Skip to content
CAI
Software that uses CAICheck a score

activemerchant/active_merchant

61.8

Adequate · 26 September 2026

72.5k

lines of production code

Ruby

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This release delivers a significant security upgrade by fixing [CVE redacted] in the rexml gem, alongside a major architectural shift that extracts offsite payment integrations into a separate gem. The core library introduces structured result objects for AVS and CVV checks, modernizes HTTP connection handling with proxy and SSL/TLS configuration support, and adds country code validation. A wide range of payment gateways, including Braintree, PayPal, and Payflow, receive extensive updates, new features like 3D Secure 2 and network tokenization, and refactored internal logic. The release also removes legacy generator scripts, deprecated integrations, and outdated test coverage, while adding comprehensive unit and schema validation tests for the remaining gateways.

Features

Add Cecabank payment gateway support

Introduces the Cecabank payment gateway, enabling merchants to process credit card transactions via both XML and JSON REST APIs. The implementation includes support for standard purchase, authorization, capture, void, and refund operations, along with encrypted sensitive data handling and scrubbing for security compliance.

_lib/active\merchant/billing/gateways/cecabank · high confidence

Add FirstPay gateway support for REST/JSON and digital wallets

Added a new REST/JSON-based implementation of the FirstPay payment gateway (FirstPayJsonGateway) alongside the existing XML-based implementation (FirstPayXmlGateway). The new implementation enables support for Apple Pay and Google Pay via the WALLET\_TYPES mapping and handles network tokenization credit cards. Both implementations share common configuration in a new FirstPayCommon module.

_lib/active\_merchant/billing/gateways/first\pay · high confidence

Add MiGS payment gateway integration

Users can now process payments through the MiGS (Merchant Internet Gateway System) payment provider. This change introduces the necessary mapping codes for transaction responses, issuer responses, and 3D Secure verification statuses, along with credit card type definitions required for the new gateway.

_lib/active\merchant/billing/gateways/migs · high confidence

Add QuickPay V10 API support with shared common logic

The QuickPay gateway now supports the V10 API alongside existing V4-V7 implementations. A new \QuickpayCommon\ module provides shared configuration, including supported countries, card types, and response codes, while \QuickpayV10\ implements the new API version with features like customer IP tracking, 3D Secure parameters, and synchronous operations. The V4-V7 gateway continues to support older API versions with XML-based communication.

_lib/active\merchant/billing/gateways/quickpay · high confidence

Added support scripts for gateway inspection and SSL verification

New Ruby scripts in lib/support enable programmatic inspection of payment gateways and verification of their SSL/TLS configurations. GatewaySupport enumerates all available gateways and their supported actions, while OutboundHosts scans the codebase to list external hosts contacted by gateways. SSLVerify checks that each gateway's live URL presents a valid SSL certificate, and SSLVersion tests whether each gateway supports a minimum TLS version (defaulting to TLS 1.1). These tools provide a way to audit gateway capabilities and security posture directly from the codebase.

lib/support · high confidence

Introduces structured result objects for AVS and CVV checks

The library now uses dedicated \AVSResult\ and \CVVResult\ classes to represent Address Verification System and Card Verification Value check outcomes. These objects encapsulate the raw response codes and human-readable messages, and are exposed via the \Response\ object's \avs\_result\ and \cvv\_result\ attributes. This change replaces the previous approach of returning raw strings or hashes, providing a more robust and consistent way to inspect verification statuses.

_lib/active\merchant/billing · high confidence

Refactored HTTP connection handling and added country code support

The library has been refactored to use a new, dedicated \Connection\ class for managing HTTP/HTTPS requests, introducing support for proxy configuration (address, port, user, password) and configurable SSL/TLS versions (min/max). Additionally, a new \Country\ class has been added to provide structured access to ISO 3166-1 country codes (alpha2, alpha3, and numeric), enabling more robust country validation and formatting in payment flows.

_lib/active\merchant · high confidence

Removals

Nochex integration removed from ActiveMerchant

The Nochex payment integration, including its helper and notification classes, has been removed from the ActiveMerchant library. This change eliminates the ability to process payments via the Nochex gateway.

_lib/active\merchant/billing/integrations/nochex · high confidence

Removal of PayPal integration helper and notification classes

The PayPal integration helper and notification classes have been removed from the codebase. This eliminates the built-in support for handling PayPal IPN (Instant Payment Notification) webhooks and generating the necessary form fields for PayPal checkout flows. Users relying on these specific integration classes will need to migrate to alternative payment processing methods.

