68% true-factor-auth

Code Review | True Factor Auth

WordPress plugin True Factor Auth scored68%from 54 tests.

About plugin

  • Plugin page: true-factor-auth
  • Plugin version: 1.0.4
  • PHP compatiblity: 7.2+
  • PHP version: 7.4.16
  • WordPress compatibility: 5.4-5.6
  • WordPress version: 6.3.1
  • First release: Sep 16, 2020
  • Latest release: Jan 29, 2021
  • Number of updates: 5
  • Update frequency: every 27.0 days
  • Top authors: truewp (100%)

Code review

54 tests

User reviews

1 review

Install metrics

10+ active /466 total downloads

Benchmarks

Plugin footprint 83% from 16 tests

Installer Passed 1 test

🔺 Critical test (weight: 50) | It is important to correctly install your plugin, without throwing errors or notices
Install script ran successfully

Server metrics [RAM: ▲1.11MB] [CPU: ▲7.36ms] Passed 4 tests

This is a short check of server-side resources used by True Factor Auth
Normal server usage
PageMemory (MB)CPU Time (ms)
Home /4.47 ▲1.0153.12 ▲17.16
Dashboard /wp-admin4.45 ▲1.1167.74 ▲7.34
Posts /wp-admin/edit.php4.50 ▲1.1456.79 ▲10.56
Add New Post /wp-admin/post-new.php7.05 ▲1.16106.63 ▼0.00
Media Library /wp-admin/upload.php4.41 ▲1.1947.01 ▲11.55
SMS Settings /wp-admin/admin.php?page=tfa_sms4.5148.24
Phone Number Confirmation /wp-admin/admin.php?page=tfa_tel_confirmation4.4545.50
Access Rules /wp-admin/admin.php?page=tfa_rules4.3342.25
Verification /wp-admin/admin.php?page=tfa_verification_handlers4.4542.49
Two-Factor Login /wp-admin/admin.php?page=tfa_login_2fa4.4444.27
Edit Rule /wp-admin/admin.php?page=tfa-action-edit4.4346.33
Modules /wp-admin/admin.php?page=true-factor-auth4.3945.64

Server storage [IO: ▲18.18MB] [DB: ▲0.07MB] Passed 3 tests

Filesystem and database footprint
The plugin installed successfully
Filesystem: 4,248 new files
Database: 1 new table, 7 new options
New tables
wp_truefactor_rule
New WordPress options
db_upgraded
widget_recent-comments
trufauth_db_version
can_compress_scripts
theysaidso_admin_options
widget_theysaidso_widget
widget_recent-posts

Browser metrics Passed 4 tests

An overview of browser requirements for True Factor Auth
Minimal impact on browser resources
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /3,251 ▲49016.23 ▲1.839.28 ▲7.5841.37 ▲3.60
Dashboard /wp-admin2,484 ▲3065.97 ▲0.2599.10 ▲1.0444.71 ▼1.41
Posts /wp-admin/edit.php2,351 ▲2513.17 ▲1.1837.18 ▲1.0635.99 ▼2.58
Add New Post /wp-admin/post-new.php1,617 ▲8022.97 ▲4.70647.60 ▲8.8534.15 ▼27.11
Media Library /wp-admin/upload.php1,727 ▲3275.73 ▲1.38104.54 ▲4.6446.09 ▲3.31
SMS Settings /wp-admin/admin.php?page=tfa_sms1,2242.8131.6130.98
Phone Number Confirmation /wp-admin/admin.php?page=tfa_tel_confirmation1,2012.8330.3234.73
Access Rules /wp-admin/admin.php?page=tfa_rules1,2552.9032.5825.23
Verification /wp-admin/admin.php?page=tfa_verification_handlers1,1592.9932.7633.15
Two-Factor Login /wp-admin/admin.php?page=tfa_login_2fa1,1362.9730.4126.70
Edit Rule /wp-admin/admin.php?page=tfa-action-edit1,2552.8131.9532.23
Modules /wp-admin/admin.php?page=true-factor-auth1,2793.1233.9026.89

