPForo/Reply.php:13
    • > PHP Fatal error
      Uncaught Error: Class 'HCaptcha\\Abstracts\\LoginBase' not found in wp-content/plugins/hcaptcha-for-forms-and-more/src/php/ProfileBuilder/Login.php:18

User-side errors 0% from 1 test

🔹 Test weight: 20 | This is a smoke test targeting browser errors/issues
These are user-side errors you should fix
    • > GET request to /wp-admin/options-general.php?page=hcaptcha
    • > Console-api (severe) in unknown
    https://js.hcaptcha.com/1/api.js?onload=hCaptchaOnLoad&render=explicit 2:288028 "Missing sitekey - https://hcaptcha.com/docs/configuration#jsapi"

Optimizations

Plugin configuration 93% from 29 tests

readme.txt Passed 16 tests

Often overlooked, readme.txt is one of the most important files in your plugin
5 plugin tags: hcaptcha, spam, recaptcha, abuse, captcha

hcaptcha-for-forms-and-more/hcaptcha.php 85% from 13 tests

The main PHP file in "hCaptcha for WordPress" ver. 3.4.1 adds more information about the plugin and also serves as the entry point for this plugin
Please take the time to fix the following:
  • Main file name: Even though not officially enforced, the main plugin file should be the same as the plugin slug ("hcaptcha-for-forms-and-more.php" instead of "hcaptcha.php")
  • Requires PHP: The required version number did not match the one declared in readme.txt ("7.0.0" instead of "7.0")

Code Analysis Passed 3 tests

File types Passed 1 test

🔸 Test weight: 35 | This is a short overview of programming languages used in this plugin, detecting executable files
Good job! No executable or dangerous file extensions detected12,244 lines of code in 218 files:
LanguageFilesBlank linesComment linesLines of code
PHP1292,7396,70610,054
JavaScript613171541,196
CSS161215637
SVG972207
PO File14952140
HTML1105
JSON1005

PHP code Passed 2 tests

Analyzing logical lines of code, cyclomatic complexity, and other code metrics
All good! No complexity issues found
Cyclomatic complexity
Average complexity per logical line of code0.29
Average class complexity7.85
▷ Minimum class complexity1.00
▷ Maximum class complexity84.00
Average method complexity2.24
▷ Minimum method complexity1.00
▷ Maximum method complexity18.00
Code structure
Namespaces60
Interfaces1
Traits0
Classes120
▷ Abstract classes1512.50%
▷ Concrete classes10587.50%
▷ Final classes00.00%
Methods668
▷ Static methods436.44%
▷ Public methods46569.61%
▷ Protected methods9914.82%
▷ Private methods10415.57%
Functions35
▷ Named functions1542.86%
▷ Anonymous functions2057.14%
Constants244
▷ Global constants10.41%
▷ Class constants24399.59%
▷ Public constants243100.00%

Plugin size 50% from 2 tests

Image compression 50% from 2 tests

It is recommended to compress PNG files in your plugin to minimize bandwidth usage
48 PNG files occupy 0.50MB with 0.26MB in potential savings
Potential savings
Compression of 5 random PNG files using pngquant
FileSize - originalSize - compressedSavings
assets/images/passster-logo.png6.22KB3.44KB▼ 44.64%
assets/images/formidable-forms-logo.png6.68KB3.69KB▼ 44.80%
assets/images/memberpress-logo.png20.20KB5.26KB▼ 73.94%
assets/images/divi-logo.png6.71KB3.17KB▼ 52.74%
assets/images/sendinblue-logo.png6.00KB3.52KB▼ 41.32%