88% miniorange-login-security

Code Review | Two Factor Authentication (2FA , MFA, OTP SMS and Email)

WordPress plugin Two Factor Authentication (2FA , MFA, OTP SMS and Email) scored88%from 54 tests.

About plugin

Code review

54 tests

User reviews

6 reviews

Install metrics

600+ active /25,779 total downloads

Benchmarks

Plugin footprint 83% from 16 tests

Installer Passed 1 test

🔺 Critical test (weight: 50) | Checking the installer triggered no errors
The plugin installed gracefully, with no errors

Server metrics [RAM: ▲1.04MB] [CPU: ▲7.66ms] Passed 4 tests

An overview of server-side resources used by Two Factor Authentication (2FA , MFA, OTP SMS and Email)
No issues were detected with server-side resource usage
PageMemory (MB)CPU Time (ms)
Home /4.64 ▲1.1853.55 ▲11.24
Dashboard /wp-admin4.35 ▲1.0465.76 ▲9.69
Posts /wp-admin/edit.php4.40 ▲1.0459.83 ▲12.06
Add New Post /wp-admin/post-new.php6.95 ▲1.06105.85 ▼2.34
Media Library /wp-admin/upload.php4.27 ▲1.0453.54 ▲16.14
Two Factor /wp-admin/admin.php?page=mo_2fa_two_fa4.4567.37
/wp-admin/users.php?page=reset4.2358.23
Troubleshooting /wp-admin/admin.php?page=mo_2fa_troubleshooting4.2147.32
Account /wp-admin/admin.php?page=mo_2fa_account4.3450.12

Server storage [IO: ▲1.85MB] [DB: ▲0.00MB] Passed 3 tests

How much does this plugin use your filesystem and database?
This plugin installed successfully
Filesystem: 130 new files
Database: 2 new tables, 6 new options
New tables
wp_mo2f_user_details
wp_mo2f_user_login_info
New WordPress options
can_compress_scripts
theysaidso_admin_options
widget_recent-comments
widget_recent-posts
db_upgraded
widget_theysaidso_widget

Browser metrics Passed 4 tests

An overview of browser requirements for Two Factor Authentication (2FA , MFA, OTP SMS and Email)
There were no issues detected in relation to browser resource usage
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /2,923 ▲17713.60 ▼0.698.80 ▲7.1044.86 ▲3.63
Dashboard /wp-admin2,229 ▲414.89 ▲0.04107.44 ▲3.4169.29 ▲26.52
Posts /wp-admin/edit.php2,124 ▲382.03 ▲0.0334.93 ▼3.6634.44 ▲3.35
Add New Post /wp-admin/post-new.php1,697 ▲17722.45 ▼1.09708.59 ▲96.9446.72 ▼11.85
Media Library /wp-admin/upload.php1,423 ▲354.10 ▼0.1298.34 ▲0.1444.16 ▲1.92
Two Factor /wp-admin/admin.php?page=mo_2fa_two_fa3,48613.38274.0594.75
/wp-admin/users.php?page=reset6891.188.3320.31
Troubleshooting /wp-admin/admin.php?page=mo_2fa_troubleshooting1,1812.0829.0339.58
Account /wp-admin/admin.php?page=mo_2fa_account1,1172.0726.9737.66

Uninstaller [IO: ▲0.00MB] [DB: ▲0.00MB] 75% from 4 tests

🔸 Tests weight: 35 | The uninstall procedure must remove all plugin files and extra database tables
These items require your attention
  • Zombie WordPress options detected upon uninstall: 6 options
    • widget_theysaidso_widget
    • can_compress_scripts
    • db_upgraded
    • theysaidso_admin_options
    • widget_recent-posts
    • widget_recent-comments

Smoke tests Passed 4 tests

Server-side errors Passed 1 test

🔹 Test weight: 20 | A shallow check that no server-side errors were triggered
Good news, no errors were detected

SRP Passed 2 tests

🔹 Tests weight: 20 | The single-responsibility principle: PHP files have to remain inert when accessed directly, throwing no errors and performing no actions
Congratulations! This plugin passed the SRP test

User-side errors Passed 1 test

🔹 Test weight: 20 | This is a shallow check for browser errors
No browser errors were detected

Optimizations

Plugin configuration 90% from 29 tests

readme.txt 94% from 16 tests

The readme.txt file is important because it is parsed by WordPress.org for the public listing of your plugin
Attributes that need to be fixed:
  • Tags: Please reduce the number of tags, currently 46 tag instead of maximum 10
The official readme.txt is a good inspiration

miniorange-login-security/miniorange_2_factor_settings.php 85% from 13 tests

"Two Factor Authentication (2FA , MFA, OTP SMS and Email)" version 1.4.1's primary PHP file adds more information about the plugin and serves as the entry point for WordPress
Please take the time to fix the following:
  • Main file name: Please rename the main PHP file in this plugin to the plugin slug ("miniorange-login-security.php" instead of "miniorange_2_factor_settings.php")
  • Description: The description should be shorter than 140 characters (currently 289 characters long)

Code Analysis 97% from 3 tests

File types Passed 1 test

🔸 Test weight: 35 | Executable files are not allowed as they can serve as attack vectors
Everything looks great! No dangerous files found in this plugin15,751 lines of code in 98 files:
LanguageFilesBlank linesComment linesLines of code
PHP721,0491,6748,178
CSS157791695,511
JavaScript94922482,006
Markdown224056

PHP code 50% from 2 tests

A brief analysis of cyclomatic complexity and code structure for this plugin
The following items need your attention
  • Method cyclomatic complexity should be reduced to less than 100 (currently 144)
Cyclomatic complexity
Average complexity per logical line of code0.35
Average class complexity32.62
▷ Minimum class complexity1.00
▷ Maximum class complexity189.00
Average method complexity5.85
▷ Minimum method complexity1.00
▷ Maximum method complexity144.00
Code structure
Namespaces0
Interfaces0
Traits0
Classes21
▷ Abstract classes00.00%
▷ Concrete classes21100.00%
▷ Final classes00.00%
Methods137
▷ Static methods2921.17%
▷ Public methods11886.13%
▷ Protected methods00.00%
▷ Private methods1913.87%
Functions36
▷ Named functions36100.00%
▷ Anonymous functions00.00%
Constants49
▷ Global constants48.16%
▷ Class constants4591.84%
▷ Public constants45100.00%

Plugin size 0% from 2 tests

Image compression 0% from 2 tests

It is recommended to compress PNG files in your plugin to minimize bandwidth usage
29 PNG files occupy 0.57MB with 0.31MB in potential savings
Potential savings
Compression of 5 random PNG files using pngquant
FileSize - originalSize - compressedSavings
includes/images/authmethods/SecurityQuestions.png17.75KB7.58KB▼ 57.32%
includes/images/authmethods/EmailVerification.png11.27KB4.95KB▼ 56.09%
includes/images/support3.png2.49KB2.11KB▼ 15.28%
(invalid) includes/images/bank-transfer.png42.97KB0.00KB▼ 100.00%
includes/images/miniOrange2.png3.94KB2.26KB▼ 42.53%