62% miniorange-google-apps-login

Code Review | Login with Google Apps

WordPress plugin Login with Google Apps scored62%from 54 tests.

About plugin

  • Plugin page: miniorange-google...
  • Plugin version: 7.0.1
  • PHP compatiblity: 5.3+
  • PHP version: 7.4.16
  • WordPress compatibility: 3.5-5.8
  • WordPress version: 6.3.1
  • First release: Jun 27, 2016
  • Latest release: Dec 2, 2021
  • Number of updates: 31
  • Update frequency: every 65.4 days
  • Top authors: cyberlord92 (100%)

Code review

54 tests

User reviews

2 reviews

Install metrics

70+ active /9,185 total downloads

Benchmarks

Plugin footprint 83% from 16 tests

Installer Passed 1 test

🔺 Critical test (weight: 50) | All plugins must install correctly, without throwing any errors, warnings, or notices
The plugin installed successfully, without throwing any errors or notices

Server metrics [RAM: ▲1.57MB] [CPU: ▲8.69ms] Passed 4 tests

Analyzing server-side resources used by Login with Google Apps
Server-side resource usage in normal parameters
PageMemory (MB)CPU Time (ms)
Home /5.03 ▲1.5757.40 ▲13.34
Dashboard /wp-admin4.87 ▲1.5768.36 ▲11.02
Posts /wp-admin/edit.php4.99 ▲1.6361.99 ▲7.49
Add New Post /wp-admin/post-new.php7.47 ▲1.59101.49 ▲2.91
Media Library /wp-admin/upload.php4.80 ▲1.5755.85 ▲19.84
Import Export Configuration /wp-admin/admin.php?page=saml_import_export_config4.8048.77
Licensing Plans /wp-admin/admin.php?page=gsuitepricing4.9354.12
Proxy Setup /wp-admin/admin.php?page=proxy_setup4.8052.65
Service Provider /wp-admin/admin.php?page=service_provider_saml4.8055.29
Attribute/Role Mapping /wp-admin/admin.php?page=mapping_saml4.8154.46
Identity Provider /wp-admin/admin.php?page=identity_provider_saml4.8053.98
Google Apps Login /wp-admin/admin.php?page=mogalsettings4.8151.38
Account /wp-admin/admin.php?page=galoginaccount4.8054.87
Sign in Settings /wp-admin/admin.php?page=sign_in_setting_saml4.8045.02
Add-ons /wp-admin/admin.php?page=addons_saml4.8051.29

Server storage [IO: ▲2.15MB] [DB: ▲0.00MB] Passed 3 tests

A short overview of filesystem and database impact
No storage issues were detected
Filesystem: 160 new files
Database: no new tables, 9 new options
New WordPress options
widget_recent-posts
can_compress_scripts
mo_saml_free_version
widget_theysaidso_widget
db_upgraded
widget_saml_login_widget
theysaidso_admin_options
widget_recent-comments
widget_mo_oauth_widget_new

Browser metrics Passed 4 tests

An overview of browser requirements for Login with Google Apps
There were no issues detected in relation to browser resource usage
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /2,861 ▲10014.30 ▼0.051.90 ▲0.1441.53 ▼3.84
Dashboard /wp-admin2,250 ▲795.67 ▲0.0097.97 ▲0.0786.52 ▲40.47
Posts /wp-admin/edit.php2,170 ▲702.06 ▲0.0835.72 ▼1.2135.25 ▼2.66
Add New Post /wp-admin/post-new.php1,737 ▲20222.23 ▲4.05775.59 ▲115.0453.44 ▼9.48
Media Library /wp-admin/upload.php1,470 ▲704.24 ▲0.06115.31 ▲7.9246.59 ▲1.79
Import Export Configuration /wp-admin/admin.php?page=saml_import_export_config1,1222.2225.8433.95
Licensing Plans /wp-admin/admin.php?page=gsuitepricing2,3412.3646.7981.78
Proxy Setup /wp-admin/admin.php?page=proxy_setup1,1432.2027.0533.42
Service Provider /wp-admin/admin.php?page=service_provider_saml1,2592.1026.4033.56
Attribute/Role Mapping /wp-admin/admin.php?page=mapping_saml1,4402.1133.4536.96
Identity Provider /wp-admin/admin.php?page=identity_provider_saml1,2932.2326.0247.77
Google Apps Login /wp-admin/admin.php?page=mogalsettings1,2962.2328.8142.29
Account /wp-admin/admin.php?page=galoginaccount1,1722.2528.9629.27
Sign in Settings /wp-admin/admin.php?page=sign_in_setting_saml1,2202.2224.7347.37
Add-ons /wp-admin/admin.php?page=addons_saml1,0552.2125.2941.65

