90% prevent-xss-vulnerability

Code Review | Prevent XSS Vulnerability

WordPress plugin Prevent XSS Vulnerability scored 90% from 54 tests.

About plugin

  • Plugin page: prevent-xss-vulne...
  • Plugin version: 2.0.1
  • PHP version: 7.4.16
  • WordPress compatibility: 3.5-6.0
  • WordPress version: 6.3.1
  • First release: Aug 23, 2017
  • Latest release: Aug 19, 2022
  • Number of updates: 36
  • Update frequency: every 50.7 days
  • Top authors: sasiddiqui (100%)

Code review

54 tests

User reviews

6 reviews

Install metrics

7,000+ active / 46,069 total downloads

Benchmarks

Plugin footprint 83% from 16 tests

Installer Passed 1 test

🔺 Critical test (weight: 50) | Verifying that this plugin installs correctly without errors
Install script ran successfully

Server metrics [RAM: ▲0.02MB] [CPU: ▼0.08ms] Passed 4 tests

Server-side resources used by Prevent XSS Vulnerability
No issues were detected with server-side resource usage
PageMemory (MB)CPU Time (ms)
Home /3.47 ▲0.0144.51 ▼3.81
Dashboard /wp-admin3.33 ▲0.0258.08 ▲3.66
Posts /wp-admin/edit.php3.44 ▲0.0953.92 ▼0.17
Add New Post /wp-admin/post-new.php5.91 ▲0.0293.33 ▲1.63
Media Library /wp-admin/upload.php3.25 ▲0.0243.12 ▲2.04
Reflected XSS /wp-admin/admin.php?page=prevent-xss-vulnerability-reflected-settings3.3137.81
About /wp-admin/admin.php?page=prevent-xss-vulnerability-about3.3143.50
Self-XSS /wp-admin/admin.php?page=prevent-xss-vulnerability-self-settings3.2638.56

Server storage [IO: ▲1.01MB] [DB: ▲0.00MB] Passed 3 tests

Input-output and database impact of this plugin
This plugin installed successfully
Filesystem: 30 new files
Database: no new tables, 6 new options
New WordPress options
theysaidso_admin_options
db_upgraded
widget_recent-posts
widget_recent-comments
widget_theysaidso_widget
can_compress_scripts

Browser metrics Passed 4 tests

Prevent XSS Vulnerability: an overview of browser usage
Minimal impact on browser resources
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /2,831 ▲4213.21 ▲0.031.68 ▼0.1249.18 ▲3.09
Dashboard /wp-admin2,240 ▲344.85 ▼0.99105.84 ▼5.9244.41 ▲0.90
Posts /wp-admin/edit.php2,120 ▲342.05 ▲0.0137.87 ▲2.1432.68 ▼1.76
Add New Post /wp-admin/post-new.php1,437 ▼8317.86 ▼3.12644.90 ▼90.4850.86 ▼1.03
Media Library /wp-admin/upload.php1,422 ▲344.14 ▼0.05112.73 ▲0.2149.49 ▲1.82
Reflected XSS /wp-admin/admin.php?page=prevent-xss-vulnerability-reflected-settings1,1982.0629.0450.61
About /wp-admin/admin.php?page=prevent-xss-vulnerability-about2,1822.0431.7349.30
Self-XSS /wp-admin/admin.php?page=prevent-xss-vulnerability-self-settings8572.0526.3825.00

Uninstaller [IO: ✅] [DB: ▲0.00MB] 75% from 4 tests

🔸 Tests weight: 35 | It is important to correctly uninstall your plugin, without leaving any traces
Please fix the following items
  • Zombie WordPress options detected upon uninstall: 6 options
    • widget_recent-posts
    • theysaidso_admin_options
    • widget_recent-comments
    • widget_theysaidso_widget
    • can_compress_scripts
    • db_upgraded

Smoke tests Passed 4 tests

Server-side errors Passed 1 test

🔹 Test weight: 20 | A shallow check that no server-side errors were triggered
Everything seems fine, however this is by no means an exhaustive test

SRP Passed 2 tests

🔹 Tests weight: 20 | SRP (Single-Responsibility Principle) - PHP files must act as libraries and never output text or perform any action when accessed directly in a browser
Looking good! No server-side errors or output on direct access of PHP files

User-side errors Passed 1 test

🔹 Test weight: 20 | This is just a short smoke test looking for browser issues
Everything seems fine on the user side

Optimizations

Plugin configuration 97% from 29 tests

readme.txt 94% from 16 tests

The readme.txt file is undoubtedly the most important file in your plugin, preparing it for public listing on WordPress.org
Attributes that need to be fixed: The official readme.txt might help

prevent-xss-vulnerability/prevent-xss-vulnerability.php Passed 13 tests

This is the main PHP file of "Prevent XSS Vulnerability" version 2.0.1, providing information about the plugin in the header fields and serving as the principal entry point to the plugin's functions
37 characters long description:
Secure your site from the XSS Attack.

Code Analysis Passed 3 tests

File types Passed 1 test

🔸 Test weight: 35 | A short glimpse at programming languages used with this plugin and a check that no dangerous files are present
No dangerous file extensions were detected9,480 lines of code in 22 files:
LanguageFilesBlank linesComment linesLines of code
SVG9118,119
PHP91453631,258
PO File14548100
CSS2002
JavaScript1001

PHP code Passed 2 tests

Analyzing logical lines of code, cyclomatic complexity, and other code metrics
There are no cyclomatic complexity problems detected for this plugin
Cyclomatic complexity
Average complexity per logical line of code0.27
Average class complexity13.83
▷ Minimum class complexity1.00
▷ Maximum class complexity45.00
Average method complexity3.33
▷ Minimum method complexity1.00
▷ Maximum method complexity16.00
Code structure
Namespaces0
Interfaces0
Traits0
Classes6
▷ Abstract classes00.00%
▷ Concrete classes6100.00%
▷ Final classes116.67%
Methods33
▷ Static methods00.00%
▷ Public methods1854.55%
▷ Protected methods00.00%
▷ Private methods1545.45%
Functions0
▷ Named functions00.00%
▷ Anonymous functions00.00%
Constants6
▷ Global constants6100.00%
▷ Class constants00.00%
▷ Public constants00.00%

Plugin size Passed 2 tests

Image compression Passed 2 tests

Using a strong compression for your PNG files is a great way to speed-up your plugin
2 PNG files occupy 0.03MB with 0.01MB in potential savings
Potential savings
Compression of 2 random PNG files using pngquant
FileSize - originalSize - compressedSavings
assets/images/media-post-permalink.png24.03KB11.56KB▼ 51.92%
assets/images/prevent-xss-vulnerability.png7.36KB7.25KB▼ 1.51%