73% secure-wp-admin

Code Review | Secure WP Admin

WordPress plugin Secure WP Admin scored73%from 54 tests.

About plugin

  • Plugin page: secure-wp-admin
  • Plugin version: 1.4.1
  • PHP version: 7.4.16
  • WordPress compatibility: 4.0-6.0
  • WordPress version: 6.3.1
  • First release: Mar 8, 2016
  • Latest release: May 24, 2022
  • Number of updates: 50
  • Update frequency: every 45.4 days
  • Top authors: wooexpert (86%)wpexpertsio (16%)

Code review

54 tests

User reviews

1 review

Install metrics

90+ active /3,997 total downloads

Benchmarks

Plugin footprint 83% from 16 tests

Installer Passed 1 test

🔺 Critical test (weight: 50) | It is important to correctly install your plugin, without throwing errors or notices
The plugin installed gracefully, with no errors

Server metrics [RAM: ▲1.29MB] [CPU: ▲8.08ms] Passed 4 tests

This is a short check of server-side resources used by Secure WP Admin
No issues were detected with server-side resource usage
PageMemory (MB)CPU Time (ms)
Home /4.77 ▲1.3154.35 ▲7.62
Dashboard /wp-admin4.64 ▲1.3463.06 ▲9.55
Posts /wp-admin/edit.php4.69 ▲1.3366.35 ▲18.05
Add New Post /wp-admin/post-new.php7.16 ▲1.2795.35 ▼2.89
Media Library /wp-admin/upload.php4.47 ▲1.2454.29 ▲18.91

Server storage [IO: ▲4.72MB] [DB: ▲0.00MB] Passed 3 tests

How much does this plugin use your filesystem and database?
There were no storage issued detected upon installing this plugin
Filesystem: 470 new files
Database: no new tables, 6 new options
New WordPress options
widget_recent-comments
db_upgraded
widget_recent-posts
can_compress_scripts
theysaidso_admin_options
widget_theysaidso_widget

Browser metrics Passed 4 tests

Checking browser requirements for Secure WP Admin
There were no issues detected in relation to browser resource usage
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /3,011 ▲26519.42 ▲5.042.23 ▼0.4243.45 ▼1.15
Dashboard /wp-admin2,387 ▲1999.74 ▲4.84203.05 ▲91.3290.35 ▲47.71
Posts /wp-admin/edit.php2,313 ▲2246.80 ▲4.81120.85 ▲86.1675.15 ▲36.63
Add New Post /wp-admin/post-new.php1,719 ▲20525.38 ▲7.88685.11 ▼18.1041.59 ▼8.43
Media Library /wp-admin/upload.php1,446 ▲587.18 ▲3.00144.96 ▲43.6275.03 ▲26.32
Secure WP Admin /wp-admin/crb_carbon_fields_container_secure_wp_admin.php260.440.1314.48

Uninstaller [IO: ▲0.00MB] [DB: ▲0.00MB] 75% from 4 tests

🔸 Tests weight: 35 | The uninstall procedure must remove all plugin files and extra database tables
It is recommended to fix the following
  • This plugin does not fully uninstall, leaving 6 options in the database
    • can_compress_scripts
    • widget_recent-comments
    • widget_recent-posts
    • theysaidso_admin_options
    • widget_theysaidso_widget
    • db_upgraded

Smoke tests 25% from 4 tests

Server-side errors Passed 1 test

🔹 Test weight: 20 | This is a shallow check for server-side errors
Everything seems fine, however this is by no means an exhaustive test

