77% zero-spam

Code Review | Zero Spam for WordPress

WordPress plugin Zero Spam for WordPress scored77%from 54 tests.

About plugin

  • Plugin page: zero-spam
  • Plugin version: 5.5.1
  • PHP compatiblity: 7.3+
  • PHP version: 7.4.16
  • WordPress compatibility: 5.2-6.2.2
  • WordPress version: 6.3.1
  • First release: Jul 21, 2014
  • Latest release: May 28, 2023
  • Number of updates: 319
  • Update frequency: every 10.1 days
  • Top authors: bmarshall511 (100%)

Code review

54 tests

User reviews

135 reviews

Install metrics

40,000+ active /1,172,324 total downloads

Benchmarks

Plugin footprint 83% from 16 tests

Installer Passed 1 test

🔺 Critical test (weight: 50) | Verifying that this plugin installs correctly without errors
The plugin installed successfully, without throwing any errors or notices

Server metrics [RAM: ▲0.20MB] [CPU: ▲14.43ms] Passed 4 tests

Analyzing server-side resources used by Zero Spam for WordPress
No issues were detected with server-side resource usage
PageMemory (MB)CPU Time (ms)
Home /3.56 ▲0.1064.91 ▲23.56
Dashboard /wp-admin3.55 ▲0.2173.18 ▲11.53
Posts /wp-admin/edit.php3.60 ▲0.2576.96 ▲25.14
Add New Post /wp-admin/post-new.php6.14 ▲0.25103.74 ▼2.51
Media Library /wp-admin/upload.php3.48 ▲0.2570.16 ▲32.20
Zero Spam /wp-admin/options-general.php?page=wordpress-zero-spam-settings3.5061.56
Zero Spam /wp-admin/index.php?page=wordpress-zero-spam-dashboard3.5065.71

Server storage [IO: ▲4.63MB] [DB: ▲0.00MB] Passed 3 tests

How much does this plugin use your filesystem and database?
No storage issues were detected
Filesystem: 581 new files
Database: 2 new tables, 7 new options
New tables
wp_wpzerospam_blocked
wp_wpzerospam_log
New WordPress options
widget_recent-posts
db_upgraded
theysaidso_admin_options
widget_theysaidso_widget
wpzerospam_honeypot
widget_recent-comments
can_compress_scripts

Browser metrics Passed 4 tests

Checking browser requirements for Zero Spam for WordPress
Minimal impact on browser resources
PageNodesMemory (MB)Script (ms)Layout (ms)
Home /2,808 ▲6214.19 ▼0.161.95 ▲0.2941.52 ▲3.15
Dashboard /wp-admin2,216 ▲395.61 ▼0.0289.04 ▼0.9242.15 ▼1.00
Posts /wp-admin/edit.php2,121 ▲181.95 ▲0.0038.43 ▼1.5132.35 ▼3.48
Add New Post /wp-admin/post-new.php1,546 ▲1823.09 ▲0.28684.40 ▲59.9954.81 ▲4.42
Media Library /wp-admin/upload.php1,421 ▲214.20 ▼0.00101.86 ▼7.0545.75 ▼0.26
Zero Spam /wp-admin/options-general.php?page=wordpress-zero-spam-settings1,8362.2030.3847.52
Zero Spam /wp-admin/index.php?page=wordpress-zero-spam-dashboard2,40313.87216.77168.74

Uninstaller [IO: ▲0.00MB] [DB: ▲0.00MB] 75% from 4 tests

🔸 Tests weight: 35 | All plugins must uninstall correctly, removing their source code and extra database tables they might have created
The following items require your attention
  • This plugin does not fully uninstall, leaving 6 options in the database
    • can_compress_scripts
    • widget_theysaidso_widget
    • theysaidso_admin_options
    • widget_recent-posts
    • widget_recent-comments
    • db_upgraded

Smoke tests 50% from 4 tests

Server-side errors Passed 1 test

🔹 Test weight: 20 | A shallow check that no server-side errors were triggered
Good news, no errors were detected

SRP 50% from 2 tests

🔹 Tests weight: 20 | It is important to ensure that your PHP files perform no action when accessed directly, respecting the single-responsibility principle
Please fix the following items
  • 70× PHP files trigger server-side errors or warnings when accessed directly (only 10 are shown):
    • > PHP Fatal error
      Uncaught Error: Class 'Sabre\\Cache\\AbstractCacheTest' not found in wp-content/plugins/zero-spam/vendor/sabre/cache/tests/Cache/MemcachedTest.php:9
    • > PHP Fatal error
      Uncaught Error: Interface 'GuzzleHttp\\Promise\\PromiseInterface' not found in wp-content/plugins/zero-spam/vendor/guzzlehttp/promises/src/RejectedPromise.php:11
    • > PHP Fatal error
      Uncaught Error: Interface 'GuzzleHttp\\Promise\\PromiseInterface' not found in wp-content/plugins/zero-spam/vendor/guzzlehttp/promises/src/FulfilledPromise.php:11
    • > PHP Fatal error
      Uncaught Error: Call to undefined function wp_kses() in wp-content/plugins/zero-spam/includes/templates/admin-pie.php:10
    • > PHP Fatal error
      Uncaught Error: Class 'Sabre\\Cache\\AbstractCacheTest' not found in wp-content/plugins/zero-spam/vendor/sabre/cache/tests/Cache/MemoryCacheTest.php:9
    • > PHP Fatal error
      Uncaught Error: Interface 'Psr\\Http\\Message\\StreamInterface' not found in wp-content/plugins/zero-spam/vendor/guzzlehttp/psr7/src/MultipartStream.php:13
    • > PHP Notice
      Undefined variable: entries in wp-content/plugins/zero-spam/includes/templates/admin-hours-list.php on line 34
    • > PHP Fatal error
      Uncaught Error: Class 'GuzzleHttp\\Cookie\\CookieJar' not found in wp-content/plugins/zero-spam/vendor/guzzlehttp/guzzle/src/Cookie/SessionCookieJar.php:8
    • > PHP Fatal error
      Uncaught Error: Interface 'Psr\\SimpleCache\\CacheInterface' not found in wp-content/plugins/zero-spam/vendor/sabre/cache/lib/Memcached.php:22
    • > PHP Fatal error
      Uncaught Error: Class 'GuzzleHttp\\Cookie\\CookieJar' not found in wp-content/plugins/zero-spam/vendor/guzzlehttp/guzzle/src/Cookie/FileCookieJar.php:10

