68% miniorange-malware-protection

Code Review | Malware Scanner

WordPress plugin Malware Scanner scored68%from 54 tests.

About plugin

Code review

54 tests

User reviews

4 reviews

Install metrics

10,000+ active /18,610 total downloads

Benchmarks

Plugin footprint 65% from 16 tests

Installer Passed 1 test

🔺 Critical test (weight: 50) | Checking the installer triggered no errors
Installer ran successfully

Server metrics [RAM: ▲1.30MB] [CPU: ▲3.94ms] Passed 4 tests

Server-side resources used by Malware Scanner
This plugin has minimal impact on server resources
PageMemory (MB)CPU Time (ms)
Home /4.89 ▲1.4354.55 ▲12.59
Dashboard /wp-admin4.64 ▲1.3061.33 ▼2.35
Posts /wp-admin/edit.php4.69 ▲1.3461.00 ▲17.83
Add New Post /wp-admin/post-new.php7.18 ▲1.2992.74 ▼12.32
Media Library /wp-admin/upload.php4.50 ▲1.2752.33 ▲21.99
Dashboard /wp-admin/admin.php?page=mo_mmp_dashboard4.5475.61
Advanced Blocking /wp-admin/admin.php?page=mo_mmp_advancedblocking4.5956.41
Malware Scan /wp-admin/admin.php?page=mo_mmp_malwarescan4.6851.19
Backup /wp-admin/admin.php?page=mo_mmp_backup4.5755.96
Reports /wp-admin/admin.php?page=mo_mmp_reports4.5651.29
Login and Spam /wp-admin/admin.php?page=mo_mmp_login_and_spam4.6355.55
Notifications /wp-admin/admin.php?page=mo_mmp_notifications4.6157.92
Troubleshooting /wp-admin/admin.php?page=mo_mmp_troubleshooting4.5448.95
WAF /wp-admin/admin.php?page=mo_mmp_waf4.6955.66
Account /wp-admin/admin.php?page=mo_mmp_account4.6252.83

Server storage [IO: ▲1.15MB] [DB: ▲0.01MB] Passed 3 tests

Analyzing filesystem and database footprints of this plugin
There were no storage issued detected upon installing this plugin
Filesystem: 116 new files
Database: 11 new tables, 33 new options
New tables
wp_wpns_malware_scan_report_details
wp_wpns_blocked_ips
wp_wpns_transactions
wp_wpns_attack_logs
wp_wpns_email_sent_audit
wp_wpns_files_scan
wp_wpns_malware_hash_file
wp_wpns_whitelisted_ips
wp_wpns_ip_rate_details
wp_wpns_malware_scan_report
...
New WordPress options
LFIAttack
mo_mmp_switch_adv_block
mo_wpns_enable_brute_force
mo_mmp_switch_notif
XSSAttack
mo_mmp_check_sql_injection
RCEAttack
mo_mmp_scan_themes
mo_mmp_check_vulnerable_code
mo_wpns_show_remaining_attempts
...

Browser metrics Passed 4 tests

An overview of browser requirements for Malware Scanner
Minimal impact on browser resources
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /2,982 ▲22114.61 ▲0.241.68 ▲0.0339.60 ▼7.08
Dashboard /wp-admin2,373 ▲1935.64 ▼0.2185.40 ▼13.1279.92 ▲38.58
Posts /wp-admin/edit.php2,192 ▲892.11 ▲0.1238.33 ▲2.7536.37 ▲6.93
Add New Post /wp-admin/post-new.php1,595 ▲6122.92 ▲4.77663.70 ▲47.44148.12 ▲83.97
Media Library /wp-admin/upload.php1,489 ▲864.24 ▲0.04100.27 ▲4.8567.24 ▲27.89
Dashboard /wp-admin/admin.php?page=mo_mmp_dashboard1,1852.2629.9339.18
Advanced Blocking /wp-admin/admin.php?page=mo_mmp_advancedblocking2,1812.3731.2742.25
Malware Scan /wp-admin/admin.php?page=mo_mmp_malwarescan1,8002.4545.8732.65
Backup /wp-admin/admin.php?page=mo_mmp_backup1,1792.2929.1930.02
Reports /wp-admin/admin.php?page=mo_mmp_reports1,5012.5746.4033.54
Login and Spam /wp-admin/admin.php?page=mo_mmp_login_and_spam1,5272.2932.0434.97
Notifications /wp-admin/admin.php?page=mo_mmp_notifications2,0608.70165.1680.32
Troubleshooting /wp-admin/admin.php?page=mo_mmp_troubleshooting1,1952.2628.2428.39
WAF /wp-admin/admin.php?page=mo_mmp_waf2,2162.5251.0150.52
Account /wp-admin/admin.php?page=mo_mmp_account1,1772.2829.1233.90

Uninstaller [IO: ▲0.00MB] [DB: ▲0.00MB] 50% from 4 tests

🔸 Tests weight: 35 | Checking the uninstaller removed all traces of the plugin
You still need to fix the following
  • The plugin did not uninstall successfully, leaving 1 table in the database
    • wp_wpns_ip_rate_details
  • Zombie WordPress options detected upon uninstall: 17 options
    • RFIAttack
    • widget_recent-comments
    • XSSAttack
    • RCEAttack
    • WAFEnabled
    • widget_recent-posts
    • limitAttack
    • actionRateL
    • LFIAttack
    • theysaidso_admin_options
    • ...