_lib/active\merchant/billing/integrations/paypal · high confidence

Removed Chronopay integration files

The Chronopay integration helper and notification classes have been removed from the ActiveMerchant billing module. This eliminates the ability to process payments and handle notifications for the Chronopay gateway.

_lib/active\merchant/billing/integrations/chronopay · high confidence

Removed Gestpay integration implementation files

The Gestpay integration files (common.rb, helper.rb, notification.rb) have been deleted from the codebase. This removes the ability to process payments and notifications via the Gestpay payment gateway.

_lib/active\merchant/billing/integrations/gestpay · high confidence

Removed gateway generator templates and scaffolding

The generator templates for creating new payment gateways (including the Ruby generator class and associated template files for unit and remote tests) have been removed from the codebase. This eliminates the automated scaffolding tool used to generate new gateway implementations, meaning developers must now create new gateways manually or via other means.

script/generator/generators/gateway · high confidence

Removed legacy script/generator scripts

The legacy generator scripts in the script/generator directory (base.rb, generator.rb, and manifest.rb) have been removed. This eliminates the 'script/generate' command-line tool used for generating payment gateways and integrations, indicating a shift away from this code generation workflow.

script/generator · high confidence

Removed offsite payment integrations from the main library

The \lib/active\_merchant/billing/integrations\ directory has been removed, deleting the \ActionViewHelper\ and all individual integration modules (such as PayPal, Nochex, and others). This change extracts the offsite payment integrations into a separate \offsite\_payments\ gem, meaning users must now depend on that external gem to use these features.

_lib/active\merchant/billing/integrations · high confidence

Removed the CIA build notification rake task

The Rake task responsible for monitoring the Subversion repository and sending email notifications about build failures has been removed. This eliminates the automatic email alerts for broken builds.

lib/tasks · high confidence

Security

Upgrade rexml to 3.3.8 to fix [CVE redacted]

The rexml gem has been upgraded to version 3.3.8 to address the security vulnerability [CVE redacted], ensuring the library is protected against the identified XML processing issue.

(repo-wide) · high confidence

Behavioural changes

Add Gemfiles for testing against multiple Rails and ActiveSupport versions

The project now includes dedicated Gemfiles for testing compatibility with specific versions of the Rails framework and the ActiveSupport library. New files have been added to the gemfiles directory to pin activesupport versions 4.2.0, 5.0.0, 5.1.0, 5.2.0, 6.0.0, and 7.2.1, each evaluating the main Gemfile to ensure the library functions correctly across these different environments.

gemfiles · medium confidence

Added support for additional currencies and soft descriptors in the Orbital gateway

The Orbital gateway now supports a significantly expanded list of currencies, with new ISO codes and their corresponding numeric codes added to \orbital\_codes.rb\. Additionally, a new \OrbitalSoftDescriptors\ class has been introduced to handle merchant name, city, phone, URL, and email for Chase Paymentech Canada customers, including validation for phone number formats and field length limits.

_lib/active\merchant/billing/gateways/orbital · high confidence

Braintree gateway refactored with shared common logic and new token nonce implementation

The Braintree gateway implementation has been restructured to extract shared configuration and scrubbing logic into a new \BraintreeCommon\ module, which defines supported countries, card types (including Diners Club and Maestro), and sensitive data filtering rules. Additionally, a new \TokenNonce\ class has been introduced to handle the creation of credit card and bank account (ACH) nonces via Braintree's GraphQL API, supporting both credit card and ACH payment methods with proper address and mandate handling.

_lib/active\merchant/billing/gateways/braintree · high confidence

Extensive updates to payment gateway implementations

This change introduces a wide range of updates across multiple payment gateways, including the addition of new gateways (e.g., HiPay, Global Transport, Rapyd, and others), support for new features such as 3D Secure 2, network tokenization, and Apple/Google Pay, as well as numerous bug fixes, deprecations, and API version updates. Specific gateways like Adyen, Worldpay, CyberSource, and Stripe have received significant updates to their functionality and supported fields.

