72% miniorange-penetration-testing-tool

Code Review | miniOrange Penetration Testing Tool

WordPress plugin miniOrange Penetration Testing Tool scored 72% from 54 tests.

About plugin

  • Plugin page: miniorange-penetr...
  • Plugin version: 1.0.4
  • PHP compatiblity: 5.3.0+
  • PHP version: 7.4.16
  • WordPress compatibility: 4.6-5.5.1
  • WordPress version: 5.9.2
  • First release: Aug 11, 2020
  • Latest release: Oct 7, 2020
  • Number of updates: 19
  • Update frequency: every 3.0 days
  • Top authors: cyberlord92 (100%)

Code review

54 tests

User reviews

1 review

Install metrics

30+ active / 572 total downloads

Benchmarks

Plugin footprint 82% from 16 tests

Installer Passed 1 test

🔺 Critical test (weight: 50) | The install procedure must perform silently
The plugin installed gracefully, with no errors

Server metrics [RAM: ▲0.08MB] [CPU: ▼293.54ms] 75% from 4 tests

This is a short check of server-side resources used by miniOrange Penetration Testing Tool
The following require your attention
  • CPU: You should keep total CPU usage under 500.00ms (currently 1,652.24ms on /wp-admin/admin.php?page=moSPT_site_statistics)
PageMemory (MB)CPU Time (ms)
Home /3.68 ▲0.1655.27 ▲4.59
Dashboard /wp-admin3.52 ▲0.1133.99 ▼1.54
Posts /wp-admin/edit.php3.74 ▲0.1039.87 ▲2.81
Add New Post /wp-admin/post-new.php6.98 ▲0.0191.35 ▼1,175.50
Media Library /wp-admin/upload.php3.39 ▲0.1023.45 ▲0.07
Summary /wp-admin/admin.php?page=moSPT_site_statistics3.421,652.24
Account /wp-admin/admin.php?page=moSPT_site_account3.4932.59
Scan /wp-admin/admin.php?page=moSPT_site_PenTest3.3928.87

Server storage [IO: ▲0.73MB] [DB: ▲0.00MB] Passed 3 tests

A short overview of filesystem and database impact
This plugin was installed successfully
Filesystem: 42 new files
Database: no new tables, 3 new options
New WordPress options
mo_wpns_new_registration
mo_2factor_user_registration_status
MoSPT_dbversion

Browser metrics Passed 4 tests

An overview of browser requirements for miniOrange Penetration Testing Tool
This plugin has a minimal impact on browser resources
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /3,801 ▲5715.93 ▲0.255.87 ▼0.022.08 ▼0.40
Dashboard /wp-admin2,931 ▲706.13 ▲0.02116.21 ▼19.79171.61 ▲3.94
Posts /wp-admin/edit.php2,725 ▲343.24 ▲0.0062.81 ▼0.84145.50 ▲4.14
Add New Post /wp-admin/post-new.php1,693 ▲3218.16 ▲1.94376.08 ▼45.68195.83 ▲46.70
Media Library /wp-admin/upload.php1,741 ▲435.71 ▲0.25121.53 ▼12.84204.84 ▲13.46
Summary /wp-admin/admin.php?page=moSPT_site_statistics1,4163.1465.15211.98
Account /wp-admin/admin.php?page=moSPT_site_account1,2732.7665.64175.56
Scan /wp-admin/admin.php?page=moSPT_site_PenTest1,3102.9866.09233.72

Uninstaller [IO: ▲0.00MB] [DB: ▲0.00MB] 75% from 4 tests

🔸 Tests weight: 35 | The uninstall procedure must remove all plugin files and extra database tables
Please fix the following items
  • Zombie WordPress options detected upon uninstall: 2 options
    • mo_wpns_new_registration
    • mo_2factor_user_registration_status

Smoke tests 25% from 4 tests

Server-side errors Passed 1 test

🔹 Test weight: 20 | Just a short smoke test targeting errors on the server (in the Apache logs)
Even though everything seems fine, this is not an exhaustive test

