72% really-simple-ssl

Code Review | Really Simple SSL

WordPress plugin Really Simple SSL scored72%from 54 tests.

About plugin

  • Plugin page: really-simple-ssl
  • Plugin version: 7.2.0
  • PHP compatiblity: 7.2+
  • PHP version: 7.4.16
  • WordPress compatibility: 5.8-6.4
  • WordPress version: 6.3.1
  • First release: Mar 15, 2015
  • Latest release: Nov 15, 2023
  • Number of updates: 351
  • Update frequency: every 9.0 days
  • Top authors: RogierLankhorst (99.15%)

Code review

54 tests

User reviews

8408 reviews

Install metrics

5,000,000+ active /137,224,137 total downloads

Benchmarks

Plugin footprint 82% from 16 tests

Installer Passed 1 test

🔺 Critical test (weight: 50) | All plugins must install correctly, without throwing any errors, warnings, or notices
This plugin's installer ran successfully

Server metrics [RAM: ▲0.11MB] [CPU: ▼0.42ms] Passed 4 tests

Analyzing server-side resources used by Really Simple SSL
Normal server usage
PageMemory (MB)CPU Time (ms)
Home /3.52 ▲0.0636.06 ▼6.55
Dashboard /wp-admin3.48 ▲0.1358.06 ▼1.31
Posts /wp-admin/edit.php3.53 ▲0.1756.21 ▲7.56
Add New Post /wp-admin/post-new.php6.01 ▲0.1295.98 ▼1.40
Media Library /wp-admin/upload.php3.34 ▲0.1144.47 ▲9.97
SSL & Security3 /wp-admin/options-general.php?page=really-simple-security3.3460.03

Server storage [IO: ▲6.47MB] [DB: ▲0.01MB] 67% from 3 tests

Analyzing filesystem and database footprints of this plugin
It is recommended to fix the following issues
  • You have illegally modified 3 files (4.40KB) outside of "wp-content/plugins/really-simple-ssl/" and "wp-content/uploads/"
    • (new file) "wp-content/plugins/really-simple-ssl/settings/src/utils/Flag/Flags/CwCurac\314\247ao.js"
    • (new file) "wp-content/plugins/really-simple-ssl/settings/src/utils/Flag/Flags/CwCura\303\247ao.js"
    • (modified) wp-config.php
Filesystem: 749 new files
Database: no new tables, 10 new options
New WordPress options
theysaidso_admin_options
rsssl_plusone_count
widget_recent-comments
rsssl_show_onboarding
rsssl_admin_notices
widget_theysaidso_widget
rsssl_options
db_upgraded
can_compress_scripts
widget_recent-posts

Browser metrics Passed 4 tests

Checking browser requirements for Really Simple SSL
This plugin has a minimal impact on browser resources
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /2,824 ▲6214.05 ▼0.661.53 ▼0.1340.90 ▼4.94
Dashboard /wp-admin2,232 ▲585.59 ▼0.0692.76 ▼8.6742.73 ▼1.66
Posts /wp-admin/edit.php2,135 ▲352.01 ▲0.0639.92 ▼0.8339.59 ▲5.93
Add New Post /wp-admin/post-new.php1,538 ▲1223.29 ▼0.42619.25 ▼16.8552.07 ▲0.32
Media Library /wp-admin/upload.php1,431 ▲374.26 ▲0.0499.44 ▼2.3243.06 ▲1.94
SSL & Security3 /wp-admin/options-general.php?page=really-simple-security1,9478.31261.7090.84

Uninstaller [IO: ▲0.00MB] [DB: ▲0.01MB] 75% from 4 tests

🔸 Tests weight: 35 | The uninstall procedure must remove all plugin files and extra database tables
You still need to fix the following
  • The uninstall procedure has failed, leaving 8 options in the database
    • db_upgraded
    • rsssl_show_onboarding
    • widget_recent-posts
    • theysaidso_admin_options
    • widget_theysaidso_widget
    • rsssl_options
    • can_compress_scripts
    • widget_recent-comments

Smoke tests 25% from 4 tests

Server-side errors 0% from 1 test

🔹 Test weight: 20 | This is a short smoke test looking for server-side errors
Please fix the following server-side errors
    • > GET request to /wp-admin/options-general.php?page=really-simple-security
    • > Warning in wp-content/plugins/really-simple-ssl/lets-encrypt/functions.php+222
    fsockopen(): unable to connect to 127.0.0.1:8443 (Connection refused)
    • > GET request to /wp-admin/options-general.php?page=really-simple-security
    • > Warning in wp-content/plugins/really-simple-ssl/lets-encrypt/functions.php+222
    fsockopen(): unable to connect to 127.0.0.1:2222 (Connection refused)

