10% lockerpress-wordpress-security

Code Review | LockerPress - WordPress Security Plugin

WordPress plugin LockerPress - WordPress Security Plugin scored10%from 54 tests.

About plugin

  • Plugin page: lockerpress-wordp...
  • Plugin version: 1.0
  • PHP version: 7.4.16
  • WordPress compatibility: 3.0-3.4
  • WordPress version: 6.3.1
  • First release: Jun 20, 2012
  • Latest release: Jul 1, 2012
  • Number of updates: 14
  • Update frequency: every 0.8 days
  • Top authors: lockerpress (100%)

Code review

54 tests

User reviews

1 review

Install metrics

80+ active /5,508 total downloads

Benchmarks

Plugin footprint 40% from 16 tests

Installer 0% from 1 test

🔺 Critical test (weight: 50) | Verifying that this plugin installs correctly without errors
It is recommended to fix the following installer errors
  • This plugin did not install gracefully
    • > User deprecated in wp-includes/functions.php+5737
    Function get_bloginfo was called with an argument that is deprecated since version 2.2.0! The siteurl option is deprecated for the family of bloginfo() functions. Use the url option instead.

Server metrics [RAM: ▼1.88MB] [CPU: ▼50.38ms] Passed 4 tests

Analyzing server-side resources used by LockerPress - WordPress Security Plugin
Server-side resource usage in normal parameters
PageMemory (MB)CPU Time (ms)
Home /2.11 ▼1.366.20 ▼31.17
Dashboard /wp-admin2.13 ▼1.185.78 ▼40.80
Posts /wp-admin/edit.php2.13 ▼1.236.14 ▼41.37
Add New Post /wp-admin/post-new.php2.13 ▼3.767.13 ▼88.16
Media Library /wp-admin/upload.php2.13 ▼1.106.13 ▼24.54
LockerPress /wp-admin/admin.php?page=lockerpress-wordpress-security/core.php2.136.31
Custom Login URL /wp-admin/admin.php?page=login_url2.136.66

Server storage [IO: ▲0.97MB] [DB: ▲0.00MB] Passed 3 tests

Analyzing filesystem and database footprints of this plugin
This plugin was installed successfully
Filesystem: 29 new files
Database: no new tables, 6 new options
New WordPress options
can_compress_scripts
db_upgraded
widget_recent-comments
widget_theysaidso_widget
widget_recent-posts
theysaidso_admin_options

Browser metrics Passed 4 tests

A check of browser resources used by LockerPress - WordPress Security Plugin
This plugin has a minimal impact on browser resources
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /2,827 ▲7014.44 ▲0.071.64 ▼0.6743.33 ▼4.37
Dashboard /wp-admin2,233 ▲454.88 ▼0.03110.28 ▲4.0537.44 ▼2.81
Posts /wp-admin/edit.php2,119 ▲302.00 ▲0.0139.63 ▲0.1337.14 ▲0.75
Add New Post /wp-admin/post-new.php1,554 ▲3523.41 ▲0.09633.72 ▼48.5960.62 ▼2.86
Media Library /wp-admin/upload.php1,415 ▲274.19 ▲0.0295.01 ▼8.9942.30 ▲0.02
LockerPress /wp-admin/admin.php?page=lockerpress-wordpress-security/core.php1,0081.9833.5126.99
Custom Login URL /wp-admin/admin.php?page=login_url8742.2530.2527.52

Uninstaller [IO: ▲0.00MB] [DB: ▲0.00MB] 50% from 4 tests

🔸 Tests weight: 35 | The uninstall procedure must remove all plugin files and extra database tables
You still need to fix the following
  • Uninstall procedure had uncaught errors
    • > User deprecated in wp-includes/functions.php+5737
    Function get_bloginfo was called with an argument that is deprecated since version 2.2.0! The siteurl option is deprecated for the family of bloginfo() functions. Use the url option instead.
  • The uninstall procedure has failed, leaving 6 options in the database
    • widget_recent-posts
    • widget_theysaidso_widget
    • widget_recent-comments
    • db_upgraded
    • can_compress_scripts
    • theysaidso_admin_options

Smoke tests 0% from 4 tests

Server-side errors 0% from 1 test

🔹 Test weight: 20 | This is a short smoke test looking for server-side errors
These server-side errors were triggered
  • 9 occurences, only the last one shown
    • > GET request to /wp-admin/admin.php?page=login_url
    • > POST request to /wp-admin/admin-ajax.php
    • > User deprecated in wp-includes/functions.php+5737
    Function get_bloginfo was called with an argument that is deprecated since version 2.2.0! The siteurl option is deprecated for the family of bloginfo() functions. Use the url option instead.
  • 21 occurences, only the last one shown
    • > GET request to /wp-admin/admin.php?page=login_url
    • > POST request to /wp-admin/admin-ajax.php
    • > Notice in wp-content/plugins/lockerpress-wordpress-security/core.php+65
    Trying to access array offset on value of type bool
  • 2 occurences, only the last one shown
    • > GET request to /wp-admin/admin.php?page=login_url
    • > POST request to /wp-admin/admin-ajax.php
    • > Notice in wp-content/plugins/lockerpress-wordpress-security/core.php+189
    unserialize(): Error at offset 0 of 77 bytes

