90% sar-one-click-security

Code Review | SAR One Click Security

WordPress plugin SAR One Click Security scored90%from 54 tests.

About plugin

  • Plugin page: sar-one-click-sec...
  • Plugin version: 1.3
  • PHP version: 7.4.16
  • WordPress compatibility: 3.9.2-5.4
  • WordPress version: 6.3.1
  • First release: Aug 14, 2014
  • Latest release: Apr 10, 2020
  • Number of updates: 36
  • Update frequency: every 57.4 days
  • Top authors: samuelaguilera (100%)

Code review

54 tests

User reviews

7 reviews

Install metrics

500+ active /8,753 total downloads

Benchmarks

Plugin footprint 82% from 16 tests

Installer Passed 1 test

🔺 Critical test (weight: 50) | Checking the installer triggered no errors
The plugin installed gracefully, with no errors

Server metrics [RAM: ▲0.04MB] [CPU: ▼3.17ms] Passed 4 tests

An overview of server-side resources used by SAR One Click Security
This plugin has minimal impact on server resources
PageMemory (MB)CPU Time (ms)
Home /3.50 ▲0.0443.18 ▲1.57
Dashboard /wp-admin3.34 ▲0.0459.19 ▲6.90
Posts /wp-admin/edit.php3.40 ▲0.0453.23 ▼5.31
Add New Post /wp-admin/post-new.php5.93 ▲0.0487.75 ▼15.78
Media Library /wp-admin/upload.php3.27 ▲0.0441.84 ▲6.83

Server storage [IO: ▲0.06MB] [DB: ▲0.00MB] 67% from 3 tests

Analyzing filesystem and database footprints of this plugin
These are issues you should consider
  • Illegal file modification found: 2 files (2.99KB) outside of "wp-content/plugins/sar-one-click-security/" and "wp-content/uploads/"
    • (new file) wp-content/.htaccess
    • (modified) .htaccess
Filesystem: 6 new files
Database: no new tables, 9 new options
New WordPress options
theysaidso_admin_options
widget_recent-comments
sar_ocs_wpc_htaccess
widget_recent-posts
db_upgraded
sar_ocs_apache24_notice
widget_theysaidso_widget
sar_ocs_ver
can_compress_scripts

Browser metrics Passed 4 tests

This is an overview of browser requirements for SAR One Click Security
Minimal impact on browser resources
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /2,789 ▲2814.34 ▼0.371.83 ▼0.2142.10 ▼4.09
Dashboard /wp-admin2,195 ▲155.50 ▼0.2083.89 ▼7.9139.89 ▼1.37
Posts /wp-admin/edit.php2,100 ▼02.02 ▲0.0336.04 ▼3.6737.65 ▲0.57
Add New Post /wp-admin/post-new.php1,526 ▼222.99 ▼0.11685.15 ▲45.1457.26 ▲5.96
Media Library /wp-admin/upload.php1,397 ▼64.20 ▲0.05112.51 ▲6.5247.36 ▲3.63

Uninstaller [IO: ▲0.00MB] [DB: ▲0.00MB] 75% from 4 tests

🔸 Tests weight: 35 | The uninstall procedure must remove all plugin files and extra database tables
Please fix the following items
  • Zombie WordPress options detected upon uninstall: 6 options
    • theysaidso_admin_options
    • db_upgraded
    • can_compress_scripts
    • widget_theysaidso_widget
    • widget_recent-posts
    • widget_recent-comments

Smoke tests Passed 4 tests

Server-side errors Passed 1 test

🔹 Test weight: 20 | This is a short smoke test looking for server-side errors
The smoke test was a success, however most plugin functionality was not tested

SRP Passed 2 tests

🔹 Tests weight: 20 | The single-responsibility principle: PHP files have to remain inert when accessed directly, throwing no errors and performing no actions
Everything seems fine, however this is by no means an exhaustive test

User-side errors Passed 1 test

🔹 Test weight: 20 | Just a short smoke test targeting errors on the browser (console and network errors and warnings)
Everything seems fine, but this is not an exhaustive test

Optimizations

Plugin configuration Passed 29 tests

readme.txt Passed 16 tests

Perhaps the most important file in your plugin readme.txt gets parsed in order to generate the public listing of your plugin
10 plugin tags: spam, security, login, htaccess, hardening...

sar-one-click-security/sar-one-click-security.php Passed 13 tests

The entry point to "SAR One Click Security" version 1.3 is a PHP file that has certain tags in its header comment area
63 characters long description:
Adds some extra security to your WordPress with only one click.

Code Analysis Passed 3 tests

File types Passed 1 test

🔸 Test weight: 35 | Executable files are not allowed as they can serve as attack vectors
No dangerous file extensions were detected228 lines of code in 2 files:
LanguageFilesBlank linesComment linesLines of code
PHP17590204
PO File11124

PHP code Passed 2 tests

Cyclomatic complexity and code structure are the fingerprint of this plugin
All good! No complexity issues found
Cyclomatic complexity
Average complexity per logical line of code0.18
Average class complexity0.00
▷ Minimum class complexity0.00
▷ Maximum class complexity0.00
Average method complexity0.00
▷ Minimum method complexity0.00
▷ Maximum method complexity0.00
Code structure
Namespaces0
Interfaces0
Traits0
Classes0
▷ Abstract classes00.00%
▷ Concrete classes00.00%
▷ Final classes00.00%
Methods0
▷ Static methods00.00%
▷ Public methods00.00%
▷ Protected methods00.00%
▷ Private methods00.00%
Functions9
▷ Named functions9100.00%
▷ Anonymous functions00.00%
Constants1
▷ Global constants1100.00%
▷ Class constants00.00%
▷ Public constants00.00%

Plugin size Passed 2 tests

Image compression Passed 2 tests

PNG files should be compressed to save space and minimize bandwidth usage
PNG images were not found in this plugin