10% sitelock

Code Review | SiteLock Security

WordPress plugin SiteLock Security scored10%from 54 tests.

About plugin

  • Plugin page: sitelock
  • Plugin version: 4.2.3
  • PHP compatiblity: 7.0+
  • PHP version: 7.4.16
  • WordPress compatibility: 3.8.1-6.3.2
  • WordPress version: 6.3.1
  • First release: May 2, 2013
  • Latest release: Nov 2, 2023
  • Number of updates: 53
  • Update frequency: every 72.7 days
  • Top authors: SiteLockSecurity (100%)

Code review

54 tests

User reviews

12 reviews

Install metrics

1,000+ active /34,196 total downloads

Benchmarks

Plugin footprint 40% from 16 tests

Installer 0% from 1 test

🔺 Critical test (weight: 50) | All plugins must install correctly, without throwing any errors, warnings, or notices
These installer errors require your attention
  • Install procedure validation failed for this plugin
    • > Notice in wp-content/plugins/sitelock/sitelock.php+38
    Undefined index: SITELOCK_IP_HEADER

Server metrics [RAM: ▼1.92MB] [CPU: ▼50.63ms] Passed 4 tests

Server-side resources used by SiteLock Security
Server-side resource usage in normal parameters
PageMemory (MB)CPU Time (ms)
Home /2.07 ▼1.405.16 ▼36.44
Dashboard /wp-admin2.09 ▼1.225.82 ▼41.68
Posts /wp-admin/edit.php2.09 ▼1.276.75 ▼39.29
Add New Post /wp-admin/post-new.php2.09 ▼3.806.71 ▼85.12
Media Library /wp-admin/upload.php2.09 ▼1.146.03 ▼28.74
SiteLock Security /wp-admin/tools.php?page=sitelock2.115.84

Server storage [IO: ▲0.44MB] [DB: ▲0.00MB] Passed 3 tests

Filesystem and database footprint
The plugin installed successfully
Filesystem: 49 new files
Database: no new tables, 9 new options
New WordPress options
theysaidso_admin_options
widget_recent-comments
sitelock_site_id
sl_secret
can_compress_scripts
widget_recent-posts
wpslp_options
db_upgraded
widget_theysaidso_widget

Browser metrics Passed 4 tests

An overview of browser requirements for SiteLock Security
This plugin renders optimally with no browser resource issues detected
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /2,947 ▲18614.42 ▼0.301.71 ▲0.0449.13 ▲6.58
Dashboard /wp-admin2,319 ▲1425.74 ▲0.0694.83 ▲3.8040.90 ▼1.37
Posts /wp-admin/edit.php2,139 ▲422.26 ▲0.2638.43 ▲1.8632.11 ▼3.03
Add New Post /wp-admin/post-new.php1,564 ▲3518.17 ▼5.45619.68 ▼70.5169.25 ▲12.74
Media Library /wp-admin/upload.php1,439 ▲394.36 ▲0.1498.03 ▲1.1941.85 ▼0.04
SiteLock Security /wp-admin/tools.php?page=sitelock8441.8725.5824.94

Uninstaller [IO: ▲0.00MB] [DB: ▲0.00MB] 50% from 4 tests

🔸 Tests weight: 35 | Verifying that this plugin uninstalls completely without leaving any traces
The following items require your attention
  • This plugin cannot be uninstalled
    • > Notice in wp-content/plugins/sitelock/sitelock.php+38
    Undefined index: SITELOCK_IP_HEADER
  • This plugin does not fully uninstall, leaving 9 options in the database
    • sitelock_site_id
    • widget_theysaidso_widget
    • can_compress_scripts
    • theysaidso_admin_options
    • db_upgraded
    • sl_secret
    • widget_recent-comments
    • widget_recent-posts
    • wpslp_options

Smoke tests 25% from 4 tests

Server-side errors 0% from 1 test

🔹 Test weight: 20 | This is a shallow check for server-side errors
Please fix the following server-side errors
    • > GET request to /wp-admin/tools.php?page=sitelock
    • > Notice in wp-content/plugins/sitelock/sitelock.php+38
    Undefined index: SITELOCK_IP_HEADER