Uninstaller [IO: ▲0.00MB] [DB: ▲0.00MB] 75% from 4 tests

🔸 Tests weight: 35 | The uninstall procedure must remove all plugin files and extra database tables
The following items require your attention
  • The uninstall procedure has failed, leaving 8 options in the database
    • db_upgraded
    • widget_recent-posts
    • can_compress_scripts
    • theysaidso_admin_options
    • widget_recent-comments
    • widget_saml_login_widget
    • widget_theysaidso_widget
    • widget_mo_oauth_widget_new

Smoke tests 25% from 4 tests

Server-side errors Passed 1 test

🔹 Test weight: 20 | Just a short smoke test targeting errors on the server (in the Apache logs)
Even though no errors were found, this is by no means an exhaustive test

SRP 0% from 2 tests

🔹 Tests weight: 20 | SRP (Single-Responsibility Principle) - PHP files must act as libraries and never output text or perform any action when accessed directly in a browser
Please fix the following
  • 6× PHP files perform the action of outputting non-empty strings when accessed directly:
    • > /wp-content/plugins/miniorange-google-apps-login/views/settings.php
    • > /wp-content/plugins/miniorange-google-apps-login/views/oauth/oauth_customization.php
    • > /wp-content/plugins/miniorange-google-apps-login/views/oauth/oauth_addons.php
    • > /wp-content/plugins/miniorange-google-apps-login/views/oauth/oauth-configuration-update-app-custom.php
    • > /wp-content/plugins/miniorange-google-apps-login/views/oauth/oauth_sign_in_settings.php
    • > /wp-content/plugins/miniorange-google-apps-login/views/saml/saml-addons.php
  • 117× GET requests to PHP files trigger server-side errors or Error 500 responses (only 10 are shown):
    • > PHP Fatal error
      Uncaught Error: Call to undefined function mo_saml_get_test_url() in wp-content/plugins/miniorange-google-apps-login/views/saml/saml-sp.php:12
    • > PHP Fatal error
      Uncaught Error: Call to undefined function admin_url() in wp-content/plugins/miniorange-google-apps-login/controllers/settings.php:2
    • > PHP Warning
      include(MOV_GSUITE_DIRviews/oauth/instructions/class-mo-oauth-instruction-html.php): failed to open stream: No such file or directory in wp-content/plugins/miniorange-google-apps-login/controllers/oauth/oauth-configuration.php on line 9
    • > PHP Warning
      include(MOV_GSUITE_DIRviews/oauth/oauth_sign_in_settings.php): failed to open stream: No such file or directory in wp-content/plugins/miniorange-google-apps-login/controllers/oauth/oauth-signinsetting.php on line 9
    • > PHP Fatal error
      Uncaught Error: Call to undefined function esc_html() in wp-content/plugins/miniorange-google-apps-login/views/oauth/oauth-configuration-update-app-standard.php:21
    • > PHP Fatal error
      Uncaught Error: Call to undefined function get_mo_gsuite_option() in wp-content/plugins/miniorange-google-apps-login/controllers/messages.php:3
    • > PHP Warning
      include(MOV_GSUITE_DIRviews/oauth/oauth_report.php): failed to open stream: No such file or directory in wp-content/plugins/miniorange-google-apps-login/controllers/oauth/oauth-report.php on line 8
    • > PHP Warning
      include(MOV_GSUITE_DIRviews/saml/saml-addons.php): failed to open stream: No such file or directory in wp-content/plugins/miniorange-google-apps-login/controllers/saml/saml-addons.php on line 5
    • > PHP Fatal error
      Uncaught Error: Call to undefined function esc_html() in wp-content/plugins/miniorange-google-apps-login/views/oauth/oauth_report.php:21
    • > PHP Fatal error
      Uncaught Error: Class 'Base_Request_action' not found in wp-content/plugins/miniorange-google-apps-login/handler/saml/class-mo-gsuite-saml-request-handler.php:9