_lib/active\merchant/billing/gateways · high confidence

Introduce Thor-based gateway generator

The gateway generator has been rewritten to use Thor instead of the previous Rubigen-based implementation. This change updates the generator's internal structure and templates, ensuring that newly generated gateways include a verify method, error code handling, and transcript scrubbing support.

generators · high confidence

Introduce recurring payments and EFT/ACH support for Beanstream

The Beanstream gateway now supports recurring payments, allowing users to set up and manage subscription-based transactions. Additionally, the gateway adds support for EFT/ACH and Interac Online payments, expanding the range of payment methods available to users. The implementation includes mapping ISO province codes for US and CA, sending customer IP for fraud management, and handling secure profiles.

_lib/active\merchant/billing/gateways/beanstream · high confidence

Modernizes ActiveMerchant's core loading and deprecation handling

ActiveMerchant now explicitly requires specific ActiveSupport extensions and standard library modules (such as base64, securerandom, and timeout) rather than relying on implicit or gem-based loading. The library also introduces a centralized deprecation warning system that logs messages via a logger or standard output, and enforces I18n locale availability.

lib · high confidence

PayPal: Deprecate recurring billing and add new API capabilities

The PayPal gateway has deprecated the recurring billing functionality (recurring, update\_recurring, cancel\_recurring, etc.), which will now emit deprecation warnings. The gateway also adds support for new PayPal API features, including mass payments (transfer), full and partial refunds, reauthorization, and the GetTransactionDetails/GetBalance/DoAuthorization/ManagePendingTransactionStatus/RequestDetails wrapping. Additionally, the response object now exposes the checkout status, contact phone number, and note field, while the common API now supports API signatures and updated API versions.

_lib/active\merchant/billing/gateways/paypal · high confidence

Payflow gateway refactored to support NVP and recurring billing

The Payflow gateway implementation was refactored to support the PayPal NVP protocol, enabling safe retries for connection failures and allowing separate vendor and user credentials. A new PayflowResponse class was introduced to expose the profile ID and payment history, while the PayflowExpressResponse was updated to include phone number, full name, and shipping address details. The change also adds support for recurring billing transactions and introduces a verbosity option for requests.

_lib/active\merchant/billing/gateways/payflow · high confidence

Refactored script/generate to use Thor instead of Rubigen

The script/generate command-line tool has been rewritten to use the Thor library instead of the previous Rubigen-based implementation. This change updates the underlying framework for generating code (such as new gateways), which may affect how the script is invoked or how generators are loaded, but provides a more modern and consistent command-line interface.

script · high confidence

Removal of integration generator templates

The integration generator templates (including helper, notification, and module test templates) have been removed from the project. This change eliminates the scaffolding used to generate integration payment processor templates, indicating a shift away from this code generation approach.

script/generator/generators/integration · high confidence

Removed example reference file

The example reference file tc\_example.rb, which demonstrated usage of the ActiveMerchant library for Trust Commerce, has been removed from the references directory.

references · high confidence

Removed legacy ActiveMerchant modules

Deleted the Country, PostsData, RequiresParameters, and Validateable modules from lib/active\_merchant/lib. This removes the country code validation, the low-level HTTP POST helper, the parameter validation helper, and the validation/error-handling mixin that previously supported credit card and other gateway objects.

_lib/active\merchant/lib · high confidence

Updated root certificate bundle

The \lib/certs/cacert.pem\ file has been updated to include additional root certificates, specifically adding support for DigiCert, Wirecard, Barclays, and other authorities to improve SSL/TLS verification for gateways using \ssl\_post\.

lib/certs · medium confidence

Test coverage

Add unit tests for gateways in test/unit/gateways; Added CyberSource XSD schema validation files for versions 1.121, 1.153, 1.155, 1.156, and 1.164; Added PayPal XSD schema files for XML validation; Added XSD schema files for Orbital request types PTI77, PTI83, and PTI95; Added XSD schemas for FirstData E4 gateway versions 11 and 27; Added unit tests for PayPal gateway common API; Added unit tests for core payment and connection components; Expanded remote test coverage across numerous payment gateways; Modernize test infrastructure with new stubbing and assertion helpers; Removed integration helper tests for Bogus, Chronopay, Gestpay, Nochex, and PayPal; Removed integration notification tests for Chronopay, Gestpay, Nochex, PayPal, and the base Notification class; Removed obsolete integration tests; Removed remote tests for multiple payment gateways.

