71% wp-hide-security-enhancer

Code Review | WP Hide & Security Enhancer

WordPress plugin WP Hide & Security Enhancer scored71%from 54 tests.

About plugin

  • Plugin page: wp-hide-security-...
  • Plugin version: 2.2.9
  • PHP compatiblity: 5.4+
  • PHP version: 7.4.16
  • WordPress compatibility: 4.0-6.4.1
  • WordPress version: 6.3.1
  • First release: Dec 9, 2015
  • Latest release: Nov 22, 2023
  • Number of updates: 144
  • Update frequency: every 20.2 days
  • Top authors: nsp-code (100%)

Code review

54 tests

User reviews

265 reviews

Install metrics

70,000+ active /2,293,156 total downloads

Benchmarks

Plugin footprint 82% from 16 tests

Installer Passed 1 test

🔺 Critical test (weight: 50) | It is important to correctly install your plugin, without throwing errors or notices
Install script ran successfully

Server metrics [RAM: ▲3.30MB] [CPU: ▲19.33ms] Passed 4 tests

Analyzing server-side resources used by WP Hide & Security Enhancer
This plugin has minimal impact on server resources
PageMemory (MB)CPU Time (ms)
Home /6.24 ▲2.7766.60 ▲26.06
Dashboard /wp-admin6.80 ▲3.4670.32 ▲12.95
Posts /wp-admin/edit.php6.83 ▲3.4775.61 ▲21.50
Add New Post /wp-admin/post-new.php9.48 ▲3.60117.29 ▲16.81
Media Library /wp-admin/upload.php6.75 ▲3.5282.29 ▲43.77
Hide→ Login / Admin /wp-admin/admin.php?page=wp-hide-admin6.6963.53
Overview→ Scan ! /wp-admin/admin.php?page=wp-hide-security-scan6.57495.54
Security→ Headers /wp-admin/admin.php?page=wp-hide-security-headers3.9450.44
Security→ Captcha /wp-admin/admin.php?page=wp-hide-login3.9341.91
Settings→ CDN /wp-admin/admin.php?page=wp-hide-cdn3.9239.88
Hide→ Rewrite / URLs /wp-admin/admin.php?page=wp-hide-rewrite3.9242.91
Hide→ General / Html /wp-admin/admin.php?page=wp-hide-general3.9640.75
Setup ! /wp-admin/admin.php?page=wp-hide3.9247.04

Server storage [IO: ▲3.17MB] [DB: ▲0.02MB] 67% from 3 tests

Filesystem and database footprint
Just a few items left to fix
  • Illegal file modification detected: 3 files (2.31KB) outside of "wp-content/plugins/wp-hide-security-enhancer/" and "wp-content/uploads/"
    • (new file) wp-content/cache/wph/.empty
    • (modified) .htaccess
    • (new file) wp-content/mu-plugins/wp-hide-loader.php
Filesystem: 190 new files
Database: no new tables, 8 new options
New WordPress options
widget_theysaidso_widget
widget_recent-posts
db_upgraded
can_compress_scripts
theysaidso_admin_options
wph-first-view
widget_recent-comments
wph_settings

Browser metrics Passed 4 tests

Checking browser requirements for WP Hide & Security Enhancer
Normal browser usage
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /2,987 ▲22514.69 ▲0.331.91 ▲0.0436.44 ▼5.92
Dashboard /wp-admin2,390 ▲2165.66 ▲0.0887.66 ▼15.5348.86 ▲3.99
Posts /wp-admin/edit.php2,179 ▲792.01 ▲0.0439.90 ▼3.2143.56 ▲6.46
Add New Post /wp-admin/post-new.php1,594 ▲6823.02 ▼0.03613.29 ▼74.8652.94 ▲2.39
Media Library /wp-admin/upload.php1,473 ▲794.15 ▼0.08120.85 ▲18.4048.85 ▲3.50
Hide→ Login / Admin /wp-admin/admin.php?page=wp-hide-admin1,2182.2225.1061.86
Overview→ Scan ! /wp-admin/admin.php?page=wp-hide-security-scan2,7471.8437.4869.59
Security→ Headers /wp-admin/admin.php?page=wp-hide-security-headers1,3281.7131.8180.26
Security→ Captcha /wp-admin/admin.php?page=wp-hide-login1,3721.7526.2351.87
Settings→ CDN /wp-admin/admin.php?page=wp-hide-cdn1,1051.6824.6751.15
Hide→ Rewrite / URLs /wp-admin/admin.php?page=wp-hide-rewrite1,2612.0927.1253.82
Hide→ General / Html /wp-admin/admin.php?page=wp-hide-general1,8721.7034.7254.23
Setup ! /wp-admin/admin.php?page=wp-hide1,5625.5249.4871.32

Uninstaller [IO: ▲0.00MB] [DB: ▲0.03MB] 75% from 4 tests

🔸 Tests weight: 35 | All plugins must uninstall correctly, removing their source code and extra database tables they might have created
You still need to fix the following
  • This plugin did not uninstall successfully, leaving 8 options in the database
    • widget_recent-comments
    • wph_settings
    • wph-first-view
    • can_compress_scripts
    • widget_recent-posts
    • theysaidso_admin_options
    • widget_theysaidso_widget
    • db_upgraded

Smoke tests 25% from 4 tests

Server-side errors Passed 1 test

🔹 Test weight: 20 | Just a short smoke test targeting errors on the server (in the Apache logs)
The smoke test was a success, however most plugin functionality was not tested

