74% wordfence-login-security

Code Review | Wordfence Login Security

WordPress plugin Wordfence Login Security scored74%from 54 tests.

About plugin

  • Plugin page: wordfence-login-s...
  • Plugin version: 1.1.7
  • PHP compatiblity: 5.5+
  • PHP version: 7.4.16
  • WordPress compatibility: 4.5-6.4
  • WordPress version: 6.3.1
  • First release: May 30, 2019
  • Latest release: Nov 6, 2023
  • Number of updates: 53
  • Update frequency: every 30.6 days
  • Top authors: wfalexk (50.94%)wfryan (43.4%)wfmatt (9.43%)

Code review

54 tests

User reviews

17 reviews

Install metrics

50,000+ active /721,395 total downloads

Benchmarks

Plugin footprint 65% from 16 tests

Installer Passed 1 test

🔺 Critical test (weight: 50) | Checking the installer triggered no errors
Install script ran successfully

Server metrics [RAM: ▲1.06MB] [CPU: ▲1.79ms] Passed 4 tests

Analyzing server-side resources used by Wordfence Login Security
Server-side resource usage in normal parameters
PageMemory (MB)CPU Time (ms)
Home /4.54 ▲1.0744.93 ▲7.04
Dashboard /wp-admin4.38 ▲1.0352.71 ▼4.41
Posts /wp-admin/edit.php4.49 ▲1.1452.72 ▲10.26
Add New Post /wp-admin/post-new.php6.96 ▲1.0786.40 ▼3.37
Media Library /wp-admin/upload.php4.30 ▲1.0744.13 ▲7.90

Server storage [IO: ▲1.38MB] [DB: ▲0.00MB] Passed 3 tests

Filesystem and database footprint
There were no storage issued detected upon installing this plugin
Filesystem: 123 new files
Database: 3 new tables, 7 new options
New tables
wp_wfls_role_counts
wp_wfls_2fa_secrets
wp_wfls_settings
New WordPress options
db_upgraded
widget_recent-comments
widget_theysaidso_widget
wordfence_ls_version
theysaidso_admin_options
can_compress_scripts
widget_recent-posts

Browser metrics Passed 4 tests

Wordfence Login Security: an overview of browser usage
This plugin has a minimal impact on browser resources
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /2,834 ▲8714.35 ▲0.221.69 ▲0.1338.09 ▲0.32
Dashboard /wp-admin2,227 ▲505.53 ▼0.1393.32 ▼10.0268.64 ▲26.04
Posts /wp-admin/edit.php2,150 ▲531.97 ▲0.0237.87 ▲1.1035.40 ▲2.90
Add New Post /wp-admin/post-new.php1,564 ▲3823.36 ▲0.29697.47 ▲11.0754.93 ▲2.80
Media Library /wp-admin/upload.php1,441 ▲414.08 ▼0.0498.02 ▲3.5768.59 ▲27.85

Uninstaller [IO: ▲0.00MB] [DB: ▲0.00MB] 50% from 4 tests

🔸 Tests weight: 35 | It is important to correctly uninstall your plugin, without leaving any traces
Please fix the following items
  • The plugin did not uninstall successfully, leaving 3 tables in the database
    • wp_wfls_settings
    • wp_wfls_role_counts
    • wp_wfls_2fa_secrets
  • Zombie WordPress options detected upon uninstall: 6 options
    • can_compress_scripts
    • db_upgraded
    • widget_recent-comments
    • widget_recent-posts
    • theysaidso_admin_options
    • widget_theysaidso_widget

Smoke tests 75% from 4 tests

Server-side errors Passed 1 test

🔹 Test weight: 20 | This is a shallow check for server-side errors
The smoke test was a success, however most plugin functionality was not tested