SRP 0% from 2 tests

🔹 Tests weight: 20 | The single-responsibility principle: PHP files have to remain inert when accessed directly, throwing no errors and performing no actions
The following issues need your attention
  • 1× PHP files output text when accessed directly:
    • > /wp-content/plugins/secure-wp-admin/includes/option_fields/vendor/htmlburger/carbon-fields/templates/Exception/incorrect-syntax.php
  • 205× GET requests to PHP files have triggered server-side errors or warnings (only 10 are shown):
    • > PHP Fatal error
      Uncaught Error: Class 'Composer\\Installers\\BaseInstaller' not found in wp-content/plugins/secure-wp-admin/includes/option_fields/vendor/composer/installers/src/Composer/Installers/PortoInstaller.php:4
    • > PHP Notice
      Undefined variable: plural in wp-content/plugins/secure-wp-admin/includes/option_fields/vendor/htmlburger/carbon-fields/templates/Exception/incorrect-syntax.php on line 32
    • > PHP Fatal error
      Uncaught Error: Class 'Carbon_Fields\\Field\\Field' not found in wp-content/plugins/secure-wp-admin/includes/option_fields/vendor/htmlburger/carbon-fields/core/Field/Oembed_Field.php:8
    • > PHP Fatal error
      Uncaught Error: Class 'Composer\\Installers\\BaseInstaller' not found in wp-content/plugins/secure-wp-admin/includes/option_fields/vendor/composer/installers/src/Composer/Installers/BonefishInstaller.php:4
    • > PHP Fatal error
      Uncaught Error: Class 'Carbon_Fields\\Field\\Select_Field' not found in wp-content/plugins/secure-wp-admin/includes/option_fields/vendor/htmlburger/carbon-fields/core/Field/Radio_Image_Field.php:8
    • > PHP Fatal error
      Uncaught Error: Class 'Carbon_Fields\\Field\\Scripts_Field' not found in wp-content/plugins/secure-wp-admin/includes/option_fields/vendor/htmlburger/carbon-fields/core/Field/Footer_Scripts_Field.php:9
    • > PHP Fatal error
      Uncaught Error: Class 'Composer\\Installers\\BaseInstaller' not found in wp-content/plugins/secure-wp-admin/includes/option_fields/vendor/composer/installers/src/Composer/Installers/KodiCMSInstaller.php:4
    • > PHP Fatal error
      Uncaught Error: Class 'Composer\\Installers\\BaseInstaller' not found in wp-content/plugins/secure-wp-admin/includes/option_fields/vendor/composer/installers/src/Composer/Installers/PhiftyInstaller.php:4
    • > PHP Fatal error
      Uncaught Error: Class 'Composer\\Installers\\BaseInstaller' not found in wp-content/plugins/secure-wp-admin/includes/option_fields/vendor/composer/installers/src/Composer/Installers/EzPlatformInstaller.php:4
    • > PHP Fatal error
      Uncaught Error: Class 'Composer\\Installers\\BaseInstaller' not found in wp-content/plugins/secure-wp-admin/includes/option_fields/vendor/composer/installers/src/Composer/Installers/OntoWikiInstaller.php:4

User-side errors 0% from 1 test

🔹 Test weight: 20 | This is a shallow check for browser errors
Please fix the following user-side errors
    • > GET request to /wp-admin/crb_carbon_fields_container_secure_wp_admin.php
    • > Network (severe)
    wp-admin/crb_carbon_fields_container_secure_wp_admin.php - Failed to load resource: the server responded with a status of 404 (Not Found)

Optimizations

Plugin configuration Passed 29 tests

readme.txt Passed 16 tests

The readme.txt file is important because it is parsed by WordPress.org for the public listing of your plugin
3 plugin tags: secure admin, site security, secure wp admin

secure-wp-admin/secure-wp-admin.php Passed 13 tests

The primary PHP file in "Secure WP Admin" version 1.4.1 is used by WordPress to initiate all plugin functionality
72 characters long description:
Want to lock WP Admin with some PIN code? Then this is the right plugin.

Code Analysis Passed 3 tests

File types Passed 1 test

🔸 Test weight: 35 | Executable files are not allowed as they can serve as attack vectors
Success! There were no dangerous files found in this plugin74,640 lines of code in 439 files:
LanguageFilesBlank linesComment linesLines of code
JavaScript14315,93328,39059,757
PHP2412,6166,57310,910
PO File121,1321,6232,507
JSON800580
CSS27288124558
Markdown5610279
YAML27026
XML12023

PHP code Passed 2 tests

A brief analysis of cyclomatic complexity and code structure for this plugin
There are no cyclomatic complexity problems detected for this plugin
Cyclomatic complexity
Average complexity per logical line of code0.26
Average class complexity5.32
▷ Minimum class complexity1.00
▷ Maximum class complexity61.00
Average method complexity2.04
▷ Minimum method complexity1.00
▷ Maximum method complexity43.00
Code structure
Namespaces25
Interfaces5
Traits0
Classes216
▷ Abstract classes136.02%
▷ Concrete classes20393.98%
▷ Final classes10.49%
Methods941
▷ Static methods828.71%
▷ Public methods75179.81%
▷ Protected methods18219.34%
▷ Private methods80.85%
Functions94
▷ Named functions2223.40%
▷ Anonymous functions7276.60%
Constants32
▷ Global constants721.88%
▷ Class constants2578.12%
▷ Public constants25100.00%

Plugin size Passed 2 tests

Image compression Passed 2 tests

It is recommended to compress PNG files in your plugin to minimize bandwidth usage
2 PNG files occupy 0.01MB with 0.00MB in potential savings
Potential savings
Compression of 2 random PNG files using pngquant
FileSize - originalSize - compressedSavings
img/icon.png2.08KB1.30KB▼ 37.39%
img/default-logo.png6.29KB2.90KB▼ 53.89%