10% spoofproof

Code Review | SpoofProof

WordPress plugin SpoofProof scored10%from 54 tests.

About plugin

  • Plugin page: spoofproof
  • Plugin version: 1.0
  • PHP version: 7.4.16
  • WordPress compatibility: 4.3-4.6
  • WordPress version: 6.3.1
  • First release: Nov 23, 2015
  • Latest release: Sep 6, 2016
  • Number of updates: 37
  • Update frequency: every 7.9 days
  • Top authors: ciphertooth (100%)

Code review

54 tests

User reviews

1 review

Install metrics

10+ active /1,081 total downloads

Benchmarks

Plugin footprint 40% from 16 tests

Installer 0% from 1 test

🔺 Critical test (weight: 50) | All plugins must install correctly, without throwing any errors, warnings, or notices
The following installer errors require your attention
  • Install procedure had errors
    • > User deprecated in wp-includes/functions.php+5643
    File wp-db.php is deprecated since version 6.1.0! Use wp-includes/class-wpdb.php instead.

Server metrics [RAM: ▲0.10MB] [CPU: ▼6.05ms] Passed 4 tests

Server-side resources used by SpoofProof
This plugin does not affect your website's performance
PageMemory (MB)CPU Time (ms)
Home /3.56 ▲0.1037.09 ▼7.19
Dashboard /wp-admin3.40 ▲0.1049.37 ▼3.53
Posts /wp-admin/edit.php3.52 ▲0.1652.56 ▲1.26
Add New Post /wp-admin/post-new.php5.98 ▲0.1095.61 ▼14.75
Media Library /wp-admin/upload.php3.33 ▲0.1037.04 ▲4.59

Server storage [IO: ▲0.55MB] [DB: ▲0.00MB] Passed 3 tests

Analyzing filesystem and database footprints of this plugin
This plugin was installed successfully
Filesystem: 39 new files
Database: 2 new tables, 7 new options
New tables
wp_users_suppliment
wp_users_images
New WordPress options
db_upgraded
SpoofProof_db_version
theysaidso_admin_options
widget_recent-comments
widget_recent-posts
can_compress_scripts
widget_theysaidso_widget

Browser metrics Passed 4 tests

An overview of browser requirements for SpoofProof
There were no issues detected in relation to browser resource usage
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /2,805 ▲1914.26 ▲1.161.79 ▼4.0043.66 ▼2.88
Dashboard /wp-admin2,211 ▲345.79 ▲0.1491.92 ▼0.6540.83 ▼8.57
Posts /wp-admin/edit.php2,116 ▲162.00 ▼0.0140.47 ▼0.0936.47 ▲2.47
Add New Post /wp-admin/post-new.php1,548 ▲1918.37 ▼4.84601.74 ▼63.9468.88 ▲8.00
Media Library /wp-admin/upload.php1,413 ▲164.32 ▲0.06100.47 ▼4.0343.74 ▼2.20

Uninstaller [IO: ▲0.00MB] [DB: ▲0.00MB] 50% from 4 tests

🔸 Tests weight: 35 | Checking the uninstaller removed all traces of the plugin
It is recommended to fix the following
  • The plugin did not uninstall successfully, leaving 2 tables in the database
    • wp_users_suppliment
    • wp_users_images
  • This plugin does not fully uninstall, leaving 7 options in the database
    • SpoofProof_db_version
    • db_upgraded
    • widget_recent-comments
    • widget_recent-posts
    • widget_theysaidso_widget
    • theysaidso_admin_options
    • can_compress_scripts

Smoke tests 50% from 4 tests

Server-side errors Passed 1 test

🔹 Test weight: 20 | A smoke test targeting server-side errors
Even though everything seems fine, this is not an exhaustive test

SRP 0% from 2 tests

🔹 Tests weight: 20 | The single-responsibility principle applies for WordPress plugins as well - please make sure your PHP files perform no actions when accessed directly
Please take a closer look at the following
  • 1× PHP files perform the action of outputting non-empty strings when accessed directly:
    • > /wp-content/plugins/spoofproof/spoofproof.php
  • 1× PHP files trigger server errors when accessed directly:
    • > PHP Fatal error
      Uncaught Error: Call to undefined function wp_enqueue_script() in wp-content/plugins/spoofproof/spoofproof-page-options.php:2

User-side errors Passed 1 test

🔹 Test weight: 20 | This is just a short smoke test looking for browser issues
Everything seems fine, but this is not an exhaustive test

Optimizations

Plugin configuration Passed 29 tests

readme.txt Passed 16 tests

The readme.txt file uses markdown syntax to describe your plugin to the world
6 plugin tags: injection, anti-javascript-injection, spoofproof, anti-php-injection, anti-injection...

spoofproof/spoofproof.php Passed 13 tests

The main PHP script in "SpoofProof" version 1.0 is automatically included on every request by WordPress
94 characters long description:
Real security for Word Press we stop Spoofing, Phishing, redirection attacks and MItM attacks.

Code Analysis Passed 3 tests

File types Passed 1 test

🔸 Test weight: 35 | Executable files are not allowed as they can serve as attack vectors
There were no executable files found in this plugin1,056 lines of code in 4 files:
LanguageFilesBlank linesComment linesLines of code
PHP249261688
CSS1384290
JavaScript151078

PHP code Passed 2 tests

A short review of cyclomatic complexity and code structure
Everything seems fine, there were no complexity issues found
Cyclomatic complexity
Average complexity per logical line of code0.15
Average class complexity1.00
▷ Minimum class complexity1.00
▷ Maximum class complexity1.00
Average method complexity1.00
▷ Minimum method complexity1.00
▷ Maximum method complexity1.00
Code structure
Namespaces0
Interfaces0
Traits0
Classes1
▷ Abstract classes00.00%
▷ Concrete classes1100.00%
▷ Final classes00.00%
Methods3
▷ Static methods00.00%
▷ Public methods3100.00%
▷ Protected methods00.00%
▷ Private methods00.00%
Functions20
▷ Named functions20100.00%
▷ Anonymous functions00.00%
Constants4
▷ Global constants4100.00%
▷ Class constants00.00%
▷ Public constants00.00%

Plugin size Passed 2 tests

Image compression Passed 2 tests

Often times overlooked, PNG files can occupy unnecessary space in your plugin
21 PNG files occupy 0.36MB with 0.13MB in potential savings
Potential savings
Compression of 5 random PNG files using pngquant
FileSize - originalSize - compressedSavings
img/toload/wordpress-logo.png45.60KB21.94KB▼ 51.89%
img/horse.png5.41KB5.00KB▼ 7.54%
img/CipherTooth.png2.11KB0.88KB▼ 58.12%
img/steak.png31.30KB12.97KB▼ 58.55%
img/masks.png6.19KB5.88KB▼ 5.03%