78% webemailprotector

Code Review | Email Address Security by WebEmailProtector

WordPress plugin Email Address Security by WebEmailProtector scored78%from 54 tests.

About plugin

  • Plugin page: webemailprotector
  • Plugin version: 3.3.6
  • PHP compatiblity: 5.3+
  • PHP version: 7.4.16
  • WordPress compatibility: 3.0.1-6.0.2
  • WordPress version: 6.3.1
  • First release: May 6, 2014
  • Latest release: Sep 14, 2022
  • Number of updates: 102
  • Update frequency: every 29.9 days
  • Top authors: dsrodzin (100%)

Code review

54 tests

User reviews

14 reviews

Install metrics

300+ active /23,088 total downloads

Benchmarks

Plugin footprint 83% from 16 tests

Installer Passed 1 test

🔺 Critical test (weight: 50) | Checking the installer triggered no errors
The plugin installed successfully, without throwing any errors or notices

Server metrics [RAM: ▲0.10MB] [CPU: ▼3.66ms] Passed 4 tests

Server-side resources used by Email Address Security by WebEmailProtector
This plugin has minimal impact on server resources
PageMemory (MB)CPU Time (ms)
Home /3.58 ▲0.1241.03 ▲1.84
Dashboard /wp-admin3.40 ▲0.1045.60 ▼7.01
Posts /wp-admin/edit.php3.45 ▲0.1049.13 ▲0.51
Add New Post /wp-admin/post-new.php6.00 ▲0.1291.80 ▼7.81
Media Library /wp-admin/upload.php3.33 ▲0.1034.99 ▼0.31
WebEmailProtector /wp-admin/options-general.php?page=webemailprotector_plugin_options3.3271.48

Server storage [IO: ▲0.52MB] [DB: ▲0.00MB] Passed 3 tests

Filesystem and database footprint
There were no storage issued detected upon installing this plugin
Filesystem: 37 new files
Database: no new tables, 34 new options
New WordPress options
wepdb_wep_ver
wepdb_wep_emo_1
wepdb_wep_emo_5
wepdb_wep_entry_2
wepdb_wep_emo_4
wepdb_wep_email_5
db_upgraded
wepdb_wep_entry_3
wepdb_wep_email_1
wepdb_wep_email_3
...

Browser metrics Passed 4 tests

Checking browser requirements for Email Address Security by WebEmailProtector
This plugin renders optimally with no browser resource issues detected
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /2,937 ▲17613.40 ▼0.958.02 ▲6.3137.97 ▼6.88
Dashboard /wp-admin2,200 ▲205.53 ▼0.0483.47 ▼10.5346.47 ▲2.92
Posts /wp-admin/edit.php2,114 ▲141.98 ▼0.0439.80 ▲4.7246.17 ▲13.57
Add New Post /wp-admin/post-new.php1,534 ▲823.54 ▲0.25599.31 ▼83.9681.82 ▲27.57
Media Library /wp-admin/upload.php1,408 ▲54.20 ▼0.0594.71 ▲0.3136.83 ▼8.74
WebEmailProtector /wp-admin/options-general.php?page=webemailprotector_plugin_options1,1461.8426.6687.31

Uninstaller [IO: ▲0.00MB] [DB: ▲0.00MB] 75% from 4 tests

🔸 Tests weight: 35 | Verifying that this plugin uninstalls completely without leaving any traces
Please fix the following items
  • Zombie WordPress options detected upon uninstall: 34 options
    • widget_theysaidso_widget
    • wepdb_wep_verified_3
    • wepdb_wep_email_3
    • wepdb_wep_verified_4
    • theysaidso_admin_options
    • db_upgraded
    • wepdb_wep_entry_2
    • wepdb_wep_email_2
    • wepdb_nextemail
    • wepdb_wep_display_name_5
    • ...

Smoke tests 50% from 4 tests

Server-side errors Passed 1 test

🔹 Test weight: 20 | A shallow check that no server-side errors were triggered
Even though no errors were found, this is by no means an exhaustive test