User-side errors 0% from 1 test

🔹 Test weight: 20 | This is a shallow check for browser errors
Please take a look at the following user-side issues
    • > GET request to /wp-admin/index.php?page=wordpress-zero-spam-dashboard
    • > Other (warning) in unknown
    /wp-admin/index.php?page=wordpress-zero-spam-dashboard 172 Unrecognized feature: 'web-share'.
    • > GET request to /wp-admin/index.php?page=wordpress-zero-spam-dashboard
    • > Security (warning) in unknown
    security - Error with Permissions-Policy header: Unrecognized feature: 'ambient-light-sensor'.
    • > GET request to /wp-admin/index.php?page=wordpress-zero-spam-dashboard
    • > Security (warning) in unknown
    security - Error with Permissions-Policy header: Unrecognized feature: 'bluetooth'.
    • > GET request to /wp-admin/index.php?page=wordpress-zero-spam-dashboard
    • > Deprecation (warning) in unknown
    https://static.xx.fbcdn.net/rsrc.php/v3/yD/r/CxzjCMQABR5.js?_nc_x=Ij3Wp8lg5Kz 271 Listener added for a synchronous 'DOMSubtreeModified' DOM Mutation Event. This event type is deprecated (https://w3c.github.io/uievents/#legacy-event-types) and work is underway to remove it from this browser. Usage of this event listener will cause performance issues today, and represents a risk of future incompatibility. Consider using MutationObserver instead.
    • > GET request to /wp-admin/index.php?page=wordpress-zero-spam-dashboard
    • > Console-api (severe) in unknown
    https://static.xx.fbcdn.net/rsrc.php/v3/yD/r/CxzjCMQABR5.js?_nc_x=Ij3Wp8lg5Kz 60:573 "ErrorUtils caught an error:\n\nCannot listen to an undefined element. [Caught in: Tried to listen to element of type click]\n\nSubsequent non-fatal errors won't be logged; see https://fburl.com/debugjs."

Optimizations

Plugin configuration 86% from 29 tests

readme.txt Passed 16 tests

You should put a lot of thought into formatting readme.txt as it is used by WordPress.org to prepare the public listing of your plugin
5 plugin tags: security, firewall, protection, spam, spam blocker

zero-spam/wordpress-zero-spam.php 69% from 13 tests

The principal PHP file in "Zero Spam for WordPress" v. 5.5.1 is loaded by WordPress automatically on each request
It is important to fix the following:
  • Domain Path: The domain path folder was not found ("/languages")
  • Requires PHP: Required version must match the one declared in readme.txt ("7.4" instead of "7.3")
  • Description: Please don't use more than 140 characters for the plugin description (currently 214 characters long)
  • Main file name: It is recommended to name the main PHP file as the plugin slug ("zero-spam.php" instead of "wordpress-zero-spam.php")

Code Analysis Passed 3 tests

File types Passed 1 test

🔸 Test weight: 35 | A short review of files and their extensions; it is not recommended to include executable files
Good job! No executable or dangerous file extensions detected37,505 lines of code in 550 files:
LanguageFilesBlank linesComment linesLines of code
PHP1883,6568,62017,671
JavaScript5222211,484
Markdown211,32103,836
JSON19001,438
CSS35831,085
SVG307271,003
Sass11519890
YAML36054
XML21035
make1409

PHP code Passed 2 tests

Cyclomatic complexity and code structure are the fingerprint of this plugin
This plugin has no cyclomatic complexity issues
Cyclomatic complexity
Average complexity per logical line of code0.45
Average class complexity15.22
▷ Minimum class complexity1.00
▷ Maximum class complexity108.00
Average method complexity3.19
▷ Minimum method complexity1.00
▷ Maximum method complexity42.00
Code structure
Namespaces37
Interfaces30
Traits4
Classes129
▷ Abstract classes10.78%
▷ Concrete classes12899.22%
▷ Final classes3426.56%
Methods1,115
▷ Static methods19117.13%
▷ Public methods99288.97%
▷ Protected methods40.36%
▷ Private methods11910.67%
Functions137
▷ Named functions3727.01%
▷ Anonymous functions10072.99%
Constants80
▷ Global constants67.50%
▷ Class constants7492.50%
▷ Public constants6385.14%

Plugin size Passed 2 tests

Image compression Passed 2 tests

Using a strong compression for your PNG files is a great way to speed-up your plugin
6 PNG files occupy 0.07MB with 0.03MB in potential savings
Potential savings
Compression of 5 random PNG files using pngquant
FileSize - originalSize - compressedSavings
modules/contactform7/icon-cf7.png24.57KB8.95KB▼ 63.56%
modules/give/icon-givewp.png17.68KB7.53KB▼ 57.44%
assets/img/icon-stop-forum-spam.png7.10KB2.58KB▼ 63.68%
modules/wpuseravatar/icon-profilepress.png1.50KB1.61KB0.00%
modules/formidable/icon-formidable.png2.03KB2.22KB0.00%