90% shellshock-check

Code Review | Shellshock Check

WordPress plugin Shellshock Check scored90%from 54 tests.

About plugin

  • Plugin page: shellshock-check
  • Plugin version: 1.1.0
  • PHP version: 7.4.16
  • WordPress compatibility: 3.0-4.3
  • WordPress version: 6.3.1
  • First release: Sep 30, 2014
  • Latest release: Sep 7, 2015
  • Number of updates: 7
  • Update frequency: every 48.9 days
  • Top authors: freediver (100%)

Code review

54 tests

User reviews

4 reviews

Install metrics

50+ active /3,204 total downloads

Benchmarks

Plugin footprint 83% from 16 tests

Installer Passed 1 test

🔺 Critical test (weight: 50) | The install procedure must perform silently
The plugin installed gracefully, with no errors

Server metrics [RAM: ▲0.00MB] [CPU: ▼2.31ms] Passed 4 tests

An overview of server-side resources used by Shellshock Check
Server-side resource usage in normal parameters
PageMemory (MB)CPU Time (ms)
Home /3.46 ▲0.0036.84 ▼1.47
Dashboard /wp-admin3.31 ▲0.0144.47 ▼3.36
Posts /wp-admin/edit.php3.36 ▲0.0145.89 ▼0.66
Add New Post /wp-admin/post-new.php5.89 ▲0.0090.43 ▼3.75
Media Library /wp-admin/upload.php3.23 ▲0.0036.36 ▲3.30
Shellshock /wp-admin/options-general.php?page=shell-shock-test3.2029.78

Server storage [IO: ▲0.04MB] [DB: ▲0.07MB] Passed 3 tests

A short overview of filesystem and database impact
This plugin was installed successfully
Filesystem: 3 new files
Database: no new tables, 6 new options
New WordPress options
db_upgraded
widget_recent-comments
widget_theysaidso_widget
can_compress_scripts
theysaidso_admin_options
widget_recent-posts

Browser metrics Passed 4 tests

A check of browser resources used by Shellshock Check
This plugin renders optimally with no browser resource issues detected
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /2,829 ▲9414.43 ▲0.051.83 ▼0.0240.02 ▼3.44
Dashboard /wp-admin2,210 ▲225.87 ▲0.9598.98 ▼13.2738.38 ▼2.45
Posts /wp-admin/edit.php2,090 ▼22.04 ▼0.0139.94 ▼1.1437.18 ▲0.95
Add New Post /wp-admin/post-new.php1,542 ▲2823.43 ▲5.93589.16 ▼7.3457.35 ▼2.94
Media Library /wp-admin/upload.php1,386 ▼24.22 ▲0.0196.38 ▲0.2342.55 ▲0.30
Shellshock /wp-admin/options-general.php?page=shell-shock-test7822.0526.8630.13

Uninstaller [IO: ▲0.00MB] [DB: ▲0.07MB] 75% from 4 tests

🔸 Tests weight: 35 | It is important to correctly uninstall your plugin, without leaving any traces
You still need to fix the following
  • The uninstall procedure has failed, leaving 6 options in the database
    • theysaidso_admin_options
    • widget_recent-posts
    • widget_recent-comments
    • can_compress_scripts
    • db_upgraded
    • widget_theysaidso_widget

Smoke tests Passed 4 tests

Server-side errors Passed 1 test

🔹 Test weight: 20 | A smoke test targeting server-side errors
Good news, no errors were detected

SRP Passed 2 tests

🔹 Tests weight: 20 | SRP (Single-Responsibility Principle) - PHP files must act as libraries and never output text or perform any action when accessed directly in a browser
No output text or server-side errors detected on direct access of PHP files

User-side errors Passed 1 test

🔹 Test weight: 20 | This is just a short smoke test looking for browser issues
Everything seems fine, but this is not an exhaustive test

Optimizations

Plugin configuration 97% from 29 tests

readme.txt 94% from 16 tests

Often overlooked, readme.txt is one of the most important files in your plugin
Please fix the following attributes:
  • Screenshots: Screenshot #1 (Shellshock in action) image not found
Please take inspiration from this readme.txt

shellshock-check/shellshock-check.php Passed 13 tests

The main PHP file in "Shellshock Check" ver. 1.1.0 adds more information about the plugin and also serves as the entry point for this plugin
63 characters long description:
Test if the server is affected by the Shellshock vulnerability.

Code Analysis Passed 3 tests

File types Passed 1 test

🔸 Test weight: 35 | This is an overview of file extensions present in this plugin and a short test that no dangerous files are bundled with this plugin
Good job! No executable or dangerous file extensions detected119 lines of code in 1 file:
LanguageFilesBlank linesComment linesLines of code
PHP12810119

PHP code Passed 2 tests

Cyclomatic complexity and code structure are the fingerprint of this plugin
No complexity issues detected
Cyclomatic complexity
Average complexity per logical line of code0.45
Average class complexity0.00
▷ Minimum class complexity0.00
▷ Maximum class complexity0.00
Average method complexity0.00
▷ Minimum method complexity0.00
▷ Maximum method complexity0.00
Code structure
Namespaces0
Interfaces0
Traits0
Classes0
▷ Abstract classes00.00%
▷ Concrete classes00.00%
▷ Final classes00.00%
Methods0
▷ Static methods00.00%
▷ Public methods00.00%
▷ Protected methods00.00%
▷ Private methods00.00%
Functions5
▷ Named functions5100.00%
▷ Anonymous functions00.00%
Constants0
▷ Global constants00.00%
▷ Class constants00.00%
▷ Public constants00.00%

Plugin size Passed 2 tests

Image compression Passed 2 tests

PNG files should be compressed to save space and minimize bandwidth usage
1 PNG file occupies 0.03MB with 0.02MB in potential savings
Potential savings
Compression of 1 random PNG file using pngquant
FileSize - originalSize - compressedSavings
screenshot-1.png30.27KB10.18KB▼ 66.36%