10% rsfirewall

Code Review | RSFirewall!

WordPress plugin RSFirewall! scored10%from 54 tests.

About plugin

  • Plugin page: rsfirewall
  • Plugin version: 1.1.30
  • PHP compatiblity: 5.4+
  • PHP version: 7.4.16
  • WordPress compatibility: 4.5.15-6.2.2
  • WordPress version: 6.3.1
  • First release: Jul 9, 2019
  • Latest release: Oct 10, 2023
  • Number of updates: 36
  • Update frequency: every 43.2 days
  • Top authors: rsjoomla (100%)

Code review

54 tests

User reviews

4 reviews

Install metrics

3,000+ active /10,122 total downloads

Benchmarks

Plugin footprint 57% from 16 tests

Installer 0% from 1 test

🔺 Critical test (weight: 50) | All plugins must install correctly, without throwing any errors, warnings, or notices
The following installer errors require your attention
  • The plugin did not install without errors
    • > Notice in wp-content/plugins/rsfirewall/installer/installer.php+70
    Undefined variable: test

Server metrics [RAM: ▲1.99MB] [CPU: ▲25.11ms] 75% from 4 tests

Analyzing server-side resources used by RSFirewall!
Please fix the following
  • CPU: Try to keep total CPU usage under 500.00ms (currently 548.50ms on /wp-admin/admin.php?page=rsfirewall)
PageMemory (MB)CPU Time (ms)
Home /4.59 ▲1.1349.29 ▲11.34
Dashboard /wp-admin5.61 ▲2.3089.50 ▲36.13
Posts /wp-admin/edit.php5.65 ▲2.2986.72 ▲41.14
Add New Post /wp-admin/post-new.php8.13 ▲2.24117.58 ▲11.83
Media Library /wp-admin/upload.php5.54 ▲2.3181.06 ▲47.33
RSS Feeds /wp-admin/edit.php?post_type=rsf_feeds5.5976.19
Configuration /wp-admin/admin.php?page=rsfirewall_configuration5.4569.62
RSFirewall! /wp-admin/admin.php?page=rsfirewall5.69548.50
Exceptions /wp-admin/edit.php?post_type=rsf_exceptions5.5974.96
File Contents /wp-admin/admin.php?page=rsfirewall_file5.4568.49
Ignored Files /wp-admin/admin.php?page=rsfirewall_ignored5.4573.65
Blocklist / Safelist /wp-admin/edit.php?post_type=rsf_lists5.5973.57
Threats /wp-admin/edit.php?post_type=rsf_threats5.5971.25
System Check /wp-admin/admin.php?page=rsfirewall_check5.4873.86
File Differences /wp-admin/admin.php?page=rsfirewall_diff5.52329.52

Server storage [IO: ▲2.64MB] [DB: ▲0.11MB] Passed 3 tests

A short overview of filesystem and database impact
This plugin was installed successfully
Filesystem: 474 new files
Database: 4 new tables, 19 new options
New tables
wp_rsfirewall_ignored
wp_rsfirewall_hashes
wp_rsfirewall_offenders
wp_rsfirewall_signatures
New WordPress options
rsfirewall_two_factor_auth
rsfirewall_import
rsfirewall_updates
rsfirewall_country_blocking
db_upgraded
can_compress_scripts
rsfirewall_active_scanner
widget_recent-comments
widget_theysaidso_widget
rsfirewall_hardening
...

Browser metrics Passed 4 tests

This is an overview of browser requirements for RSFirewall!
Normal browser usage
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /2,993 ▲20714.40 ▼0.132.13 ▲0.3637.66 ▼5.59
Dashboard /wp-admin2,374 ▲2004.90 ▼0.7196.06 ▲11.2972.14 ▲30.91
Posts /wp-admin/edit.php2,193 ▲962.36 ▲0.3733.96 ▼1.2235.00 ▼2.25
Add New Post /wp-admin/post-new.php1,601 ▲7523.28 ▼0.49610.89 ▼72.0932.41 ▼17.84
Media Library /wp-admin/upload.php1,489 ▲894.35 ▲0.0398.11 ▼6.0079.16 ▲35.70
RSS Feeds /wp-admin/edit.php?post_type=rsf_feeds1,1972.3234.1031.41
Configuration /wp-admin/admin.php?page=rsfirewall_configuration1,7562.3848.1245.17
RSFirewall! /wp-admin/admin.php?page=rsfirewall1,2162.7481.2534.53
Exceptions /wp-admin/edit.php?post_type=rsf_exceptions1,2572.3132.8734.17
File Contents /wp-admin/admin.php?page=rsfirewall_file8481.8028.3523.79
Ignored Files /wp-admin/admin.php?page=rsfirewall_ignored8901.7627.3223.59
Blocklist / Safelist /wp-admin/edit.php?post_type=rsf_lists1,2302.2234.6331.73
Threats /wp-admin/edit.php?post_type=rsf_threats1,3972.3032.7028.93
System Check /wp-admin/admin.php?page=rsfirewall_check1,3591.9834.9424.78
File Differences /wp-admin/admin.php?page=rsfirewall_diff8661.8925.4824.77

Uninstaller [IO: ▲0.00MB] [DB: ▲0.07MB] 75% from 4 tests

🔸 Tests weight: 35 | It is important to correctly uninstall your plugin, without leaving any traces
The following items require your attention
  • This plugin does not fully uninstall, leaving 10 options in the database
    • widget_theysaidso_widget
    • widget_recent-comments
    • db_upgraded
    • rsfirewall_hardening
    • theysaidso_admin_options
    • widget_recent-posts
    • rsfirewall_two_factor_auth
    • can_compress_scripts
    • rsfirewall_lite_version
    • rsfirewall_country_blocking

