74% wp-otp

Code Review | WP-OTP

WordPress plugin WP-OTP scored74%from 54 tests.

About plugin

  • Plugin page: wp-otp
  • Plugin version: 0.6.1
  • PHP compatiblity: 7.4+
  • PHP version: 7.4.16
  • WordPress compatibility: 4.6-5.6
  • WordPress version: 6.3.1
  • First release: Nov 4, 2016
  • Latest release: Feb 18, 2021
  • Number of updates: 30
  • Update frequency: every 52.3 days
  • Top authors: noplanman (100%)

Code review

54 tests

User reviews

8 reviews

Install metrics

100+ active /9,663 total downloads

Benchmarks

Plugin footprint 65% from 16 tests

Installer Passed 1 test

🔺 Critical test (weight: 50) | Verifying that this plugin installs correctly without errors
The plugin installed gracefully, with no errors

Server metrics [RAM: ▼0.01MB] [CPU: ▼4.37ms] Passed 4 tests

Server-side resources used by WP-OTP
No issues were detected with server-side resource usage
PageMemory (MB)CPU Time (ms)
Home /3.46 ▲0.0045.16 ▲2.96
Dashboard /wp-admin3.31 ▼0.0452.66 ▼11.13
Posts /wp-admin/edit.php3.36 ▲0.0051.56 ▼1.39
Add New Post /wp-admin/post-new.php5.89 ▲0.0095.23 ▼7.09
Media Library /wp-admin/upload.php3.23 ▲0.0036.41 ▲2.12

Server storage [IO: ▲2.12MB] [DB: ▲0.00MB] Passed 3 tests

Filesystem and database footprint
This plugin installed successfully
Filesystem: 378 new files
Database: no new tables, 6 new options
New WordPress options
widget_recent-posts
db_upgraded
can_compress_scripts
theysaidso_admin_options
widget_recent-comments
widget_theysaidso_widget

Browser metrics Passed 4 tests

This is an overview of browser requirements for WP-OTP
This plugin has a minimal impact on browser resources
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /2,789 ▲4314.75 ▲0.391.84 ▼0.8842.62 ▼3.99
Dashboard /wp-admin2,195 ▲215.65 ▲0.0494.58 ▲4.3342.79 ▲3.89
Posts /wp-admin/edit.php2,097 ▼32.04 ▼0.0040.42 ▲2.2639.33 ▲2.57
Add New Post /wp-admin/post-new.php1,545 ▲1923.38 ▲5.88651.47 ▼63.1651.41 ▼8.66
Media Library /wp-admin/upload.php1,394 ▼64.23 ▲0.0296.89 ▼7.9039.31 ▼11.60

Uninstaller [IO: ▲2.12MB] [DB: ▲0.00MB] 50% from 4 tests

🔸 Tests weight: 35 | Verifying that this plugin uninstalls completely without leaving any traces
Please fix the following items
  • The plugin did not uninstall correctly, leaving 378 files (2.12MB) in the plugin directory
    • (new file) admin/images/freeotpplus.png
    • (new file) admin/images/app-store.png
    • (new file) admin/images/onetimepass.png
    • (new file) admin/class-wp-otp-admin.php
    • (new file) admin/images/play-store.png
    • (new file) admin/images/andotp.png
    • (new file) admin/images/f-droid.png
    • (new file) admin/images/aegis.png
    • (new file) admin/css/wp-otp-admin.css
    • (new file) admin/images/otp-authenticator.png
    • ...
  • Zombie WordPress options were found after uninstall: 6 options
    • widget_recent-comments
    • can_compress_scripts
    • db_upgraded
    • theysaidso_admin_options
    • widget_theysaidso_widget
    • widget_recent-posts

Smoke tests 75% from 4 tests

Server-side errors Passed 1 test

🔹 Test weight: 20 | This is a short smoke test looking for server-side errors
Even though everything seems fine, this is not an exhaustive test

