10% picknwork-security

Code Review | Picknwork Security

WordPress plugin Picknwork Security scored10%from 54 tests.

About plugin

  • Plugin page: picknwork-security
  • Plugin version: 1.0.1
  • PHP version: 7.4.16
  • WordPress compatibility: 3.0.1-5.9
  • WordPress version: 6.3.1
  • First release: Oct 24, 2021
  • Latest release: Feb 11, 2022
  • Number of updates: 16
  • Update frequency: every 7.6 days
  • Top authors: picknwork (100%)

Code review

54 tests

User reviews

1 review

Install metrics

10+ active /353 total downloads

Benchmarks

Plugin footprint 58% from 16 tests

Installer 0% from 1 test

🔺 Critical test (weight: 50) | All plugins must install correctly, without throwing any errors, warnings, or notices
It is recommended to fix the following installer errors
  • This plugin did not install gracefully
    • > Error in wp-content/plugins/picknwork-security/includes/function.php+583
    Uncaught Error: Cannot use object of type WP_Error as array in wp-content/plugins/picknwork-security/includes/function.php:583
    Stack trace:
    #0 wp-content/plugins/picknwork-security/includes/function.php(649): pnw_push()
    #1 wp-content/plugins/picknwork-security/includes/function.php(655): pnw_get_all_setting()
    #2 wp-content/plugins/picknwork-security/picknworksecurity.php(96): include('/var/www/wordpr...')
    #3 wp-admin/includes/plugin.php(2318): include_once('/var/www/wordpr...')
    #4 wp-admin/includes/plugin.php(663): plugin_sandbox_scrape()

Server metrics [RAM: ▼0.01MB] [CPU: ▼7.46ms] Passed 4 tests

An overview of server-side resources used by Picknwork Security
This plugin does not affect your website's performance
PageMemory (MB)CPU Time (ms)
Home /3.46 ▲0.0038.75 ▼0.57
Dashboard /wp-admin3.31 ▼0.0443.37 ▼19.01
Posts /wp-admin/edit.php3.36 ▲0.0044.58 ▲0.23
Add New Post /wp-admin/post-new.php5.89 ▲0.0080.28 ▼10.49
Media Library /wp-admin/upload.php3.23 ▲0.0044.86 ▲8.16

Server storage [IO: ▲0.37MB] [DB: ▲0.00MB] Passed 3 tests

Filesystem and database footprint
This plugin was installed successfully
Filesystem: 30 new files
Database: no new tables, 6 new options
New WordPress options
can_compress_scripts
theysaidso_admin_options
widget_recent-comments
widget_theysaidso_widget
db_upgraded
widget_recent-posts

Browser metrics Passed 4 tests

This is an overview of browser requirements for Picknwork Security
This plugin renders optimally with no browser resource issues detected
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /2,825 ▲7913.16 ▼1.272.08 ▲0.4743.93 ▲4.82
Dashboard /wp-admin2,206 ▲215.90 ▲0.02101.03 ▼18.2841.23 ▼0.98
Posts /wp-admin/edit.php2,086 ▼32.02 ▼0.0436.53 ▲0.1034.69 ▲2.22
Add New Post /wp-admin/post-new.php1,534 ▲123.03 ▼0.10638.56 ▼32.5061.47 ▲7.46
Media Library /wp-admin/upload.php1,388 ▲34.23 ▲0.0492.71 ▼24.6741.95 ▼5.13

Uninstaller [IO: ▲0.00MB] [DB: ▲0.00MB] 75% from 4 tests

🔸 Tests weight: 35 | Checking the uninstaller removed all traces of the plugin
The following items require your attention
  • Zombie WordPress options detected upon uninstall: 6 options
    • theysaidso_admin_options
    • can_compress_scripts
    • widget_recent-comments
    • widget_theysaidso_widget
    • widget_recent-posts
    • db_upgraded

Smoke tests 50% from 4 tests

Server-side errors Passed 1 test

🔹 Test weight: 20 | This is a short smoke test looking for server-side errors
Even though everything seems fine, this is not an exhaustive test

