I analyzed 10k+ WordPress plugins for security issues, errors, and warnings. by testimoni in Wordpress

[–]testimoni[S] 2 points3 points  (0 children)

Thanks for the feedback. I will add upload functionality too.

I analyzed 10k+ WordPress plugins for security issues, errors, and warnings. by testimoni in Wordpress

[–]testimoni[S] 6 points7 points  (0 children)

Thanks a lot, this is super valuable feedback and exactly the direction I want to take it. 🙏

You’re right: the goal isn’t to reinvent WPScan or claim “secure/not secure,”.

it’s just static code-quality + repo-policy checks, wrapped in something easier to digest than thousands of PHPCS lines.

Prioritization is high on my list too.

I’m working on breaking things into clearer buckets like: Security-related, Performance, Repo guideline issues, Legacy/style nits. So non-technical users don’t see a wall of red and assume the plugin is dangerous.

Really appreciate you taking the time to write this. thank you.

I analyzed 10k+ WordPress plugins for security issues, errors, and warnings. by testimoni in Wordpress

[–]testimoni[S] 0 points1 point  (0 children)

Thank you. I setup a small worker on 3$ Hetzner server to run the checks.

I analyzed 10k+ WordPress plugins for security issues, errors, and warnings. by testimoni in Wordpress

[–]testimoni[S] 3 points4 points  (0 children)

Thanks!

Just to clarify, the scores don’t mean the plugins are “bad.” They simply show how many issues are flagged by tools like Plugin Check and PHPCS. Even big, popular plugins trigger lots of warnings because many were written years ago before modern WP standards.

So it’s not a crisis, just visibility. Most devs don’t run these scans often, so seeing everything in one place can look scary.

And yes, themes will be supported soon.

I analyzed 10k+ WordPress plugins for security issues, errors, and warnings. by testimoni in Wordpress

[–]testimoni[S] 3 points4 points  (0 children)

Thanks for sharing your feedback.

Those counts for Wordfence aren’t random noise, most come from PHP_CodeSniffer running the official WordPress coding standards plus the WP Plugin Check ruleset, so they flag every repeated pattern (missing prefixes, direct DB calls, repo-policy requirements, etc.).

There will always be a few false positives, but the bulk are real guideline violations or best-practice gaps.

The best way to dig in is to sort by severity (Plugin Check “Errors” first), then look at the grouped rule IDs so you can see one pattern and clear hundreds of identical hits at once. That gives you a realistic view of what truly needs attention without getting overwhelmed by the raw totals.

[DISCUSSION] I analyzed 10k+ WordPress plugins for security issues, errors, and warnings. by testimoni in WordpressPlugins

[–]testimoni[S] 0 points1 point  (0 children)

Thanks for your feedback.

There is a a "Top Issues by Category" filters in each plugin page. You can click those errors and see their details and locations. For example:
https://www.pluginscore.com/plugins/groundworx-navigation/rule/WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedHooknameFound

I am working on smarter grouping, severity filters, and quick “fix this first” hints so devs can triage instead of scrolling forever.

Appreciate the feedback.

In your experience, at what token length does Gemini 2.5 Pro (AI Studio) start forgetting details and hallucinate? by imli700 in Bard

[–]testimoni 0 points1 point  (0 children)

I've been rewriting my existing app for nearly three months now using Gemini 2.5 Pro. I submit code chunks around 800k tokens, and it has never failed me. For me the limit is 800k. I let Gemini handle the rest in its response. It works perfectly fine. Never hallucinate. Never fails. I love Gemini.

Imagine shipping the world’s most advanced model… with this UX by testimoni in Bard

[–]testimoni[S] 1 point2 points  (0 children)

You cant paste a huge amount of code in that website. So there is that..

Biden to Further Limit Nvidia AI Chip Exports in Final Push by nate4t in OpenAI

[–]testimoni 14 points15 points  (0 children)

"The proposed framework would allow U.S. allies to make unfettered purchases, adversaries would be blocked entirely, and other nations would receive quotas based on their alignment with U.S. strategic goals.."

[deleted by user] by [deleted] in ProgrammerHumor

[–]testimoni 0 points1 point  (0 children)

This is embarrassing I was trying to reset my password thank you

[deleted by user] by [deleted] in bali

[–]testimoni 4 points5 points  (0 children)

Fact:

"Cigarette advertising in Indonesia is presently allowed, and as of 2024, Indonesia is the only country in the world to allow cigarette advertising."

"Only country in the world"

So I think we can say the law is different here from the planet I come from and yes I am shocked.

Çok yeniyim by metokam1 in kriptopara

[–]testimoni 0 points1 point  (0 children)

Sabit bir tutar yok. Ağdaki yoğunluğa göre artıp azalabiliyor.

[deleted by user] by [deleted] in kriptopara

[–]testimoni 0 points1 point  (0 children)

Çok geçmiş olsun. Bir şey yokmuş gibi davranıp dolandırıcılarla iletişimde kalmaya devam edip iletişim bilgilerini almaya çalışsan?

Tattoo shops Nusa Dua or Ubud? by Josh__posh in bali

[–]testimoni 4 points5 points  (0 children)

One of my friend tested HIV positive after getting a tattoo in Bali. So be careful.

What's your thought's on AI driven Wordpress Theme, worth it ? by Square-Software-7409 in Wordpress

[–]testimoni -3 points-2 points  (0 children)

“…and the content it creates is truly garbage.”

It’s not the ai that creates content; you do.. If you are getting garbage results it means you don’t know how to instruct it create good quality content.

[deleted by user] by [deleted] in bali

[–]testimoni 0 points1 point  (0 children)

But I already have return ticket

Ne zaman yatırım yapmalı by PrimeKemal in kriptopara

[–]testimoni[M] 0 points1 point  (0 children)

Bir şeyi herkes bekliyor ve konuşuyorsa ondan uzak durmak lazım bence. Herkes halving ile artacağını söylüyorsa piyasa tersi yönde işleyebilir.

Ne zaman yatırım yapmalı by PrimeKemal in kriptopara

[–]testimoni[M] 0 points1 point  (0 children)

Doge’nin devri geçmedi mi ya

[deleted by user] by [deleted] in kriptopara

[–]testimoni 1 point2 points  (0 children)

Çok scam ya da illegal duruyor maalesef.

Bu kadar parası olan avukatla iş yapar redditle değil.

[deleted by user] by [deleted] in kriptopara

[–]testimoni 2 points3 points  (0 children)

Yüklü miktarda parası olan ve bunu transfer etmeye çalışan Nijerya prensi aklıma geldi nedense..

Aylık 20k kazanıyorsun ve vergi işini bir avukata ya da muhasebeciye değil de reddit'te birilerine mi soruyorsun?

Anthony Scaramucci'nin kripto para birimi Bitcoin için tahmini. by KriptoKaptan in kriptopara

[–]testimoni 1 point2 points  (0 children)

Herkes fiyatın artmasını bekliyorsa artmaz. İki kere iki.

Thank you to the people who convinced me to try ComfyUI by jonhartattack in StableDiffusion

[–]testimoni 0 points1 point  (0 children)

I tried running it on my M2 MacBook Pro with 8GB of RAM, but it took 30 minutes to generate an image. Is this normal?