SRP 0% from 2 tests

🔹 Tests weight: 20 | The single-responsibility principle applies for WordPress plugins as well - please make sure your PHP files perform no actions when accessed directly
Please fix the following
  • 1× PHP files perform the task of outputting text when accessed with GET requests:
    • > /wp-content/plugins/miniorange-penetration-testing-tool/views/SitePenTest_statistics.php
  • 29× PHP files trigger server errors when accessed directly (only 10 are shown):
    • > PHP Fatal error
      Uncaught Error: Call to undefined function add_action() in wp-content/plugins/miniorange-penetration-testing-tool/controllers/PenTest/ajax.php:7
    • > PHP Fatal error
      Uncaught Error: Call to undefined function sanitize_text_field() in wp-content/plugins/miniorange-penetration-testing-tool/views/navbar.php:11
    • > PHP Fatal error
      Uncaught Error: Call to undefined function site_url() in wp-content/plugins/miniorange-penetration-testing-tool/views/SitePenTest_statistics.php:100
    • > PHP Fatal error
      Uncaught Error: Call to undefined function get_site_option() in wp-content/plugins/miniorange-penetration-testing-tool/controllers/PenTest/registeration.php:2
    • > PHP Fatal error
      Uncaught Error: Class 'MoSPT_ajax' not found in wp-content/plugins/miniorange-penetration-testing-tool/controllers/PenTest/statistics.php:2
    • > PHP Warning
      include(): Failed opening 'controllers/navbar.php' for inclusion (include_path='.:/usr/share/php') in wp-content/plugins/miniorange-penetration-testing-tool/controllers/main_controller.php on line 5
    • > PHP Notice
      Undefined variable: logo_url in wp-content/plugins/miniorange-penetration-testing-tool/views/navbar.php on line 4
    • > PHP Notice
      Undefined variable: midCount in wp-content/plugins/miniorange-penetration-testing-tool/views/SitePenTest_statistics.php on line 31
    • > PHP Fatal error
      Uncaught Error: Call to undefined function plugin_dir_url() in wp-content/plugins/miniorange-penetration-testing-tool/controllers/navbar.php:3
    • > PHP Fatal error
      Uncaught Error: Call to undefined function current_user_can() in wp-content/plugins/miniorange-penetration-testing-tool/controllers/PenTest/account.php:4

User-side errors 0% from 1 test

🔹 Test weight: 20 | A shallow check that no browser errors were triggered
Please fix the following user-side errors
    • > GET request to /wp-admin/admin.php?page=moSPT_site_statistics
    • > Javascript (severe) in unknown
    /wp-admin/admin.php?page=moSPT_site_statistics 264:43 Uncaught SyntaxError: Unexpected token ','

Optimizations

Plugin configuration 96% from 29 tests

readme.txt Passed 16 tests

It's important to format your readme.txt file correctly as it is parsed for the public listing of your plugin
5 plugin tags: security, pentest, vulnerabilities, penetration, analysis

miniorange-penetration-testing-tool/miniorange_mospt_settings.php 92% from 13 tests

"miniOrange Penetration Testing Tool" version 1.0.4's main PHP file describes plugin functionality and also serves as the entry point to any WordPress functionality
It is important to fix the following:
  • Main file name: The principal plugin file should be the same as the plugin slug ("miniorange-penetration-testing-tool.php" instead of "miniorange_mospt_settings.php")

Code Analysis Passed 3 tests

File types Passed 1 test

🔸 Test weight: 35 | There should be no dangerous file extensions present in any WordPress plugin
No dangerous file extensions were detected17,047 lines of code in 31 files:
LanguageFilesBlank linesComment linesLines of code
CSS42,3812115,410
PHP24232151,469
JavaScript3325168

PHP code Passed 2 tests

A short review of cyclomatic complexity and code structure
This plugin has no cyclomatic complexity issues
Cyclomatic complexity
Average complexity per logical line of code0.28
Average class complexity6.12
▷ Minimum class complexity1.00
▷ Maximum class complexity22.00
Average method complexity2.24
▷ Minimum method complexity1.00
▷ Maximum method complexity18.00
Code structure
Namespaces0
Interfaces0
Traits0
Classes8
▷ Abstract classes00.00%
▷ Concrete classes8100.00%
▷ Final classes00.00%
Methods33
▷ Static methods26.06%
▷ Public methods33100.00%
▷ Protected methods00.00%
▷ Private methods00.00%
Functions13
▷ Named functions13100.00%
▷ Anonymous functions00.00%
Constants20
▷ Global constants210.00%
▷ Class constants1890.00%
▷ Public constants18100.00%

Plugin size Passed 2 tests

Image compression Passed 2 tests

PNG files should be compressed to save space and minimize bandwidth usage
10 PNG files occupy 0.11MB with 0.05MB in potential savings
Potential savings
Compression of 5 random PNG files using pngquant
FileSize - originalSize - compressedSavings
includes/images/normal.png15.74KB7.91KB▼ 49.78%
includes/images/normal1.png15.74KB7.91KB▼ 49.78%
includes/images/sad.png18.16KB8.79KB▼ 51.62%
includes/images/angry.png20.40KB9.65KB▼ 52.68%
includes/images/miniorange_logo.png1.95KB1.16KB▼ 40.58%