SRP 0% from 2 tests

🔹 Tests weight: 20 | A shallow check of the single-responsibility principle; PHP files should perform no action - including output of placeholder text - and trigger no errors when accessed directly
Please take a closer look at the following
  • 9× PHP files perform the task of outputting text when accessed with GET requests:
    • > /wp-content/plugins/really-simple-ssl/class-server.php
    • > /wp-content/plugins/really-simple-ssl/class-mixed-content-fixer.php
    • > /wp-content/plugins/really-simple-ssl/rlrsssl-really-simple-ssl.php
    • > /wp-content/plugins/really-simple-ssl/security/tests/code-execution.php
    • > /wp-content/plugins/really-simple-ssl/security/wordpress/disable-xmlrpc.php
    • > /wp-content/plugins/really-simple-ssl/ssl-test-page.php
    • > /wp-content/plugins/really-simple-ssl/class-front-end.php
    • > /wp-content/plugins/really-simple-ssl/lets-encrypt/class-letsencrypt-handler.php
    • > /wp-content/plugins/really-simple-ssl/class-cache.php
  • 6× PHP files trigger errors when accessed directly with GET requests:
    • > PHP Fatal error
      Uncaught Error: Call to undefined function add_filter() in wp-content/plugins/really-simple-ssl/lets-encrypt/config/notices.php:154
    • > PHP Fatal error
      require_once(): Failed opening required 'rsssl_le_pathvendor/autoload.php' (include_path='.:/usr/share/php') in wp-content/plugins/really-simple-ssl/lets-encrypt/integrations/plesk/plesk.php on line 28
    • > PHP Warning
      require_once(rsssl_le_pathvendor/autoload.php): failed to open stream: No such file or directory in wp-content/plugins/really-simple-ssl/lets-encrypt/integrations/plesk/plesk.php on line 28
    • > PHP Fatal error
      Uncaught Error: Class 'PleskX\\Api\\Struct' not found in wp-content/plugins/really-simple-ssl/lets-encrypt/vendor/plesk/api-php-lib/src/Api/Struct/SecretKey/Info.php:6
    • > PHP Fatal error
      Uncaught Error: Call to undefined function add_filter() in wp-content/plugins/really-simple-ssl/lets-encrypt/config/fields.php:39
    • > PHP Warning
      Use of undefined constant rsssl_le_path - assumed 'rsssl_le_path' (this will throw an Error in a future version of PHP) in wp-content/plugins/really-simple-ssl/lets-encrypt/integrations/plesk/plesk.php on line 28

User-side errors Passed 1 test

🔹 Test weight: 20 | This is a smoke test targeting browser errors/issues
No browser errors were detected

Optimizations

Plugin configuration 96% from 29 tests

readme.txt Passed 16 tests

Don't ignore readme.txt as it is the file that instructs WordPress.org on how to present your plugin to the world
10 plugin tags: hsts, website security, secure socket layers, secure website, force ssl...

really-simple-ssl/rlrsssl-really-simple-ssl.php 92% from 13 tests

The main PHP file in "Really Simple SSL" ver. 7.2.0 adds more information about the plugin and also serves as the entry point for this plugin
Please make the necessary changes and fix the following:
  • Main file name: It is recommended to name the main PHP file as the plugin slug ("really-simple-ssl.php" instead of "rlrsssl-really-simple-ssl.php")

Code Analysis Passed 3 tests

File types Passed 1 test

🔸 Test weight: 35 | This is an overview of file extensions present in this plugin and a short test that no dangerous files are bundled with this plugin
Everything looks great! No dangerous files found in this plugin58,632 lines of code in 690 files:
LanguageFilesBlank linesComment linesLines of code
JavaScript4011,17370529,591
PHP1973,7514,80920,733
CSS11708723,682
Sass564463103,645
HTML410759384
JSON500211
LESS1300152
Markdown4700142
XML22147
YAML43031
Bourne Shell1116
Dockerfile1105
SVG3003

PHP code Passed 2 tests

A short review of cyclomatic complexity and code structure
Everything seems fine, there were no complexity issues found
Cyclomatic complexity
Average complexity per logical line of code0.46
Average class complexity13.76
▷ Minimum class complexity1.00
▷ Maximum class complexity432.00
Average method complexity3.27
▷ Minimum method complexity1.00
▷ Maximum method complexity46.00
Code structure
Namespaces34
Interfaces0
Traits1
Classes146
▷ Abstract classes138.90%
▷ Concrete classes13391.10%
▷ Final classes00.00%
Methods818
▷ Static methods688.31%
▷ Public methods70285.82%
▷ Protected methods455.50%
▷ Private methods718.68%
Functions215
▷ Named functions18987.91%
▷ Anonymous functions2612.09%
Constants51
▷ Global constants2141.18%
▷ Class constants3058.82%
▷ Public constants2583.33%

Plugin size Passed 2 tests

Image compression Passed 2 tests

Often times overlooked, PNG files can occupy unnecessary space in your plugin
4 PNG files occupy 0.04MB with 0.02MB in potential savings
Potential savings
Compression of 4 random PNG files using pngquant
FileSize - originalSize - compressedSavings
assets/img/icon.png19.04KB9.61KB▼ 49.54%
upgrade/img/really-simple-ssl.png11.96KB6.41KB▼ 46.40%
upgrade/img/complianz-gdpr.png4.47KB1.85KB▼ 58.71%
upgrade/img/burst.png5.13KB2.20KB▼ 57.17%