SRP 0% from 2 tests

🔹 Tests weight: 20 | It is important to ensure that your PHP files perform no action when accessed directly, respecting the single-responsibility principle
Please take a closer look at the following
  • 1× PHP files output text when accessed directly:
    • > /wp-content/plugins/sitelock/public/partials/sitelock-public-display.php
  • 24× GET requests to PHP files have triggered server-side errors or warnings (only 10 are shown):
    • > PHP Notice
      Undefined variable: msg in wp-content/plugins/sitelock/admin/partials/sitelock-admin-logout.php on line 16
    • > PHP Fatal error
      Uncaught Error: Call to undefined function wp_kses() in wp-content/plugins/sitelock/admin/partials/sitelock-admin-meta-box.php:25
    • > PHP Notice
      Undefined variable: status in wp-content/plugins/sitelock/admin/partials/sitelock-admin-waf-config.php on line 33
    • > PHP Fatal error
      Uncaught Error: Call to undefined function esc_url_raw() in wp-content/plugins/sitelock/admin/partials/sitelock-admin-waf-setup.php:29
    • > PHP Notice
      Trying to access array offset on value of type null in wp-content/plugins/sitelock/admin/partials/sitelock-admin-waf-config.php on line 92
    • > PHP Notice
      Trying to access array offset on value of type null in wp-content/plugins/sitelock/admin/partials/sitelock-admin-waf-config.php on line 86
    • > PHP Fatal error
      Uncaught Error: Call to undefined function admin_url() in wp-content/plugins/sitelock/admin/partials/sitelock-admin-logout.php:19
    • > PHP Fatal error
      Uncaught Error: Call to undefined function esc_html() in wp-content/plugins/sitelock/admin/partials/sitelock-admin-scan-now.php:22
    • > PHP Fatal error
      Uncaught Error: Using $this when not in object context in wp-content/plugins/sitelock/admin/partials/sitelock-admin-scan-results.php:8
    • > PHP Notice
      Undefined variable: general_setting in wp-content/plugins/sitelock/admin/partials/sitelock-admin-waf-config.php on line 86

User-side errors Passed 1 test

🔹 Test weight: 20 | Just a short smoke test targeting errors on the browser (console and network errors and warnings)
There were no browser issues found

Optimizations

Plugin configuration 97% from 29 tests

readme.txt 94% from 16 tests

Perhaps the most important file in your plugin readme.txt gets parsed in order to generate the public listing of your plugin
Please fix the following attributes:
  • Tags: Please reduce the number of tags, currently 12 tag instead of maximum 10
You can look at the official readme.txt

sitelock/sitelock.php Passed 13 tests

"SiteLock Security" version 4.2.3's main PHP file describes plugin functionality and also serves as the entry point to any WordPress functionality
36 characters long description:
Offers deep scan and site compliance

Code Analysis Passed 3 tests

File types Passed 1 test

🔸 Test weight: 35 | A short review of files and their extensions; it is not recommended to include executable files
Success! There were no dangerous files found in this plugin4,586 lines of code in 37 files:
LanguageFilesBlank linesComment linesLines of code
PHP291,1651,6133,831
CSS389177440
JavaScript5111102315

PHP code Passed 2 tests

This plugin's cyclomatic complexity and code structure detailed below
Everything seems fine, there were no complexity issues found
Cyclomatic complexity
Average complexity per logical line of code0.57
Average class complexity37.80
▷ Minimum class complexity1.00
▷ Maximum class complexity280.00
Average method complexity4.31
▷ Minimum method complexity1.00
▷ Maximum method complexity38.00
Code structure
Namespaces0
Interfaces0
Traits0
Classes10
▷ Abstract classes00.00%
▷ Concrete classes10100.00%
▷ Final classes00.00%
Methods112
▷ Static methods32.68%
▷ Public methods8575.89%
▷ Protected methods00.00%
▷ Private methods2724.11%
Functions18
▷ Named functions1794.44%
▷ Anonymous functions15.56%
Constants6
▷ Global constants116.67%
▷ Class constants583.33%
▷ Public constants5100.00%

Plugin size Passed 2 tests

Image compression Passed 2 tests

All PNG images should be compressed to minimize bandwidth usage for end users
4 PNG files occupy 0.01MB with 0.00MB in potential savings
Potential savings
Compression of 4 random PNG files using pngquant
FileSize - originalSize - compressedSavings
admin/images/good.png1.68KB0.46KB▼ 72.51%
admin/images/pending.png1.29KB0.58KB▼ 55.10%
admin/images/failed.png1.81KB0.57KB▼ 68.27%
admin/images/icon.png1.09KB1.05KB▼ 4.11%