SRP 0% from 2 tests

🔹 Tests weight: 20 | The single-responsibility principle: PHP files have to remain inert when accessed directly, throwing no errors and performing no actions
Please fix the following
  • 1× PHP files output non-empty strings when accessed directly via GET requests:
    • > /wp-content/plugins/lockerpress-wordpress-security/views/footer.php
  • 4× PHP files trigger errors when accessed directly with GET requests:
    • > PHP Fatal error
      Uncaught Error: Call to undefined function register_activation_hook() in wp-content/plugins/lockerpress-wordpress-security/core.php:14
    • > PHP Fatal error
      Uncaught Error: Call to undefined function register_activation_hook() in wp-content/plugins/lockerpress-wordpress-security/core.php:14
    • > PHP Fatal error
      Uncaught Error: Call to undefined function get_option() in wp-content/plugins/lockerpress-wordpress-security/views/login_url.php:20
    • > PHP Fatal error
      Uncaught Error: Call to undefined function wp_enqueue_style() in wp-content/plugins/lockerpress-wordpress-security/views/wpsecure_index.php:2

User-side errors 0% from 1 test

🔹 Test weight: 20 | This is a smoke test targeting browser errors/issues
These are user-side errors you should fix
    • > GET request to /wp-admin/admin.php?page=lockerpress-wordpress-security/core.php
    • > Network (severe)
    wp-content/plugins/lockerpress/css/ui-lightness/jquery-ui-1.8.20.custom.css?ver=6.3.1 - Failed to load resource: the server responded with a status of 404 (Not Found)
    • > GET request to /wp-admin/admin.php?page=login_url
    • > Network (severe)
    wp-content/plugins/lockerpress/images/lockerpress_logo.png - Failed to load resource: the server responded with a status of 404 (Not Found)

Optimizations

Plugin configuration 87% from 29 tests

readme.txt 88% from 16 tests

The readme.txt file is important because it is parsed by WordPress.org for the public listing of your plugin
Attributes that require attention:
  • Tags: There are too many tags (20 tag instead of maximum 10)
  • Screenshots: These screenshots require images: #1 (LockerPress WordPress Security - Main Admin Panel), #2 (LockerPress - Custom Login URL), #3 (LockerPress - Change Admin User), #4 (LockerPress - Set Hack/Ban Settings & Email Notification of Failed Login Attempts), #5 (LockerPress - Enable HTTP Authentication)
The official readme.txt might help

lockerpress-wordpress-security/lockerpress.php 85% from 13 tests

"LockerPress - WordPress Security Plugin" version 1.0's main PHP file describes plugin functionality and also serves as the entry point to any WordPress functionality
Please take the time to fix the following:
  • Main file name: Even though not officially enforced, the main plugin file should be the same as the plugin slug ("lockerpress-wordpress-security.php" instead of "lockerpress.php")
  • Description: Please keep the plugin description shorter than 140 characters (currently 215 characters long)

Code Analysis Passed 3 tests

File types Passed 1 test

🔸 Test weight: 35 | A short check of programming languages and file extensions; no executable files are allowed
Everything looks great! No dangerous files found in this plugin769 lines of code in 7 files:
LanguageFilesBlank linesComment linesLines of code
PHP64315387
CSS133150382

PHP code Passed 2 tests

Cyclomatic complexity and code structure are the fingerprint of this plugin
This plugin has no cyclomatic complexity issues
Cyclomatic complexity
Average complexity per logical line of code0.31
Average class complexity29.00
▷ Minimum class complexity29.00
▷ Maximum class complexity29.00
Average method complexity3.15
▷ Minimum method complexity1.00
▷ Maximum method complexity12.00
Code structure
Namespaces0
Interfaces0
Traits0
Classes1
▷ Abstract classes00.00%
▷ Concrete classes1100.00%
▷ Final classes00.00%
Methods13
▷ Static methods00.00%
▷ Public methods1184.62%
▷ Protected methods00.00%
▷ Private methods215.38%
Functions3
▷ Named functions3100.00%
▷ Anonymous functions00.00%
Constants0
▷ Global constants00.00%
▷ Class constants00.00%
▷ Public constants00.00%

Plugin size Passed 2 tests

Image compression Passed 2 tests

All PNG images should be compressed to minimize bandwidth usage for end users
15 PNG files occupy 0.03MB with 0.01MB in potential savings
Potential savings
Compression of 5 random PNG files using pngquant
FileSize - originalSize - compressedSavings
css/ui-lightness/images/ui-bg_diagonals-thick_18_b81900_40x40.png0.25KB0.15KB▼ 39.62%
css/ui-lightness/images/ui-bg_highlight-soft_100_eeeeee_1x100.png0.09KB0.14KB0.00%
css/ui-lightness/images/ui-icons_ffd27a_256x240.png4.27KB4.11KB▼ 3.78%
css/ui-lightness/images/ui-bg_flat_10_000000_40x100.png0.17KB0.08KB▼ 51.12%
css/ui-lightness/images/ui-bg_highlight-soft_75_ffe45c_1x100.png0.13KB0.18KB0.00%