SRP 50% from 2 tests

🔹 Tests weight: 20 | It is important to ensure that your PHP files perform no action when accessed directly, respecting the single-responsibility principle
Please fix the following items
  • 11× GET requests to PHP files have triggered server-side errors or warnings (only 10 are shown):
    • > PHP Fatal error
      Uncaught Error: Call to undefined function add_action() in wp-content/plugins/webemailprotector/admin/webemailprotector_emo_delete.php:4
    • > PHP Fatal error
      Uncaught Error: Call to undefined function add_action() in wp-content/plugins/webemailprotector/admin/webemailprotector_emo_unverify.php:4
    • > PHP Fatal error
      Uncaught Error: Call to undefined function add_action() in wp-content/plugins/webemailprotector/admin/webemailprotector_email_get.php:4
    • > PHP Fatal error
      Uncaught Error: Call to undefined function add_action() in wp-content/plugins/webemailprotector/admin/webemailprotector_email_change.php:4
    • > PHP Fatal error
      Uncaught Error: Call to undefined function add_action() in wp-content/plugins/webemailprotector/admin/webemailprotector_emo_verify.php:4
    • > PHP Fatal error
      Uncaught Error: Call to undefined function add_action() in wp-content/plugins/webemailprotector/admin/webemailprotector_emo_new.php:4
    • > PHP Fatal error
      Uncaught Error: Call to undefined function add_action() in wp-content/plugins/webemailprotector/admin/webemailprotector_emo_unvalidate.php:4
    • > PHP Fatal error
      Uncaught Error: Call to undefined function add_action() in wp-content/plugins/webemailprotector/admin/webemailprotector_displayname_change.php:4
    • > PHP Fatal error
      Uncaught Error: Call to undefined function add_action() in wp-content/plugins/webemailprotector/admin/webemailprotector_emo_validate.php:4
    • > PHP Fatal error
      Uncaught Error: Call to undefined function add_action() in wp-content/plugins/webemailprotector/admin/webemailprotector_emo_default.php:4

User-side errors 0% from 1 test

🔹 Test weight: 20 | Just a short smoke test targeting errors on the browser (console and network errors and warnings)
Please take a look at the following user-side issues
    • > GET request to /wp-admin/options-general.php?page=webemailprotector_plugin_options
    • > Network (severe)
    https://www.webemailprotector.com/cgi-bin/emo_init_wp.py?callback=jQuery37004515013831248207_1697854015889&adminemail=contact%40potrivit.com&wep_ver=v3.3.6&wep_reason=new%20install&_=1697854015890 - Failed to load resource: the server responded with a status of 500 (Internal Server Error)

Optimizations

Plugin configuration 96% from 29 tests

readme.txt Passed 16 tests

You should put a lot of thought into formatting readme.txt as it is used by WordPress.org to prepare the public listing of your plugin
6 plugin tags: security, obfuscate, email, spam, encrypt...

webemailprotector/webemailprotector.php 92% from 13 tests

Analyzing the main PHP file in "Email Address Security by WebEmailProtector" version 3.3.6
It is important to fix the following:
  • Description: Please keep the plugin description shorter than 140 characters (currently 240 characters long)

Code Analysis Passed 3 tests

File types Passed 1 test

🔸 Test weight: 35 | Executable files are not allowed as they can serve as attack vectors
There were no executable files found in this plugin805 lines of code in 17 files:
LanguageFilesBlank linesComment linesLines of code
PHP127483536
JavaScript21014175
CSS341994

PHP code Passed 2 tests

Analyzing cyclomatic complexity and code structure
This plugin has no cyclomatic complexity problems
Cyclomatic complexity
Average complexity per logical line of code0.18
Average class complexity0.00
▷ Minimum class complexity0.00
▷ Maximum class complexity0.00
Average method complexity0.00
▷ Minimum method complexity0.00
▷ Maximum method complexity0.00
Code structure
Namespaces0
Interfaces0
Traits0
Classes0
▷ Abstract classes00.00%
▷ Concrete classes00.00%
▷ Final classes00.00%
Methods0
▷ Static methods00.00%
▷ Public methods00.00%
▷ Protected methods00.00%
▷ Private methods00.00%
Functions23
▷ Named functions23100.00%
▷ Anonymous functions00.00%
Constants0
▷ Global constants00.00%
▷ Class constants00.00%
▷ Public constants00.00%

Plugin size Passed 2 tests

Image compression Passed 2 tests

All PNG images should be compressed to minimize bandwidth usage for end users
18 PNG files occupy 0.46MB with 0.14MB in potential savings
Potential savings
Compression of 5 random PNG files using pngquant
FileSize - originalSize - compressedSavings
images/key.png1.52KB1.57KB0.00%
screenshot2.png1.76KB1.16KB▼ 33.94%
assets/screenshot1.png96.08KB42.81KB▼ 55.44%
images/webemailprotector_logo.png21.01KB7.26KB▼ 65.44%
images/trash-50-red.png0.78KB0.79KB0.00%