61% wp-security-audit-log

Code Review | WP Activity Log

WordPress plugin WP Activity Log scored61%from 54 tests.

About plugin

  • Plugin page: wp-security-audit...
  • Plugin version: 4.6.1
  • PHP compatiblity: 7.2+
  • PHP version: 7.4.16
  • WordPress compatibility: 5.0-6.3.1
  • WordPress version: 6.3.1
  • First release: May 23, 2013
  • Latest release: Nov 2, 2023
  • Number of updates: 495
  • Update frequency: every 7.7 days
  • Top authors: WPWhiteSecurity (97.78%)WPProHelp (2.22%)

Code review

54 tests

User reviews

398 reviews

Install metrics

200,000+ active /4,974,756 total downloads

Benchmarks

Plugin footprint 64% from 16 tests

Installer Passed 1 test

🔺 Critical test (weight: 50) | Verifying that this plugin installs correctly without errors
Install script ran successfully

Server metrics [RAM: ▲6.15MB] [CPU: ▲39.41ms] 50% from 4 tests

An overview of server-side resources used by WP Activity Log
The following require your attention
  • RAM: Total memory usage must be kept under 10MB (currently 11.53MB on /wp-admin/admin.php?page=wsal-auditlog)
  • Extra RAM: The extra memory usage should kept under 5MB (currently 6.15MB on /wp-admin/index.php?page=wsal-setup)
PageMemory (MB)CPU Time (ms)
Home /8.61 ▲5.1469.94 ▲28.82
Dashboard /wp-admin10.27 ▲6.9299.53 ▲35.15
Posts /wp-admin/edit.php9.89 ▲6.53101.16 ▲47.08
Add New Post /wp-admin/post-new.php12.37 ▲6.47136.86 ▲46.59
Media Library /wp-admin/upload.php9.70 ▲6.4686.36 ▲51.80
Search Filters ✛ /wp-admin/admin.php?page=wsal-search9.5575.63
Reports ✛ /wp-admin/admin.php?page=wsal-reports9.57129.89
Enable/Disable Events /wp-admin/admin.php?page=wsal-togglealerts11.1081.70
Settings /wp-admin/admin.php?page=wsal-settings9.5581.43
Log viewer /wp-admin/admin.php?page=wsal-auditlog11.53103.29
Help & Contact Us /wp-admin/admin.php?page=wsal-help9.5473.95
Upgrade to Premium /wp-admin/admin.php?page=upgrade9.6085.83
Integrations ✛ /wp-admin/admin.php?page=wsal-externaldb9.5570.58
Email & SMS Notifications ✛ /wp-admin/admin.php?page=wsal-emailnotifications9.5584.61
/wp-admin/index.php?page=wsal-setup9.4666.13

Server storage [IO: ▲6.88MB] [DB: ▲0.00MB] Passed 3 tests

How much does this plugin use your filesystem and database?
This plugin was installed successfully
Filesystem: 335 new files
Database: 2 new tables, 7 new options
New tables
wp_wsal_occurrences
wp_wsal_metadata
New WordPress options
wsal_setup-modal-dismissed
theysaidso_admin_options
widget_recent-posts
can_compress_scripts
widget_recent-comments
widget_theysaidso_widget
db_upgraded