SRP 50% from 2 tests

🔹 Tests weight: 20 | The single-responsibility principle: PHP files have to remain inert when accessed directly, throwing no errors and performing no actions
Almost there! Just fix the following items
  • 174× PHP files trigger errors when accessed directly with GET requests (only 10 are shown):
    • > PHP Fatal error
      Uncaught Error: Interface 'OTPHP\\FactoryInterface' not found in wp-content/plugins/wp-otp/vendor/spomky-labs/otphp/src/Factory.php:25
    • > PHP Fatal error
      Uncaught Error: Class 'chillerlan\\QRCodeTest\\Output\\QROutputTestAbstract' not found in wp-content/plugins/wp-otp/vendor/chillerlan/php-qrcode/tests/Output/QRFpdfTest.php:24
    • > PHP Fatal error
      Uncaught Error: Class 'chillerlan\\QRCode\\Output\\QRImage' not found in wp-content/plugins/wp-otp/vendor/chillerlan/php-qrcode/examples/QRImageWithLogo.php:24
    • > PHP Fatal error
      Uncaught Error: Interface 'Safe\\Exceptions\\SafeExceptionInterface' not found in wp-content/plugins/wp-otp/vendor/thecodingmachine/safe/generated/Exceptions/IconvException.php:4
    • > PHP Fatal error
      require_once(): Failed opening required 'wp-content/plugins/wp-otp/vendor/chillerlan/php-qrcode/examples/../vendor/autoload.php' (include_path='.:/usr/share/php') in wp-content/plugins/wp-otp/vendor/chillerlan/php-qrcode/examples/fpdf.php on line 7
    • > PHP Warning
      require_once(wp-content/plugins/wp-otp/vendor/chillerlan/php-settings-container/examples/../vendor/autoload.php): failed to open stream: No such file or directory in wp-content/plugins/wp-otp/vendor/chillerlan/php-settings-container/examples/advanced.php on line 14
    • > PHP Fatal error
      Uncaught Error: Interface 'Safe\\Exceptions\\SafeExceptionInterface' not found in wp-content/plugins/wp-otp/vendor/thecodingmachine/safe/generated/Exceptions/InfoException.php:4
    • > PHP Fatal error
      Uncaught Error: Interface 'Safe\\Exceptions\\SafeExceptionInterface' not found in wp-content/plugins/wp-otp/vendor/thecodingmachine/safe/generated/Exceptions/LdapException.php:4
    • > PHP Fatal error
      Uncaught Error: Interface 'Safe\\Exceptions\\SafeExceptionInterface' not found in wp-content/plugins/wp-otp/vendor/thecodingmachine/safe/generated/Exceptions/FunchandException.php:4
    • > PHP Fatal error
      Uncaught Error: Interface 'Safe\\Exceptions\\SafeExceptionInterface' not found in wp-content/plugins/wp-otp/vendor/thecodingmachine/safe/generated/Exceptions/GmpException.php:4

User-side errors Passed 1 test

🔹 Test weight: 20 | This is a smoke test targeting browser errors/issues
No browser issues were found

Optimizations

Plugin configuration Passed 29 tests

readme.txt Passed 16 tests

The readme.txt file uses markdown syntax to describe your plugin to the world
9 plugin tags: google authenticator, one time password, login, recovery, 2fa...

wp-otp/wp-otp.php Passed 13 tests

The entry point to "WP-OTP" version 0.6.1 is a PHP file that has certain tags in its header comment area
95 characters long description:
WP-OTP adds 2 Factor Authentication using TOTP. (Based on "WP Secure Login" by Brijesh Kothari)

Code Analysis Passed 3 tests

File types Passed 1 test

🔸 Test weight: 35 | This is an overview of file extensions present in this plugin and a short test that no dangerous files are bundled with this plugin
Everything looks great! No dangerous files found in this plugin25,338 lines of code in 343 files:
LanguageFilesBlank linesComment linesLines of code
PHP3045,37139,85423,317
JSON700890
Markdown91600490
YAML118037293
XML700163
HTML1260137
CSS14024
JavaScript11011
Dockerfile15210
Bourne Shell1203

PHP code Passed 2 tests

An short overview of logical lines of code, cyclomatic complexity, and other code metrics
All good! No complexity issues found
Cyclomatic complexity
Average complexity per logical line of code0.33
Average class complexity5.42
▷ Minimum class complexity1.00
▷ Maximum class complexity213.00
Average method complexity2.24
▷ Minimum method complexity1.00
▷ Maximum method complexity19.00
Code structure
Namespaces21
Interfaces10
Traits5
Classes175
▷ Abstract classes179.71%
▷ Concrete classes15890.29%
▷ Final classes1912.03%
Methods709
▷ Static methods28840.62%
▷ Public methods57080.39%
▷ Protected methods10715.09%
▷ Private methods324.51%
Functions1,134
▷ Named functions1,12298.94%
▷ Anonymous functions121.06%
Constants135
▷ Global constants53.70%
▷ Class constants13096.30%
▷ Public constants12394.62%

Plugin size Passed 2 tests

Image compression Passed 2 tests

Often times overlooked, PNG files can occupy unnecessary space in your plugin
11 PNG files occupy 0.04MB with 0.01MB in potential savings
Potential savings
Compression of 5 random PNG files using pngquant
FileSize - originalSize - compressedSavings
admin/images/play-store.png1.56KB1.38KB▼ 11.88%
admin/images/aegis.png1.82KB1.81KB▼ 0.70%
vendor/chillerlan/php-qrcode/examples/octocat.png2.41KB2.46KB0.00%
vendor/chillerlan/php-qrcode/examples/example_svg.png15.55KB6.70KB▼ 56.90%
admin/images/onetimepass.png3.39KB2.59KB▼ 23.48%