Skip to content
CAI
Software that uses CAICheck a score

akondas/flighthub

54.9

Adequate · 21 September 2026

1.7k

lines of production code

PHP

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a flight booking service built on a CQRS and Event Sourcing architecture using the Prooph Event Machine. It manages core domain entities such as flights, seats, and reservations, ensuring data consistency through optimistic concurrency control. The application exposes an API for managing flight data and processing commands, backed by PostgreSQL and RabbitMQ for persistence and messaging.

Features

Add FlightHub infrastructure components for message handling and domain logic

This change introduces a suite of infrastructure classes to support the application's core functionality. It adds HTTP middleware (MessageSchemaMiddleware, OriginalUriMiddleware) to handle message schemas and request routing. It implements domain-specific finders (FlightFinder) and resolvers (HealthCheckResolver) for querying and system health. It also provides service bus components (CommandBus, EventBus, QueryBus, UiExchange) and port implementations (FunctionalPort, OopPort) to bridge the application layer with the Prooph EventMachine runtime, alongside a ServiceFactory to wire these components together.

src/Infrastructure · high confidence

Add Prooph Event Machine skeleton and infrastructure

Introduces the Prooph Event Machine skeleton, including the main application entry point (public/index.php) and CLI scripts for projections and resets. Adds Swagger UI for API documentation, a minified STOMP client for WebSocket communication, and configuration files for RabbitMQ (broker definitions, SSL, and queue/exchange setup) and PostgreSQL (event\_streams and projections tables).

(repo-wide) · high confidence

Initial application configuration and routing setup

The application's configuration structure is established with new files defining the API router, dependency injection container, and environment-specific settings. The API router configures POST endpoints for '/messagebox' and '/messagebox/{message\_name}' as well as a GET endpoint for '/messagebox-schema'. The container configuration wires up core services including the EventStore, ProjectionManager, CommandBus, EventBus, QueryBus, DocumentStore, and OOP Flavour. Global configuration provides defaults for database (PDO), RabbitMQ connection, and event machine descriptions, all of which can be overridden via environment variables or local configuration files.

config · high confidence

Initial release of FlightHub: a CQRS and Event Sourcing based flight booking system

The repository is initialized with the core infrastructure for a flight ticket booking system, including a Docker Compose setup for local development (Postgres, RabbitMQ, PHP/NGINX), a PHP CS Fixer configuration, and a PHPUnit configuration. The project introduces the Prooph Event Machine skeleton, providing a domain model for flights, reservations, and customers, along with an event storming diagram and README documentation.

(repo-wide) · high confidence

Introduce application layer for flight domain with command, query, and event mappings

Added new application-layer classes in src/Application to define the structure of the flight domain. This includes command classes (AddFlight, BlockSeat, ReserveTicket), query classes (FindFlight, FindFlights, HealthCheck), and event classes, along with helper classes (Aggregate, Command, Event, Query, Payload, Schema) that map string identifiers to their respective PHP classes. The FlightDescription class configures the event machine processes for handling commands and recording events, while MessageDescription registers JSON schemas for commands, events, and queries, and sets up projections and resolvers for the flight system.

src/Application · high confidence

Introduce domain model for flight and seat management

Added core domain classes to src/Domain, including the Aggregate base class for event sourcing, the Flight aggregate root, and specific event classes (FlightAdded, SeatBlocked, TicketReserved). The Flight class now supports reserving tickets and blocking seats using an optimistic concurrency check (version number) to prevent race conditions, throwing FlightConcurrencyException if the flight state has changed.

src/Domain · high confidence

Test coverage

Added unit tests for flight domain logic

Added new test files for the Flight domain, including a BaseTestCase helper and specific tests for flight creation, seat reservation, and seat blocking with optimistic locking. The tests verify that flights can be created, that duplicate reservations are prevented, and that concurrent seat blocking attempts are handled correctly.

tests · high confidence

Dependencies

Initial project setup with PHP dependencies

The project was initialized with a Composer configuration (composer.json) and lock file (composer.lock) that establish the application's dependencies. This includes the core framework components (Zend Expressive, PSR-7/15 libraries), the Prooph Event Machine ecosystem (including PDO event store and Postgres document store), and development tools (PHP-CS-Fixer, PHPStan, PHPUnit).

(dependencies) · medium confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 60 → 55 (-4.8)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 99 (+0.1)
  • Architecture 100 → 85 (-15.2)
  • Maturity 61 → 61 (+0.0)
  • Readiness 38 → 33 (-4.9)
  • Security 95 → 87 (-8.6)

Resolved (11)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (composer.lock)
  • High CVE: [GHSA redacted] (composer.lock)
  • Medium CVE: [GHSA redacted] (composer.lock)
  • No exposed public API
  • Test reliability not included
  • early-stage repository — too little history to judge knowledge freshness
  • git history depth insufficient
  • git history depth insufficient
  • single-maintainer — knowledge-concentration (bus factor) risk

New (24)

  • Abandoned package: zendframework/zend-config-aggregator
  • Abandoned package: zendframework/zend-expressive-helpers
  • Abandoned package: zendframework/zend-problem-details
  • Abandoned package: zendframework/zend-stdlib
  • Abandoned package: zendframework/zend-stratigility
  • Coverage not measured — no coverage collector is wired up
  • Documentation: no installation or build instructions (README.md)
  • Duplicated block (24 lines × 2) (src/Application/Command/ReserveTicket.php)
  • Duplicated block (5 lines × 4) (src/Application/Aggregate.php)
  • High CVE: [GHSA redacted] (composer.lock)
  • High CVE: [GHSA redacted] (composer.lock)
  • High IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • Leaked secret: high-entropy-secret (env/rabbit/broker_definitions.json)
  • Medium CVE: [GHSA redacted] (composer.lock)
  • Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • Medium: security finding (details withheld)
  • No ADRs found
  • …and 4 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

akondas/flighthub was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit cbcea5de75183d72a8d6f7be46c1005d11e804d7 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.