Browser metrics Passed 4 tests

A check of browser resources used by WP Activity Log
This plugin has a minimal impact on browser resources
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /2,928 ▲18214.36 ▼0.411.61 ▼0.2237.70 ▼5.67
Dashboard /wp-admin2,334 ▲1545.69 ▲0.0496.71 ▲0.9745.60 ▼0.85
Posts /wp-admin/edit.php2,203 ▲1032.07 ▲0.1142.87 ▲6.4639.79 ▲6.54
Add New Post /wp-admin/post-new.php1,583 ▲5723.46 ▲0.50639.15 ▼149.5255.57 ▲1.59
Media Library /wp-admin/upload.php1,506 ▲1034.24 ▲0.0497.82 ▲0.3444.46 ▲1.13
Search Filters ✛ /wp-admin/admin.php?page=wsal-search1,0302.2031.9347.18
Reports ✛ /wp-admin/admin.php?page=wsal-reports1,0482.2028.2634.47
Enable/Disable Events /wp-admin/admin.php?page=wsal-togglealerts3,7881.6497.7965.26
Settings /wp-admin/admin.php?page=wsal-settings1,3862.0935.6138.68
Log viewer /wp-admin/admin.php?page=wsal-auditlog1,6382.2647.0747.08
Help & Contact Us /wp-admin/admin.php?page=wsal-help1,47412.89280.8565.84
Upgrade to Premium /wp-admin/admin.php?page=upgrade280.420.093.44
Integrations ✛ /wp-admin/admin.php?page=wsal-externaldb1,0422.3033.4240.03
Email & SMS Notifications ✛ /wp-admin/admin.php?page=wsal-emailnotifications1,0772.1834.2238.97
/wp-admin/index.php?page=wsal-setup1731.4514.439.42

Uninstaller [IO: ▲0.00MB] [DB: ▲0.00MB] 50% from 4 tests

🔸 Tests weight: 35 | Verifying that this plugin uninstalls completely without leaving any traces
Please fix the following items
  • Zombie tables were found after uninstall: 2 tables
    • wp_wsal_metadata
    • wp_wsal_occurrences
  • This plugin did not uninstall successfully, leaving 7 options in the database
    • widget_recent-posts
    • theysaidso_admin_options
    • can_compress_scripts
    • widget_theysaidso_widget
    • wsal_setup-modal-dismissed
    • db_upgraded
    • widget_recent-comments

Smoke tests 25% from 4 tests

Server-side errors 0% from 1 test

🔹 Test weight: 20 | This is a shallow check for server-side errors
These server-side errors were triggered
  • 2 occurences, only the last one shown
    • > GET request to /wp-admin/admin.php?page=wsal-externaldb
    • > request to
    • > Notice in wp-config.php+20
    Undefined index: REQUEST_METHOD

SRP 50% from 2 tests

🔹 Tests weight: 20 | SRP (Single-Responsibility Principle) - PHP files must act as libraries and never output text or perform any action when accessed directly in a browser
Almost there! Just fix the following items
  • 7× GET requests to PHP files have triggered server-side errors or warnings:
    • > PHP Fatal error
      Uncaught Error: Class 'WSAL\\Multisite\etworkWide\\AbstractTracker' not found in wp-content/plugins/wp-security-audit-log/classes/Multisite/NetworkWide/CPTsTracker.php:18
    • > PHP Fatal error
      Uncaught Error: Interface 'WSAL\\Multisite\etworkWide\\TrackerInterface' not found in wp-content/plugins/wp-security-audit-log/classes/Multisite/NetworkWide/AbstractTracker.php:30
    • > PHP Fatal error
      Uncaught Error: Class 'WSAL_Vendor\\WP_Async_Request' not found in wp-content/plugins/wp-security-audit-log/third-party/vendor/classes/wp-background-process.php:16
    • > PHP Warning
      Use of undefined constant ABSPATH - assumed 'ABSPATH' (this will throw an Error in a future version of PHP) in wp-content/plugins/wp-security-audit-log/classes/ListAdminEvents/class-list-events.php on line 34
    • > PHP Fatal error
      require_once(): Failed opening required 'ABSPATHwp-admin/includes/template.php' (include_path='.:/usr/share/php') in wp-content/plugins/wp-security-audit-log/classes/ListAdminEvents/class-list-events.php on line 34
    • > PHP Fatal error
      Uncaught Error: Call to undefined function WSAL_Vendor\\plugin_dir_path() in wp-content/plugins/wp-security-audit-log/third-party/vendor/wp-background-processing.php:21
    • > PHP Warning
      require_once(ABSPATHwp-admin/includes/template.php): failed to open stream: No such file or directory in wp-content/plugins/wp-security-audit-log/classes/ListAdminEvents/class-list-events.php on line 34