Uninstaller [IO: ▲0.00MB] [DB: ▲0.07MB] 75% from 4 tests

🔸 Tests weight: 35 | It is important to correctly uninstall your plugin, without leaving any traces
You still need to fix the following
  • This plugin does not fully uninstall, leaving 7 options in the database
    • widget_recent-posts
    • trufauth_db_version
    • widget_recent-comments
    • can_compress_scripts
    • db_upgraded
    • theysaidso_admin_options
    • widget_theysaidso_widget

Smoke tests 50% from 4 tests

Server-side errors Passed 1 test

🔹 Test weight: 20 | This is a short smoke test looking for server-side errors
Everything seems fine, however this is by no means an exhaustive test

SRP 0% from 2 tests

🔹 Tests weight: 20 | The single-responsibility principle applies for WordPress plugins as well - please make sure your PHP files perform no actions when accessed directly
Please fix the following
  • 8× GET requests to PHP files return non-empty strings:
    • > /wp-content/plugins/true-factor-auth/templates/admin/tabs.php
    • > /wp-content/plugins/true-factor-auth/vendor/mustache/mustache/bin/build_bootstrap.php
    • > /wp-content/plugins/true-factor-auth/templates/admin/template-vars.php
    • > /wp-content/plugins/true-factor-auth/trunk/vendor/mustache/mustache/bin/build_bootstrap.php
    • > /wp-content/plugins/true-factor-auth/trunk/templates/admin/template-vars.php
    • > /wp-content/plugins/true-factor-auth/trunk/templates/admin/footer-support.php
    • > /wp-content/plugins/true-factor-auth/templates/admin/footer-support.php
    • > /wp-content/plugins/true-factor-auth/trunk/templates/admin/tabs.php
  • 3812× PHP files trigger errors when accessed directly with GET requests (only 10 are shown):
    • > PHP Fatal error
      Uncaught Error: Class 'Twilio\\InstanceResource' not found in wp-content/plugins/true-factor-auth/trunk/vendor/twilio/sdk/src/Twilio/Rest/Serverless/V1/Service/Environment/VariableInstance.php:32
    • > PHP Fatal error
      Uncaught Error: Class 'Twilio\\InstanceContext' not found in wp-content/plugins/true-factor-auth/trunk/vendor/twilio/sdk/src/Twilio/Rest/Chat/V1/Service/ChannelContext.php:30
    • > PHP Fatal error
      Uncaught Error: Class 'Twilio\\Options' not found in wp-content/plugins/true-factor-auth/vendor/twilio/sdk/src/Twilio/Rest/Api/V2010/Account/Sip/IpAccessControlList/IpAddressOptions.php:45
    • > PHP Fatal error
      Uncaught Error: Class 'Twilio\\Options' not found in wp-content/plugins/true-factor-auth/vendor/twilio/sdk/src/Twilio/Rest/Preview/DeployedDevices/Fleet/DeviceOptions.php:52
    • > PHP Fatal error
      Uncaught Error: Class 'Twilio\\Options' not found in wp-content/plugins/true-factor-auth/vendor/twilio/sdk/src/Twilio/Rest/Video/V1/Room/Participant/SubscribeRulesOptions.php:25
    • > PHP Fatal error
      Uncaught Error: Class 'Twilio\\Options' not found in wp-content/plugins/true-factor-auth/vendor/twilio/sdk/src/Twilio/Rest/Api/V2010/Account/Usage/Record/AllTimeOptions.php:32
    • > PHP Fatal error
      Uncaught Error: Class 'Twilio\\ListResource' not found in wp-content/plugins/true-factor-auth/trunk/vendor/twilio/sdk/src/Twilio/Rest/Autopilot/V1/Assistant/StyleSheetList.php:18
    • > PHP Fatal error
      Uncaught Error: Class 'Twilio\\InstanceResource' not found in wp-content/plugins/true-factor-auth/vendor/twilio/sdk/src/Twilio/Rest/Preview/Sync/Service/Document/DocumentPermissionInstance.php:29
    • > PHP Fatal error
      Uncaught Error: Class 'Twilio\\Page' not found in wp-content/plugins/true-factor-auth/trunk/vendor/twilio/sdk/src/Twilio/Rest/Wireless/V1/Sim/UsageRecordPage.php:16
    • > PHP Fatal error
      Uncaught Error: Class 'Twilio\\ListResource' not found in wp-content/plugins/true-factor-auth/vendor/twilio/sdk/src/Twilio/Rest/Preview/Sync/Service/SyncList/SyncListItemList.php:23