Smoke tests 50% from 4 tests

Server-side errors Passed 1 test

🔹 Test weight: 20 | Just a short smoke test targeting errors on the server (in the Apache logs)
Good news, no errors were detected

SRP 0% from 2 tests

🔹 Tests weight: 20 | The single-responsibility principle applies for WordPress plugins as well - please make sure your PHP files perform no actions when accessed directly
Please fix the following items
  • 5× PHP files perform the action of outputting non-empty strings when accessed directly:
    • > /wp-content/plugins/miniorange-malware-protection/views/troubleshooting.php
    • > /wp-content/plugins/miniorange-malware-protection/handler/mo-block.php
    • > /wp-content/plugins/miniorange-malware-protection/controllers/malware_scanner/scan_malware.php
    • > /wp-content/plugins/miniorange-malware-protection/handler/mo-error.php
    • > /wp-content/plugins/miniorange-malware-protection/views/login_spam.php
  • 126× PHP files trigger server-side errors or warnings when accessed directly (only 10 are shown):
    • > PHP Fatal error
      Uncaught Error: Call to undefined function plugins_url() in wp-content/plugins/miniorange-malware-protection/controllers/change-password.php:7
    • > PHP Warning
      include(): Failed opening 'views/link_tracers.php' for inclusion (include_path='.:/usr/share/php') in wp-content/plugins/miniorange-malware-protection/views/advanced-blocking.php on line 4
    • > PHP Warning
      include_once(): Failed opening 'views/malware_scanner/scan_summary_view.php' for inclusion (include_path='.:/usr/share/php') in wp-content/plugins/miniorange-malware-protection/controllers/malware_scanner/scan_malware_summary.php on line 3
    • > PHP Fatal error
      Uncaught Error: Call to undefined function add_action() in wp-content/plugins/miniorange-malware-protection/handler/ajax.php:7
    • > PHP Notice
      Trying to access array offset on value of type null in wp-content/plugins/miniorange-malware-protection/views/advanced-blocking.php on line 12
    • > PHP Fatal error
      Uncaught Error: Call to undefined function esc_attr() in wp-content/plugins/miniorange-malware-protection/views/account/login.php:14
    • > PHP Warning
      Use of undefined constant ABSPATH - assumed 'ABSPATH' (this will throw an Error in a future version of PHP) in wp-content/plugins/miniorange-malware-protection/database/database_functions.php on line 3
    • > PHP Fatal error
      Uncaught Error: Call to undefined function add_query_arg() in wp-content/plugins/miniorange-malware-protection/controllers/login-security.php:5
    • > PHP Warning
      include_once(views/malware_scanner/scan_summary_view.php): failed to open stream: No such file or directory in wp-content/plugins/miniorange-malware-protection/controllers/malware_scanner/scan_malware_summary.php on line 3
    • > PHP Fatal error
      Uncaught Error: Call to undefined function esc_attr() in wp-content/plugins/miniorange-malware-protection/views/registration-security.php:13

User-side errors Passed 1 test

🔹 Test weight: 20 | A shallow check that no browser errors were triggered
Everything seems fine on the user side

Optimizations

Plugin configuration 96% from 29 tests

readme.txt Passed 16 tests

Don't ignore readme.txt as it is the file that instructs WordPress.org on how to present your plugin to the world
No tags were found

miniorange-malware-protection/mo_malware_protection_widget.php 92% from 13 tests

This is the main PHP file of "Malware Scanner" version 4.7, providing information about the plugin in the header fields and serving as the principal entry point to the plugin's functions
You should first fix the following items:
  • Main file name: Name the main plugin file the same as the plugin slug ("miniorange-malware-protection.php" instead of "mo_malware_protection_widget.php")

Code Analysis Passed 3 tests

File types Passed 1 test

🔸 Test weight: 35 | This is an overview of programming languages used in this plugin; dangerous file extensions are not allowed
There were no executable files found in this plugin16,482 lines of code in 101 files:
LanguageFilesBlank linesComment linesLines of code
PHP891,94313313,334
CSS7224582,905
JavaScript52316243

PHP code Passed 2 tests

Analyzing logical lines of code, cyclomatic complexity, and other code metrics
All good! No complexity issues found
Cyclomatic complexity
Average complexity per logical line of code0.31
Average class complexity35.96
▷ Minimum class complexity1.00
▷ Maximum class complexity257.00
Average method complexity4.12
▷ Minimum method complexity1.00
▷ Maximum method complexity45.00
Code structure
Namespaces0
Interfaces0
Traits0
Classes26
▷ Abstract classes00.00%
▷ Concrete classes26100.00%
▷ Final classes00.00%
Methods291
▷ Static methods165.50%
▷ Public methods27092.78%
▷ Protected methods00.00%
▷ Private methods217.22%
Functions81
▷ Named functions81100.00%
▷ Anonymous functions00.00%
Constants127
▷ Global constants21.57%
▷ Class constants12598.43%
▷ Public constants125100.00%

Plugin size Passed 2 tests

Image compression Passed 2 tests

PNG files should be compressed to save space and minimize bandwidth usage
13 PNG files occupy 0.20MB with 0.11MB in potential savings
Potential savings
Compression of 5 random PNG files using pngquant
FileSize - originalSize - compressedSavings
includes/images/success.png15.72KB1.48KB▼ 90.60%
includes/images/flags16.png61.80KB19.90KB▼ 67.79%
includes/images/miniorange_logo.png1.95KB1.16KB▼ 40.58%
includes/images/support3.png2.49KB2.11KB▼ 15.28%
includes/images/smile.png17.89KB8.79KB▼ 50.86%