SRP 0% from 2 tests

🔹 Tests weight: 20 | It is important to ensure that your PHP files perform no action when accessed directly, respecting the single-responsibility principle
Almost there! Just fix the following items
  • 1× PHP files output non-empty strings when accessed directly via GET requests:
    • > /wp-content/plugins/picknwork-security/picknworksecurity.php
  • 15× GET requests to PHP files have triggered server-side errors or warnings (only 10 are shown):
    • > PHP Fatal error
      Uncaught Error: Call to undefined function add_shortcode() in wp-content/plugins/picknwork-security/includes/forms.php:5
    • > PHP Warning
      Use of undefined constant ABSPATH - assumed 'ABSPATH' (this will throw an Error in a future version of PHP) in wp-content/plugins/picknwork-security/includes/function.php on line 4
    • > PHP Fatal error
      Uncaught Error: Call to undefined function esc_html_e() in wp-content/plugins/picknwork-security/templates/admin-activation.php:41
    • > PHP Fatal error
      Uncaught Error: Call to undefined function pnw_get_all_emails() in wp-content/plugins/picknwork-security/templates/admin-message-users-email.php:7
    • > PHP Fatal error
      Uncaught Error: Call to undefined function pnw_get_all_blocked() in wp-content/plugins/picknwork-security/templates/admin-blocked.php:23
    • > PHP Fatal error
      Uncaught Error: Call to undefined function pnw_get_all_emails() in wp-content/plugins/picknwork-security/templates/admin-email-list.php:22
    • > PHP Fatal error
      Uncaught Error: Call to undefined function pnw_get_keys() in wp-content/plugins/picknwork-security/templates/admin-authentication.php:23
    • > PHP Fatal error
      require_once(): Failed opening required 'ABSPATHwp-includes/pluggable.php' (include_path='.:/usr/share/php') in wp-content/plugins/picknwork-security/includes/function.php on line 4
    • > PHP Fatal error
      Uncaught Error: Call to undefined function esc_html_e() in wp-content/plugins/picknwork-security/templates/admin-add-blocked.php:34
    • > PHP Fatal error
      Uncaught Error: Call to undefined function pnw_remove_query() in wp-content/plugins/picknwork-security/includes/reset-password.php:7

User-side errors Passed 1 test

🔹 Test weight: 20 | Just a short smoke test targeting errors on the browser (console and network errors and warnings)
Everything seems fine, but this is not an exhaustive test

Optimizations

Plugin configuration 96% from 29 tests

readme.txt Passed 16 tests

Don't ignore readme.txt as it is the file that instructs WordPress.org on how to present your plugin to the world
8 plugin tags: login, athentication, picknworksecurity, otp, register...

picknwork-security/picknworksecurity.php 92% from 13 tests

"Picknwork Security" version 1.0.1's main PHP file describes plugin functionality and also serves as the entry point to any WordPress functionality
Please make the necessary changes and fix the following:
  • Main file name: It is recommended to name the main PHP file as the plugin slug ("picknwork-security.php" instead of "picknworksecurity.php")

Code Analysis Passed 3 tests

File types Passed 1 test

🔸 Test weight: 35 | This is a short overview of programming languages used in this plugin, detecting executable files
Good job! No executable or dangerous file extensions detected3,364 lines of code in 23 files:
LanguageFilesBlank linesComment linesLines of code
PHP169655192,322
CSS428342793
JavaScript310045249

PHP code Passed 2 tests

A short review of cyclomatic complexity and code structure
There were no cyclomatic complexity issued detected
Cyclomatic complexity
Average complexity per logical line of code0.54
Average class complexity0.00
▷ Minimum class complexity0.00
▷ Maximum class complexity0.00
Average method complexity0.00
▷ Minimum method complexity0.00
▷ Maximum method complexity0.00
Code structure
Namespaces0
Interfaces0
Traits0
Classes0
▷ Abstract classes00.00%
▷ Concrete classes00.00%
▷ Final classes00.00%
Methods0
▷ Static methods00.00%
▷ Public methods00.00%
▷ Protected methods00.00%
▷ Private methods00.00%
Functions47
▷ Named functions47100.00%
▷ Anonymous functions00.00%
Constants4
▷ Global constants4100.00%
▷ Class constants00.00%
▷ Public constants00.00%

Plugin size Passed 2 tests

Image compression Passed 2 tests

Often times overlooked, PNG files can occupy unnecessary space in your plugin
No PNG files were detected