User-side errors Passed 1 test

🔹 Test weight: 20 | This is a shallow check for browser errors
Everything seems fine on the user side

Optimizations

Plugin configuration 90% from 29 tests

readme.txt Passed 16 tests

The readme.txt file uses markdown syntax to describe your plugin to the world
9 plugin tags: authentication, otp, authorisation, security, google authenticator...

true-factor-auth/true-factor-auth.php 77% from 13 tests

Analyzing the main PHP file in "True Factor Auth" version 1.0.4
It is important to fix the following:
  • Text Domain: The text domain is optional since WordPress version 4.6; if you do specify it, it must be the same as the plugin slug
  • Description: Please don't use more than 140 characters for the plugin description (currently 249 characters long)
  • Domain Path: The domain path folder does not exist ("/languages/")

Code Analysis 5% from 3 tests

File types 0% from 1 test

🔸 Test weight: 35 | This is an overview of programming languages used in this plugin; dangerous file extensions are not allowed
Almost there! Just fix the following issues
  • Even if your plugin relies on executable files (for example a companion app), never distribute executable files with your plugin
    • .ms - Maxwell Script in Maxwell Render
      • wp-content/plugins/true-factor-auth/trunk/vendor/mustache/mustache/test/fixtures/templates/alpha.ms
      • wp-content/plugins/true-factor-auth/vendor/mustache/mustache/test/fixtures/templates/alpha.ms
      • wp-content/plugins/true-factor-auth/vendor/mustache/mustache/test/fixtures/templates/beta.ms
      • wp-content/plugins/true-factor-auth/trunk/vendor/mustache/mustache/test/fixtures/templates/beta.ms
108,369 lines of code in 2,087 files:
LanguageFilesBlank linesComment linesLines of code
PHP2,01228,294108,509100,286
JavaScript227536784,350
CSS81,005103,267
JSON100149
Mustache3610145
Markdown3390100
YAML26038
XML22026
Dockerfile1308

PHP code Passed 2 tests

An short overview of logical lines of code, cyclomatic complexity, and other code metrics
Great job! No cyclomatic complexity issues were detected in this plugin
Cyclomatic complexity
Average complexity per logical line of code0.13
Average class complexity2.67
▷ Minimum class complexity1.00
▷ Maximum class complexity87.00
Average method complexity1.30
▷ Minimum method complexity1.00
▷ Maximum method complexity26.00
Code structure
Namespaces198
Interfaces16
Traits2
Classes4,918
▷ Abstract classes54211.02%
▷ Concrete classes4,37688.98%
▷ Final classes40.09%
Methods26,644
▷ Static methods1,3204.95%
▷ Public methods23,92489.79%
▷ Protected methods2,6149.81%
▷ Private methods1060.40%
Functions320
▷ Named functions41.25%
▷ Anonymous functions31698.75%
Constants224
▷ Global constants188.04%
▷ Class constants20691.96%
▷ Public constants206100.00%

Plugin size Passed 2 tests

Image compression Passed 2 tests

Often times overlooked, PNG files can occupy unnecessary space in your plugin
4 PNG files occupy 0.47MB with 0.30MB in potential savings
Potential savings
Compression of 4 random PNG files using pngquant
FileSize - originalSize - compressedSavings
assets/img/flags.png69.20KB23.42KB▼ 66.16%
trunk/assets/img/flags.png69.20KB23.42KB▼ 66.16%
assets/img/flags@2x.png170.28KB68.04KB▼ 60.04%
trunk/assets/img/flags@2x.png170.28KB68.04KB▼ 60.04%