User-side errors 0% from 1 test

🔹 Test weight: 20 | This is a shallow check for browser errors
These are user-side errors you should fix
    • > GET request to /wp-admin/admin.php?page=wsal-search
    • > Network (severe)
    wp-content/plugins/wp-security-audit-log/img/wsal-search.jpg - Failed to load resource: the server responded with a status of 404 (Not Found)
    • > GET request to /wp-admin/admin.php?page=wsal-reports
    • > Network (severe)
    wp-content/plugins/wp-security-audit-log/img/wsal-reports.jpg - Failed to load resource: the server responded with a status of 404 (Not Found)
    • > GET request to /wp-admin/admin.php?page=upgrade
    • > Network (severe)
    wp-admin/admin.php?page=upgrade - Failed to load resource: the server responded with a status of 500 (Internal Server Error)
    • > GET request to /wp-admin/admin.php?page=wsal-externaldb
    • > Network (severe)
    wp-content/plugins/wp-security-audit-log/img/wsal-externaldb.jpg - Failed to load resource: the server responded with a status of 404 (Not Found)
    • > GET request to /wp-admin/admin.php?page=wsal-emailnotifications
    • > Network (severe)
    wp-content/plugins/wp-security-audit-log/img/wsal-emailnotifications.jpg - Failed to load resource: the server responded with a status of 404 (Not Found)

Optimizations

Plugin configuration 96% from 29 tests

readme.txt Passed 16 tests

Perhaps the most important file in your plugin readme.txt gets parsed in order to generate the public listing of your plugin
10 plugin tags: user tracking, log, audit trail, security audit log, website changes...

wp-security-audit-log/wp-security-audit-log.php 92% from 13 tests

The entry point to "WP Activity Log" version 4.6.1 is a PHP file that has certain tags in its header comment area
The following require your attention:
  • Description: Please don't use more than 140 characters for the plugin description (currently 280 characters long)

Code Analysis 97% from 3 tests

File types Passed 1 test

🔸 Test weight: 35 | This is an overview of file extensions present in this plugin and a short test that no dangerous files are bundled with this plugin
No dangerous file extensions were detected68,691 lines of code in 253 files:
LanguageFilesBlank linesComment linesLines of code
PHP1336,41418,84640,313
PO File75,6566,60416,013
JavaScript811,5401,8527,337
CSS207784533,914
SVG10010786
Sass1254175
JSON100153

PHP code 50% from 2 tests

Analyzing cyclomatic complexity and code structure
It is recommended to fix the following
  • Cyclomatic complexity of methods should be reduced to less than 100 (currently 186)
Cyclomatic complexity
Average complexity per logical line of code0.59
Average class complexity53.50
▷ Minimum class complexity1.00
▷ Maximum class complexity995.00
Average method complexity4.99
▷ Minimum method complexity1.00
▷ Maximum method complexity186.00
Code structure
Namespaces21
Interfaces1
Traits0
Classes120
▷ Abstract classes75.83%
▷ Concrete classes11394.17%
▷ Final classes32.65%
Methods1,578
▷ Static methods1,01664.39%
▷ Public methods1,26279.97%
▷ Protected methods633.99%
▷ Private methods25316.03%
Functions68
▷ Named functions3348.53%
▷ Anonymous functions3551.47%
Constants45
▷ Global constants2555.56%
▷ Class constants2044.44%
▷ Public constants20100.00%

Plugin size 50% from 2 tests

Image compression 50% from 2 tests

Using a strong compression for your PNG files is a great way to speed-up your plugin
45 PNG files occupy 2.09MB with 1.25MB in potential savings
Potential savings
Compression of 5 random PNG files using pngquant
FileSize - originalSize - compressedSavings
img/search/search_2.png233.38KB70.13KB▼ 69.95%
img/users-sessions-management/user_sessions_1.png87.46KB46.99KB▼ 46.27%
js/freemius-pricing/cb5fc4f6ec7ada72e986f6e7dde365bf.png22.92KB3.42KB▼ 85.08%
img/mails/daily-notification/box-shadow-up.png1.18KB0.50KB▼ 57.79%
img/external-db/db_integrations_2.png23.89KB14.33KB▼ 40.01%