73% secuplug

Code Review | SecureFusion: Ultimate WP Security - Firewall, SSL Control, Anti Spam, Login Security

WordPress plugin SecureFusion: Ultimate WP Security - Firewall, SSL Control, Anti Spam, Login Security scored73%from 54 tests.

About plugin

  • Plugin page: secuplug
  • Plugin version: 1.3.8
  • PHP compatiblity: 7.4.x or later+
  • PHP version: 7.4.16
  • WordPress compatibility: 4.9-6.3
  • WordPress version: 6.3.1
  • First release: Mar 11, 2019
  • Latest release: Aug 22, 2023
  • Number of updates: 86
  • Update frequency: every 18.9 days
  • Top authors: ugurbicer (100%)

Code review

54 tests

User reviews

1 review

Install metrics

10+ active /1,343 total downloads

Benchmarks

Plugin footprint 65% from 16 tests

Installer Passed 1 test

🔺 Critical test (weight: 50) | It is important to correctly install your plugin, without throwing errors or notices
Installer ran successfully

Server metrics [RAM: ▲1.39MB] [CPU: ▲10.55ms] Passed 4 tests

A check of server-side resources used by SecureFusion: Ultimate WP Security - Firewall, SSL Control, Anti Spam, Login Security
Server-side resource usage in normal parameters
PageMemory (MB)CPU Time (ms)
Home /4.82 ▲1.3653.92 ▲11.62
Dashboard /wp-admin4.70 ▲1.4061.60 ▲17.01
Posts /wp-admin/edit.php4.76 ▲1.4065.34 ▲13.78
Add New Post /wp-admin/post-new.php7.30 ▲1.42102.44 ▲4.86
Media Library /wp-admin/upload.php4.63 ▲1.4047.78 ▲11.95
Dashboard /wp-admin/admin.php?page=securefusion4.5344.72
Settings /wp-admin/admin.php?page=securefusion-settings4.6445.63

Server storage [IO: ▲0.23MB] [DB: ▲0.00MB] Passed 3 tests

Analyzing filesystem and database footprints of this plugin
This plugin installed successfully
Filesystem: 55 new files
Database: 1 new table, 7 new options
New tables
wp_securefusion_brute_force_table
New WordPress options
widget_theysaidso_widget
db_upgraded
can_compress_scripts
widget_recent-posts
widget_recent-comments
securefusion_settings
theysaidso_admin_options

Browser metrics Passed 4 tests

This is an overview of browser requirements for SecureFusion: Ultimate WP Security - Firewall, SSL Control, Anti Spam, Login Security
There were no issues detected in relation to browser resource usage
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /2,832 ▲9713.65 ▼0.754.29 ▲2.2542.67 ▼4.59
Dashboard /wp-admin2,238 ▲475.88 ▲1.02102.50 ▼6.4640.89 ▼0.29
Posts /wp-admin/edit.php2,121 ▲292.02 ▲0.0439.89 ▼0.7534.54 ▼0.54
Add New Post /wp-admin/post-new.php1,555 ▲2223.46 ▲0.08671.84 ▲23.3551.04 ▼5.08
Media Library /wp-admin/upload.php1,417 ▲324.23 ▲0.0598.33 ▼1.1945.70 ▲2.05
Dashboard /wp-admin/admin.php?page=securefusion1,0362.2126.3633.73
Settings /wp-admin/admin.php?page=securefusion-settings1,2582.1225.9146.74

Uninstaller [IO: ▲0.00MB] [DB: ▲0.00MB] 50% from 4 tests

🔸 Tests weight: 35 | Checking the uninstaller removed all traces of the plugin
The following items require your attention
  • This plugin does not fully uninstall, leaving 1 table in the database
    • wp_securefusion_brute_force_table
  • This plugin does not fully uninstall, leaving 7 options in the database
    • widget_recent-posts
    • widget_theysaidso_widget
    • widget_recent-comments
    • securefusion_settings
    • db_upgraded
    • theysaidso_admin_options
    • can_compress_scripts

Smoke tests 75% from 4 tests

Server-side errors Passed 1 test

🔹 Test weight: 20 | A smoke test targeting server-side errors
Good news, no errors were detected