Dependencies

Modernize Ruby and dependency configuration

The project now requires Ruby 3.1 or higher and enforces pessimistic versioning on core dependencies like activesupport (\>= 4.2), builder, i18n, nokogiri, and rexml. A new Gemfile explicitly lists optional test and remote-test dependencies (such as braintree, concurrent-ruby, and mocha) to keep them out of the main gemspec, while development dependencies like pry and test-unit are also explicitly declared.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 32 → 62 (+29.6)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 92 → 82 (-10.6)
  • Architecture 94 → 66 (-28.4)
  • Maturity 61 → 55 (-5.5)
  • Readiness 27 → 67 (+40.0)
  • Security 11 → 68 (+57.8)

Resolved (33)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • Duplicated block (10 lines × 2) (lib/active_merchant/billing/gateways/mit.rb)
  • Duplicated block (10 lines × 2) (lib/active_merchant/billing/gateways/netbanx.rb)
  • Duplicated block (10 lines × 4) (lib/active_merchant/billing/gateways/authorize_net_cim.rb)
  • Duplicated block (5 lines × 2) (lib/active_merchant/billing/gateways/jetpay.rb)
  • Duplicated block (6 lines × 2) (lib/active_merchant/billing/gateways/jetpay_v2.rb)
  • Duplicated block (6 lines × 2) (lib/active_merchant/billing/gateways/payu_latam.rb)
  • Duplicated block (7 lines × 2) (lib/active_merchant/billing/gateways/itransact.rb)
  • Duplicated block (7 lines × 2) (lib/active_merchant/billing/gateways/mastercard.rb)
  • Duplicated block (8 lines × 2) (lib/active_merchant/billing/gateways/global_collect.rb)
  • Duplicated block (8 lines × 2) (lib/active_merchant/billing/gateways/simetrik.rb)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • …and 13 more

New (468)

  • AdyenGateway.add_3ds (cognitive 18) (lib/active_merchant/billing/gateways/adyen.rb)
  • AdyenGateway.add_extra_data (cognitive 16) (lib/active_merchant/billing/gateways/adyen.rb)
  • AdyenGateway.add_extra_data (cyclomatic 17) (lib/active_merchant/billing/gateways/adyen.rb)
  • AuthorizeNetCimGateway.add_transaction (cognitive 20) (lib/active_merchant/billing/gateways/authorize_net_cim.rb)
  • AuthorizeNetGateway.parse_cim (cognitive 20) (lib/active_merchant/billing/gateways/authorize_net.rb)
  • AuthorizeNetGateway.parse_normal (cognitive 34) (lib/active_merchant/billing/gateways/authorize_net.rb)
  • AuthorizeNetGateway.parse_normal (cyclomatic 24) (lib/active_merchant/billing/gateways/authorize_net.rb)
  • BraintreeBlueGateway.verify (cognitive 18) (lib/active_merchant/billing/gateways/braintree_blue.rb)
  • CardConnectGateway.add_address (cognitive 16) (lib/active_merchant/billing/gateways/card_connect.rb)
  • CheckoutV2Gateway.add_3ds (cognitive 20) (lib/active_merchant/billing/gateways/checkout_v2.rb)
  • CheckoutV2Gateway.add_customer_data (cognitive 16) (lib/active_merchant/billing/gateways/checkout_v2.rb)
  • CheckoutV2Gateway.add_payment_method (cognitive 44) (lib/active_merchant/billing/gateways/checkout_v2.rb)
  • CheckoutV2Gateway.add_payment_method (cyclomatic 21) (lib/active_merchant/billing/gateways/checkout_v2.rb)
  • CheckoutV2Gateway.add_payment_sender_data (cognitive 30) (lib/active_merchant/billing/gateways/checkout_v2.rb)
  • CheckoutV2Gateway.add_payment_sender_data (cyclomatic 22) (lib/active_merchant/billing/gateways/checkout_v2.rb)
  • CheckoutV2Gateway.add_payout_destination_data (cognitive 25) (lib/active_merchant/billing/gateways/checkout_v2.rb)
  • CheckoutV2Gateway.add_payout_destination_data (cyclomatic 20) (lib/active_merchant/billing/gateways/checkout_v2.rb)
  • CheckoutV2Gateway.add_recipient_data (cognitive 21) (lib/active_merchant/billing/gateways/checkout_v2.rb)
  • CheckoutV2Gateway.add_recipient_data (cyclomatic 16) (lib/active_merchant/billing/gateways/checkout_v2.rb)
  • ConektaGateway.add_address (cognitive 16) (lib/active_merchant/billing/gateways/conekta.rb)
  • …and 448 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

activemerchant/active_merchant was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit ca45b1b063ce2e1495e1427e0a1d42dcb482d57d — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-7c1cb6328e11.