10% ider-login

Code Review | IDer Login for Wordpress

WordPress plugin IDer Login for Wordpress scored10%from 54 tests.

About plugin

  • Plugin page: ider-login
  • Plugin version: 1.6.1
  • PHP version: 7.4.16
  • WordPress compatibility: 4.6-4.9.8
  • WordPress version: 6.3.1
  • First release: Mar 11, 2017
  • Latest release: Mar 10, 2019
  • Number of updates: 32
  • Update frequency: every 22.6 days
  • Top authors: ider (100%)

Code review

54 tests

User reviews

1 review

Install metrics

10+ active /854 total downloads

Benchmarks

Plugin footprint 58% from 16 tests

Installer 0% from 1 test

🔺 Critical test (weight: 50) | Checking the installer triggered no errors
These installer errors require your attention
  • Install procedure had errors
    • > Warning in wp-content/plugins/ider-login/includes/IDER_Server.php+85
    array_key_exists() expects parameter 2 to be array, bool given

Server metrics [RAM: ▲0.07MB] [CPU: ▲4.88ms] Passed 4 tests

A check of server-side resources used by IDer Login for Wordpress
This plugin has minimal impact on server resources
PageMemory (MB)CPU Time (ms)
Home /3.54 ▲0.0846.24 ▲7.66
Dashboard /wp-admin3.38 ▲0.0749.69 ▲2.27
Posts /wp-admin/edit.php3.47 ▲0.1255.93 ▲10.36
Add New Post /wp-admin/post-new.php5.95 ▲0.0794.79 ▲0.66
Media Library /wp-admin/upload.php3.30 ▲0.0743.26 ▲8.93

Server storage [IO: ▲1.31MB] [DB: ▲0.00MB] Passed 3 tests

Filesystem and database footprint
This plugin was installed successfully
Filesystem: 69 new files
Database: no new tables, 8 new options
New WordPress options
widget_theysaidso_widget
widget_recent-comments
widget_ider_widget
widget_recent-posts
wposso_options
db_upgraded
theysaidso_admin_options
can_compress_scripts

Browser metrics Passed 4 tests

This is an overview of browser requirements for IDer Login for Wordpress
There were no issues detected in relation to browser resource usage
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /2,847 ▲11214.47 ▲0.091.82 ▲0.1837.66 ▼10.66
Dashboard /wp-admin2,221 ▲334.93 ▼0.97101.34 ▼0.9883.04 ▲39.83
Posts /wp-admin/edit.php2,110 ▲182.03 ▲0.0438.23 ▲3.2434.68 ▲1.72
Add New Post /wp-admin/post-new.php1,690 ▲15724.80 ▲1.82686.68 ▲10.8460.69 ▲4.35
Media Library /wp-admin/upload.php1,403 ▲154.12 ▼0.17112.16 ▲4.8646.56 ▲0.24

Uninstaller [IO: ▲0.00MB] [DB: ▲0.00MB] 75% from 4 tests

🔸 Tests weight: 35 | It is important to correctly uninstall your plugin, without leaving any traces
You still need to fix the following
  • Zombie WordPress options were found after uninstall: 8 options
    • theysaidso_admin_options
    • widget_ider_widget
    • db_upgraded
    • widget_recent-comments
    • widget_recent-posts
    • widget_theysaidso_widget
    • wposso_options
    • can_compress_scripts

Smoke tests 50% from 4 tests

Server-side errors Passed 1 test

🔹 Test weight: 20 | Just a short smoke test targeting errors on the server (in the Apache logs)
Even though no errors were found, this is by no means an exhaustive test