User-side errors 0% from 1 test

🔹 Test weight: 20 | A shallow check that no browser errors were triggered
There are user-side issues you should fix
  • 10 occurences, only the last one shown
    • > GET request to /wp-admin/admin.php?page=addons_saml
    • > Network (severe)
    wp-content/plugins/miniorange-google-apps-login/includes/js/toggleSwitch.js?version=2.1.0&ver=6.3.1 - Failed to load resource: the server responded with a status of 404 (Not Found)
    • > GET request to /wp-admin/admin.php?page=saml_import_export_config
    • > Javascript (severe) in unknown
    /wp-admin/admin.php?page=saml_import_export_config 223:22 Uncaught ReferenceError: x is not defined
    • > GET request to /wp-admin/admin.php?page=gsuitepricing
    • > Javascript (severe) in unknown
    /wp-admin/admin.php?page=gsuitepricing 215:22 Uncaught ReferenceError: x is not defined
    • > GET request to /wp-admin/admin.php?page=proxy_setup
    • > Javascript (severe) in unknown
    /wp-admin/admin.php?page=proxy_setup 223:22 Uncaught ReferenceError: x is not defined
    • > GET request to /wp-admin/admin.php?page=service_provider_saml
    • > Javascript (severe) in unknown
    /wp-admin/admin.php?page=service_provider_saml 223:22 Uncaught ReferenceError: x is not defined
    • > GET request to /wp-admin/admin.php?page=mapping_saml
    • > Javascript (severe) in unknown
    /wp-admin/admin.php?page=mapping_saml 223:22 Uncaught ReferenceError: x is not defined
    • > GET request to /wp-admin/admin.php?page=identity_provider_saml
    • > Javascript (severe) in unknown
    /wp-admin/admin.php?page=identity_provider_saml 223:22 Uncaught ReferenceError: x is not defined
    • > GET request to /wp-admin/admin.php?page=mogalsettings
    • > Javascript (severe) in unknown
    /wp-admin/admin.php?page=mogalsettings 223:22 Uncaught ReferenceError: x is not defined
    • > GET request to /wp-admin/admin.php?page=galoginaccount
    • > Javascript (severe) in unknown
    /wp-admin/admin.php?page=galoginaccount 223:22 Uncaught ReferenceError: x is not defined
    • > GET request to /wp-admin/admin.php?page=sign_in_setting_saml
    • > Javascript (severe) in unknown
    /wp-admin/admin.php?page=sign_in_setting_saml 223:22 Uncaught ReferenceError: x is not defined
    • > GET request to /wp-admin/admin.php?page=addons_saml
    • > Javascript (severe) in unknown
    /wp-admin/admin.php?page=addons_saml 223:22 Uncaught ReferenceError: x is not defined

Optimizations

Plugin configuration 90% from 29 tests

readme.txt 94% from 16 tests

The readme.txt file is important because it is parsed by WordPress.org for the public listing of your plugin
These attributes need to be fixed:
  • Screenshots: Screenshot #4 (Configure your IdP in your WordPress site.) image missing
You can look at the official readme.txt

miniorange-google-apps-login/miniorange_validation_settings.php 85% from 13 tests

The primary PHP file in "Login with Google Apps" version 7.0.1 is used by WordPress to initiate all plugin functionality
Please take the time to fix the following:
  • Main file name: Name the main plugin file the same as the plugin slug ("miniorange-google-apps-login.php" instead of "miniorange_validation_settings.php")
  • Text Domain: If you choose to specify the text domain, it must be the same as the plugin slug; optional since WordPress version 4.6

Code Analysis 5% from 3 tests

File types 0% from 1 test

🔸 Test weight: 35 | Executable files are not allowed as they can serve as attack vectors
Please fix the following items
  • Do not distribute dangerous files with your plugin
    • .crt - Security Certificate in Firefox, IE, Chrome, Safari
      • wp-content/plugins/miniorange-google-apps-login/resources/saml-resources/sp-certificate.crt
17,844 lines of code in 128 files:
LanguageFilesBlank linesComment linesLines of code
PHP1082,1301,88211,350
CSS101,2431304,645
PO File16738911,680
JavaScript72436101
HTML20068

PHP code Passed 2 tests

This is a short overview of cyclomatic complexity and code structure for this plugin
This plugin has no cyclomatic complexity problems
Cyclomatic complexity
Average complexity per logical line of code0.34
Average class complexity15.70
▷ Minimum class complexity1.00
▷ Maximum class complexity136.00
Average method complexity3.25
▷ Minimum method complexity1.00
▷ Maximum method complexity35.00
Code structure
Namespaces0
Interfaces6
Traits0
Classes54
▷ Abstract classes47.41%
▷ Concrete classes5092.59%
▷ Final classes00.00%
Methods409
▷ Static methods8721.27%
▷ Public methods36789.73%
▷ Protected methods00.00%
▷ Private methods4210.27%
Functions39
▷ Named functions39100.00%
▷ Anonymous functions00.00%
Constants121
▷ Global constants2117.36%
▷ Class constants10082.64%
▷ Public constants100100.00%

Plugin size Passed 2 tests

Image compression Passed 2 tests

It is recommended to compress PNG files in your plugin to minimize bandwidth usage
19 PNG files occupy 0.42MB with 0.17MB in potential savings
Potential savings
Compression of 5 random PNG files using pngquant
FileSize - originalSize - compressedSavings
includes/images/flags@2x.png169.54KB64.26KB▼ 62.10%
includes/images/ui-icons_222222_256x240.png6.76KB4.17KB▼ 38.24%
includes/images/ui-icons_888888_256x240.png6.83KB4.17KB▼ 38.92%
includes/images/SAML/wrong.png30.98KB13.50KB▼ 56.42%
includes/images/ui-icons_2e83ff_256x240.png4.44KB4.17KB▼ 6.02%