Smoke tests 50% from 4 tests

Server-side errors Passed 1 test

🔹 Test weight: 20 | A smoke test targeting server-side errors
Even though everything seems fine, this is not an exhaustive test

SRP 0% from 2 tests

🔹 Tests weight: 20 | The single-responsibility principle applies for WordPress plugins as well - please make sure your PHP files perform no actions when accessed directly
Please fix the following items
  • 1× GET requests to PHP files return non-empty strings:
    • > /wp-content/plugins/rsfirewall/templates/rsmodal.php
  • 81× PHP files trigger server errors when accessed directly (only 10 are shown):
    • > PHP Fatal error
      Uncaught Error: Class 'Net_DNS2_RR' not found in wp-content/plugins/rsfirewall/libraries/Net/DNS2/RR/SOA.php:46
    • > PHP Fatal error
      Uncaught Error: Using $this when not in object context in wp-content/plugins/rsfirewall/views/ignored.php:2
    • > PHP Fatal error
      Uncaught Error: Class 'Net_DNS2_RR' not found in wp-content/plugins/rsfirewall/libraries/Net/DNS2/RR/HINFO.php:30
    • > PHP Fatal error
      Uncaught Error: Class 'Net_DNS2_RR' not found in wp-content/plugins/rsfirewall/libraries/Net/DNS2/RR/APL.php:33
    • > PHP Fatal error
      Uncaught Error: Class 'Net_DNS2_RR' not found in wp-content/plugins/rsfirewall/libraries/Net/DNS2/RR/ATMA.php:32
    • > PHP Fatal error
      Uncaught Error: Class 'Net_DNS2_RR' not found in wp-content/plugins/rsfirewall/libraries/Net/DNS2/RR/SRV.php:34
    • > PHP Fatal error
      Uncaught Error: Class 'Net_DNS2_RR' not found in wp-content/plugins/rsfirewall/libraries/Net/DNS2/RR/SSHFP.php:33
    • > PHP Fatal error
      Uncaught Error: Class 'Net_DNS2_RR' not found in wp-content/plugins/rsfirewall/libraries/Net/DNS2/RR/TKEY.php:46
    • > PHP Fatal error
      Uncaught Error: Class 'Net_DNS2_RR' not found in wp-content/plugins/rsfirewall/libraries/Net/DNS2/RR/PTR.php:28
    • > PHP Fatal error
      Uncaught Error: Class 'Net_DNS2_Cache' not found in wp-content/plugins/rsfirewall/libraries/Net/DNS2/Cache/File.php:24

User-side errors Passed 1 test

🔹 Test weight: 20 | This is a smoke test targeting browser errors/issues
Everything seems fine, but this is not an exhaustive test

Optimizations

Plugin configuration Passed 29 tests

readme.txt Passed 16 tests

The readme.txt file is an important file in your plugin as it is parsed by WordPress.org to prepare the public listing of your plugin
5 plugin tags: system check, firewall, web application firewall, security, malware scanner

rsfirewall/rsfirewall.php Passed 13 tests

The entry point to "RSFirewall!" version 1.1.30 is a PHP file that has certain tags in its header comment area
134 characters long description:
Based on the success of the most popular firewall for Joomla!, RSFirewall! is now available to protect your WordPress website as well.

Code Analysis Passed 3 tests

File types Passed 1 test

🔸 Test weight: 35 | Executable files are considered dangerous and should not be included with any WordPress plugin
No dangerous file extensions were detected25,675 lines of code in 210 files:
LanguageFilesBlank linesComment linesLines of code
PHP1525,00411,93516,943
CSS84382213,319
JavaScript163776012,052
PO File17067271,868
LESS15135137890
SQL230317
XML1561285
HTML1001

PHP code Passed 2 tests

Analyzing cyclomatic complexity and code structure
No complexity issues detected
Cyclomatic complexity
Average complexity per logical line of code0.38
Average class complexity18.48
▷ Minimum class complexity1.00
▷ Maximum class complexity200.00
Average method complexity3.78
▷ Minimum method complexity1.00
▷ Maximum method complexity43.00
Code structure
Namespaces0
Interfaces1
Traits0
Classes138
▷ Abstract classes21.45%
▷ Concrete classes13698.55%
▷ Final classes00.00%
Methods885
▷ Static methods11112.54%
▷ Public methods54261.24%
▷ Protected methods32536.72%
▷ Private methods182.03%
Functions7
▷ Named functions457.14%
▷ Anonymous functions342.86%
Constants179
▷ Global constants105.59%
▷ Class constants16994.41%
▷ Public constants169100.00%

Plugin size Passed 2 tests

Image compression Passed 2 tests

It is recommended to compress PNG files in your plugin to minimize bandwidth usage
252 compressed PNG files occupy 0.42MB
Potential savings
Compression of 5 random PNG files using pngquant
FileSize - originalSize - compressedSavings
assets/images/flags/np.png0.62KB0.52KB▼ 15.93%
assets/images/flags/in.png0.42KB0.35KB▼ 16.71%
assets/images/flags/sy.png0.41KB0.35KB▼ 14.93%
assets/images/flags/im.png0.53KB0.54KB0.00%
assets/images/flags/ph.png0.50KB0.52KB0.00%