SRP 0% from 2 tests

🔹 Tests weight: 20 | It is important to ensure that your PHP files perform no action when accessed directly, respecting the single-responsibility principle
Please fix the following items
  • 5× PHP files perform the task of outputting text when accessed with GET requests:
    • > /wp-content/plugins/ider-login/includes/IDER_Rewrites.php
    • > /wp-content/plugins/ider-login/includes/IDER_Server.php
    • > /wp-content/plugins/ider-login/wp-ider-login-client.php
    • > /wp-content/plugins/ider-login/includes/IDER_Admin.php
    • > /wp-content/plugins/ider-login/vendor/jlmsrl/ider-openid-client-php/example.php
  • 10× PHP files trigger server-side errors or warnings when accessed directly:
    • > PHP Fatal error
      Uncaught Error: Class 'phpseclib\\Crypt\\Base' not found in wp-content/plugins/ider-login/vendor/phpseclib/phpseclib/phpseclib/Crypt/RC2.php:46
    • > PHP Fatal error
      Uncaught Error: Class 'phpseclib\et\\SSH2' not found in wp-content/plugins/ider-login/vendor/phpseclib/phpseclib/phpseclib/Net/SFTP.php:49
    • > PHP Fatal error
      Uncaught Error: Class 'phpseclib\\Crypt\\DES' not found in wp-content/plugins/ider-login/vendor/phpseclib/phpseclib/phpseclib/Crypt/TripleDES.php:49
    • > PHP Fatal error
      Uncaught Error: Class 'phpseclib\\Crypt\\Rijndael' not found in wp-content/plugins/ider-login/vendor/phpseclib/phpseclib/phpseclib/Crypt/AES.php:61
    • > PHP Fatal error
      Uncaught Error: Class 'phpseclib\\Crypt\\Base' not found in wp-content/plugins/ider-login/vendor/phpseclib/phpseclib/phpseclib/Crypt/Rijndael.php:66
    • > PHP Fatal error
      Uncaught Error: Class 'phpseclib\\Crypt\\Base' not found in wp-content/plugins/ider-login/vendor/phpseclib/phpseclib/phpseclib/Crypt/Twofish.php:50
    • > PHP Fatal error
      Uncaught Error: Class 'WP_Widget' not found in wp-content/plugins/ider-login/includes/IDER_Widget.php:14
    • > PHP Fatal error
      Uncaught Error: Class 'phpseclib\\Crypt\\Base' not found in wp-content/plugins/ider-login/vendor/phpseclib/phpseclib/phpseclib/Crypt/Blowfish.php:50
    • > PHP Fatal error
      Uncaught Error: Class 'phpseclib\\Crypt\\Base' not found in wp-content/plugins/ider-login/vendor/phpseclib/phpseclib/phpseclib/Crypt/DES.php:54
    • > PHP Fatal error
      Uncaught Error: Class 'phpseclib\\Crypt\\Base' not found in wp-content/plugins/ider-login/vendor/phpseclib/phpseclib/phpseclib/Crypt/RC4.php:56

User-side errors Passed 1 test

🔹 Test weight: 20 | Just a short smoke test targeting errors on the browser (console and network errors and warnings)
No browser errors were detected

Optimizations

Plugin configuration 93% from 29 tests

readme.txt 94% from 16 tests

Don't ignore readme.txt as it is the file that instructs WordPress.org on how to present your plugin to the world
Attributes that require attention:
  • Contributors: Plugin contributors field is missing
Please take inspiration from this readme.txt

ider-login/wp-ider-login-client.php 92% from 13 tests

The entry point to "IDer Login for Wordpress" version 1.6.1 is a PHP file that has certain tags in its header comment area
It is important to fix the following:
  • Main file name: The principal plugin file should be the same as the plugin slug ("ider-login.php" instead of "wp-ider-login-client.php")

Code Analysis 97% from 3 tests

File types Passed 1 test

🔸 Test weight: 35 | Executable files are considered dangerous and should not be included with any WordPress plugin
Success! There were no dangerous files found in this plugin20,507 lines of code in 56 files:
LanguageFilesBlank linesComment linesLines of code
PHP463,75411,84620,053
JSON400244
Markdown3620135
CSS213069
JavaScript1206

PHP code 50% from 2 tests

Analyzing cyclomatic complexity and code structure
Please fix the following
  • Method cyclomatic complexity should be reduced to less than 100 (currently 104)
Cyclomatic complexity
Average complexity per logical line of code0.39
Average class complexity84.13
▷ Minimum class complexity1.00
▷ Maximum class complexity550.00
Average method complexity5.80
▷ Minimum method complexity1.00
▷ Maximum method complexity104.00
Code structure
Namespaces10
Interfaces0
Traits0
Classes39
▷ Abstract classes12.56%
▷ Concrete classes3897.44%
▷ Final classes00.00%
Methods681
▷ Static methods466.75%
▷ Public methods66197.06%
▷ Protected methods30.44%
▷ Private methods172.50%
Functions7
▷ Named functions114.29%
▷ Anonymous functions685.71%
Constants182
▷ Global constants2714.84%
▷ Class constants15585.16%
▷ Public constants155100.00%

Plugin size Passed 2 tests

Image compression Passed 2 tests

All PNG images should be compressed to minimize bandwidth usage for end users
3 PNG files occupy 0.04MB with 0.02MB in potential savings
Potential savings
Compression of 3 random PNG files using pngquant
FileSize - originalSize - compressedSavings
assets/images/logo_ider_big.png40.24KB9.89KB▼ 75.43%
assets/images/ider_logo_white_32.png1.59KB1.02KB▼ 35.87%
assets/images/logo_ider.png1.59KB1.02KB▼ 35.87%