SRP 0% from 2 tests

🔹 Tests weight: 20 | The single-responsibility principle applies for WordPress plugins as well - please make sure your PHP files perform no actions when accessed directly
Please fix the following
  • 1× GET requests to PHP files return non-empty strings:
    • > /wp-content/plugins/wp-hide-security-enhancer/include/rewrite-confirm.php
  • 24× PHP files trigger server-side errors or warnings when accessed directly (only 10 are shown):
    • > PHP Warning
      include_once(): Failed opening 'ABSPATHwp-admin/includes/plugin.php' for inclusion (include_path='.:/usr/share/php') in wp-content/plugins/wp-hide-security-enhancer/compatibility/easy-digital-downloads.php on line 18
    • > PHP Warning
      include_once(): Failed opening 'ABSPATHwp-admin/includes/plugin.php' for inclusion (include_path='.:/usr/share/php') in wp-content/plugins/wp-hide-security-enhancer/compatibility/autoptimize.php on line 25
    • > PHP Warning
      include_once(ABSPATHwp-admin/includes/plugin.php): failed to open stream: No such file or directory in wp-content/plugins/wp-hide-security-enhancer/compatibility/fluentform.php on line 24
    • > PHP Fatal error
      Uncaught Error: Call to undefined function is_plugin_active() in wp-content/plugins/wp-hide-security-enhancer/compatibility/ultimate-member.php:26
    • > PHP Warning
      include_once(): Failed opening 'ABSPATHwp-admin/includes/plugin.php' for inclusion (include_path='.:/usr/share/php') in wp-content/plugins/wp-hide-security-enhancer/compatibility/fluentform.php on line 24
    • > PHP Fatal error
      Uncaught Error: Call to undefined function is_plugin_active() in wp-content/plugins/wp-hide-security-enhancer/compatibility/wp-smush.php:25
    • > PHP Warning
      include_once(): Failed opening 'ABSPATHwp-admin/includes/plugin.php' for inclusion (include_path='.:/usr/share/php') in wp-content/plugins/wp-hide-security-enhancer/compatibility/wp-smush.php on line 23
    • > PHP Warning
      include_once(): Failed opening 'ABSPATHwp-admin/includes/plugin.php' for inclusion (include_path='.:/usr/share/php') in wp-content/plugins/wp-hide-security-enhancer/compatibility/fusion-builder.php on line 24
    • > PHP Warning
      Use of undefined constant ABSPATH - assumed 'ABSPATH' (this will throw an Error in a future version of PHP) in wp-content/plugins/wp-hide-security-enhancer/compatibility/fusion-builder.php on line 24
    • > PHP Warning
      Use of undefined constant ABSPATH - assumed 'ABSPATH' (this will throw an Error in a future version of PHP) in wp-content/plugins/wp-hide-security-enhancer/compatibility/autoptimize.php on line 25

User-side errors 0% from 1 test

🔹 Test weight: 20 | This is a shallow check for browser errors
Please take a look at the following user-side issues
    • > GET request to /wp-admin/admin.php?page=wp-hide
    • > Other (warning) in unknown
    /wp-admin/admin.php?page=wp-hide 235 Allow attribute will take precedence over 'allowfullscreen'.

Optimizations

Plugin configuration 90% from 29 tests

readme.txt 94% from 16 tests

Don't ignore readme.txt as it is the file that instructs WordPress.org on how to present your plugin to the world
Please fix the following attributes:
  • Screenshots: These screenshots do not have images: #1 (Admin Interface.), #2 (Sample front html code.)
You can look at the official readme.txt

wp-hide-security-enhancer/wp-hide.php 85% from 13 tests

"WP Hide & Security Enhancer" version 2.2.9's main PHP file describes plugin functionality and also serves as the entry point to any WordPress functionality
Please take the time to fix the following:
  • Main file name: Please rename the main PHP file in this plugin to the plugin slug ("wp-hide-security-enhancer.php" instead of "wp-hide.php")
  • Requires at least: The required version number did not match the one declared in readme.txt ("2.8" instead of "4.0")

Code Analysis Passed 3 tests

File types Passed 1 test

🔸 Test weight: 35 | This is a short overview of programming languages used in this plugin, detecting executable files
No dangerous file extensions were detected20,772 lines of code in 183 files:
LanguageFilesBlank linesComment linesLines of code
PHP1727,4691,38517,239
PO File17951,2702,703
JavaScript312232500
CSS6434313
JSON10017

PHP code Passed 2 tests

Cyclomatic complexity and code structure are the fingerprint of this plugin
No complexity issues detected
Cyclomatic complexity
Average complexity per logical line of code0.43
Average class complexity15.64
▷ Minimum class complexity1.00
▷ Maximum class complexity471.00
Average method complexity3.46
▷ Minimum method complexity1.00
▷ Maximum method complexity52.00
Code structure
Namespaces0
Interfaces0
Traits0
Classes157
▷ Abstract classes00.00%
▷ Concrete classes157100.00%
▷ Final classes00.00%
Methods936
▷ Static methods10511.22%
▷ Public methods92999.25%
▷ Protected methods00.00%
▷ Private methods70.75%
Functions4
▷ Named functions375.00%
▷ Anonymous functions125.00%
Constants17
▷ Global constants17100.00%
▷ Class constants00.00%
▷ Public constants00.00%

Plugin size 50% from 2 tests

Image compression 50% from 2 tests

All PNG images should be compressed to minimize bandwidth usage for end users
4 PNG files occupy 1.38MB with 1.02MB in potential savings
Potential savings
Compression of 4 random PNG files using pngquant
FileSize - originalSize - compressedSavings
assets/images/computer.png73.52KB22.70KB▼ 69.12%
screenshot-1.png502.69KB125.66KB▼ 75.00%
screenshot-2.png831.75KB234.38KB▼ 71.82%
assets/images/warning.png4.66KB0.87KB▼ 81.23%