SRP 50% from 2 tests

🔹 Tests weight: 20 | SRP (Single-Responsibility Principle) - PHP files must act as libraries and never output text or perform any action when accessed directly in a browser
Please take a closer look at the following
  • 6× PHP files trigger server errors when accessed directly:
    • > PHP Fatal error
      Uncaught Error: Class 'WordfenceLS\\Model_Asset' not found in wp-content/plugins/wordfence-login-security/classes/model/style.php:5
    • > PHP Fatal error
      Uncaught Error: Class 'WordfenceLS\\Model_Settings' not found in wp-content/plugins/wordfence-login-security/classes/model/settings/wpoptions.php:7
    • > PHP Fatal error
      Uncaught Error: Interface 'WordfenceLS\\Utility_Lock' not found in wp-content/plugins/wordfence-login-security/classes/utility/databaselock.php:7
    • > PHP Fatal error
      Uncaught Error: Interface 'WordfenceLS\\Utility_Lock' not found in wp-content/plugins/wordfence-login-security/classes/utility/nulllock.php:8
    • > PHP Fatal error
      Uncaught Error: Class 'WordfenceLS\\Model_Asset' not found in wp-content/plugins/wordfence-login-security/classes/model/script.php:5
    • > PHP Fatal error
      Uncaught Error: Class 'WordfenceLS\\Model_Settings' not found in wp-content/plugins/wordfence-login-security/classes/model/settings/db.php:8

User-side errors Passed 1 test

🔹 Test weight: 20 | A shallow check that no browser errors were triggered
There were no browser issues found

Optimizations

Plugin configuration Passed 29 tests

readme.txt Passed 16 tests

Perhaps the most important file in your plugin readme.txt gets parsed in order to generate the public listing of your plugin
8 plugin tags: 2fa, security, captcha, login security, mfa...

wordfence-login-security/wordfence-login-security.php Passed 13 tests

"Wordfence Login Security" version 1.1.7's main PHP file describes plugin functionality and also serves as the entry point to any WordPress functionality
24 characters long description:
Wordfence Login Security

Code Analysis Passed 3 tests

File types Passed 1 test

🔸 Test weight: 35 | This is an overview of file extensions present in this plugin and a short test that no dangerous files are bundled with this plugin
Good job! No executable or dangerous file extensions detected9,895 lines of code in 107 files:
LanguageFilesBlank linesComment linesLines of code
PHP851,0791,2947,785
JavaScript93622162,084
SVG10014
CSS1201112

PHP code Passed 2 tests

A short review of cyclomatic complexity and code structure
Great job! No cyclomatic complexity issues were detected in this plugin
Cyclomatic complexity
Average complexity per logical line of code0.53
Average class complexity26.98
▷ Minimum class complexity1.00
▷ Maximum class complexity233.00
Average method complexity3.76
▷ Minimum method complexity1.00
▷ Maximum method complexity56.00
Code structure
Namespaces5
Interfaces1
Traits0
Classes44
▷ Abstract classes49.09%
▷ Concrete classes4090.91%
▷ Final classes00.00%
Methods411
▷ Static methods7718.73%
▷ Public methods31977.62%
▷ Protected methods297.06%
▷ Private methods6315.33%
Functions10
▷ Named functions110.00%
▷ Anonymous functions990.00%
Constants134
▷ Global constants1511.19%
▷ Class constants11988.81%
▷ Public constants119100.00%

Plugin size Passed 2 tests

Image compression Passed 2 tests

PNG files should be compressed to save space and minimize bandwidth usage
8 PNG files occupy 0.04MB with 0.01MB in potential savings
Potential savings
Compression of 5 random PNG files using pngquant
FileSize - originalSize - compressedSavings
img/ui-icons_cc0000_256x240.png4.44KB4.17KB▼ 6.02%
img/ui-icons_ffffff_256x240.png6.15KB4.17KB▼ 32.13%
img/ui-icons_777620_256x240.png4.44KB4.17KB▼ 6.02%
img/loading_background.png0.15KB0.15KB▼ 0.64%
img/ui-icons_555555_256x240.png6.82KB4.17KB▼ 38.82%