SRP 50% from 2 tests

🔹 Tests weight: 20 | The single-responsibility principle: PHP files have to remain inert when accessed directly, throwing no errors and performing no actions
The following issues need your attention
  • 17× PHP files trigger errors when accessed directly with GET requests (only 10 are shown):
    • > PHP Fatal error
      Uncaught Error: Class 'WaspCreators\\FieldCreator' not found in wp-content/plugins/secuplug/vendor/uuur86/wasp/src/WaspCreators/Fields/Select.php:11
    • > PHP Fatal error
      Uncaught Error: Class 'WaspCreators\\FieldCreator' not found in wp-content/plugins/secuplug/vendor/uuur86/wasp/src/WaspCreators/Fields/Radio.php:11
    • > PHP Fatal error
      Uncaught Error: Call to undefined function __() in wp-content/plugins/secuplug/securefusion.php:24
    • > PHP Fatal error
      Uncaught Error: Class 'WaspCreators\\FieldCreator' not found in wp-content/plugins/secuplug/vendor/uuur86/wasp/src/WaspCreators/Fields/Text.php:11
    • > PHP Fatal error
      Trait 'SecureFusion\\Lib\\Traits\\WPCommon' not found in wp-content/plugins/secuplug/src/Lib/Admin.php on line 14
    • > PHP Fatal error
      Uncaught Error: Class 'WaspCreators\\FieldCreator' not found in wp-content/plugins/secuplug/vendor/uuur86/wasp/src/WaspCreators/Fields/File.php:11
    • > PHP Warning
      require_once(ABSPATH/wp-includes/class-IXR.php): failed to open stream: No such file or directory in wp-content/plugins/secuplug/xmlrpc_server.php on line 9
    • > PHP Fatal error
      Uncaught Error: Class 'WaspCreators\\FieldCreator' not found in wp-content/plugins/secuplug/vendor/uuur86/wasp/src/WaspCreators/Fields/Textarea.php:11
    • > PHP Fatal error
      Trait 'SecureFusion\\Lib\\Traits\\WPCommon' not found in wp-content/plugins/secuplug/src/Lib/XMLRPC.php on line 12
    • > PHP Fatal error
      Trait 'SecureFusion\\Lib\\Traits\\WPCommon' not found in wp-content/plugins/secuplug/src/Lib/SSLControl.php on line 12

User-side errors Passed 1 test

🔹 Test weight: 20 | This is just a short smoke test looking for browser issues
There were no browser issues found

Optimizations

Plugin configuration 86% from 29 tests

readme.txt 94% from 16 tests

The readme.txt file describes your plugin functionality and requirements and it is parsed to prepare the your plugin's listing
Attributes that require attention:
  • Screenshots: No descriptions were found for these screenshots #4, #5, #6 in secuplug/assets to your readme.txt
You can take inspiration from this readme.txt

secuplug/securefusion.php 77% from 13 tests

The main file in "SecureFusion: Ultimate WP Security - Firewall, SSL Control, Anti Spam, Login Security" v. 1.3.8 serves as a complement to information provided in readme.txt and as the entry point to the plugin
You should first fix the following items:
  • Text Domain: Since WordPress version 4.6 the text domain is optional; if specified, it must be the same as the plugin slug
  • Main file name: It is recommended to name the main PHP file as the plugin slug ("secuplug.php" instead of "securefusion.php")
  • Requires PHP: Please use periods and digits for the required version (ex. "7.0" instead of "7.4.x or later")

Code Analysis Passed 3 tests

File types Passed 1 test

🔸 Test weight: 35 | This is an overview of file extensions present in this plugin and a short test that no dangerous files are bundled with this plugin
Success! There were no dangerous files found in this plugin4,138 lines of code in 47 files:
LanguageFilesBlank linesComment linesLines of code
PHP311,0828883,215
Markdown4710320
CSS1283163
SVG100154
JSON400123
JavaScript54013113
PO File1182050

PHP code Passed 2 tests

Analyzing logical lines of code, cyclomatic complexity, and other code metrics
There are no cyclomatic complexity problems detected for this plugin
Cyclomatic complexity
Average complexity per logical line of code0.44
Average class complexity18.60
▷ Minimum class complexity1.00
▷ Maximum class complexity142.00
Average method complexity3.80
▷ Minimum method complexity1.00
▷ Maximum method complexity28.00
Code structure
Namespaces5
Interfaces0
Traits1
Classes24
▷ Abstract classes14.17%
▷ Concrete classes2395.83%
▷ Final classes00.00%
Methods153
▷ Static methods1912.42%
▷ Public methods13487.58%
▷ Protected methods1711.11%
▷ Private methods21.31%
Functions5
▷ Named functions120.00%
▷ Anonymous functions480.00%
Constants6
▷ Global constants466.67%
▷ Class constants233.33%
▷ Public constants2100.00%

Plugin size Passed 2 tests

Image compression Passed 2 tests

It is recommended to compress PNG files in your plugin to minimize bandwidth usage
PNG images were not found in this plugin