Skip to content
CAI
Software that uses CAICheck a score

alexander-schranz/hexagonal-architecture-study

61.0

Adequate · 21 September 2026

6.4k

lines of production code

PHP

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Add CakePHP framework support

Added a new CakePHP 4.x application skeleton to the frameworks directory, including configuration files (app.php, bootstrap.php), CLI tools (bin/cake), routing, middleware setup, and CI/CD workflows, enabling users to scaffold and run CakePHP applications.

frameworks · high confidence

Introduce event management capabilities with message handlers and repository abstractions

Users can now create, modify, and remove events through dedicated message handlers (CreateEventMessageHandler, ModifyEventMessageHandler, RemoveEventMessageHandler) that process application messages. The change adds domain models (Event, EventTranslation) and their interfaces, along with an in-memory repository implementation (InMemoryEventRepository) that supports filtering, sorting, and pagination. Additionally, the diff introduces infrastructure for both Cycle ORM and Doctrine ORM, including entity schemas, repository implementations, and XML mapping files, enabling persistence via either ORM. The system also includes a data mapper interface and implementation for transforming data into event models.

src/event · high confidence

Dependencies

Add PHP framework and ORM integrations

Added dependency manifests for CakePHP, Laminas, Laravel, and Symfony, establishing the base PHP framework support. Additionally, introduced a new event library and its Doctrine and Cycle ORM infrastructure bridges to enable event handling across these frameworks.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 67 → 61 (-5.7)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 99 (+0.3)
  • Architecture 100 → 86 (-13.7)
  • Maturity 70 → 64 (-5.1)
  • Readiness 60 → 60 (+0.0)
  • Security 62 → 76 (+14.2)
  • Accessibility 54 (new)

Resolved (39)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (frameworks/cake/composer.lock)
  • Critical CVE: [GHSA redacted] (frameworks/cake/composer.lock)
  • Dependency hygiene not measured — no supported dependency manifest was read
  • Duplicated block (14 lines × 2) (src/event/src/Domain/Exception/EventNotFoundException.php)
  • High CVE: [GHSA redacted] (frameworks/laravel/composer.lock)
  • High CVE: [GHSA redacted] (frameworks/laravel/composer.lock)
  • High CVE: [GHSA redacted] (frameworks/cake/composer.lock)
  • High CVE: [GHSA redacted] (frameworks/laravel/composer.lock)
  • High CVE: [GHSA redacted] (frameworks/cake/composer.lock)
  • High CVE: [GHSA redacted] (frameworks/cake/composer.lock)
  • High CVE: [GHSA redacted] (frameworks/cake/composer.lock)
  • High IaC: DS-0029 (frameworks/laminas/Dockerfile)
  • High vulnerability: [GHSA redacted] (frameworks/laravel/composer.lock)
  • High vulnerability: [GHSA redacted] (frameworks/laravel/composer.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 19 more

New (33)

  • Coverage not measured — no coverage collector is wired up
  • Critical CVE: [GHSA redacted] (frameworks/cake/composer.lock)
  • Critical CVE: [GHSA redacted] (frameworks/cake/composer.lock)
  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no committed lockfile, so no resolved version to grade)
  • Documentation: no installation or build instructions (README.md)
  • Duplicated block (13–14 lines × 2) (src/event/src/Domain/Exception/EventNotFoundException.php)
  • High CVE: [GHSA redacted] (frameworks/laravel/composer.lock)
  • High CVE: [GHSA redacted] (frameworks/laravel/composer.lock)
  • High CVE: [GHSA redacted] (frameworks/laravel/composer.lock)
  • High CVE: [GHSA redacted] (frameworks/cake/composer.lock)
  • High CVE: [GHSA redacted] (frameworks/laravel/composer.lock)
  • High CVE: [GHSA redacted] (frameworks/cake/composer.lock)
  • High CVE: [GHSA redacted] (frameworks/laravel/composer.lock)
  • High CVE: [GHSA redacted] (frameworks/cake/composer.lock)
  • High CVE: [GHSA redacted] (frameworks/cake/composer.lock)
  • High CVE: [GHSA redacted] (frameworks/cake/composer.lock)
  • High IaC: DS-0029 (frameworks/laminas/Dockerfile)
  • High IaC: DS-0029 (frameworks/laminas/Dockerfile)
  • High IaC: WD-DOCKER-0001 (frameworks/laminas/Dockerfile)
  • Low CVE: [GHSA redacted] (frameworks/laravel/composer.lock)
  • …and 13 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

alexander-schranz/hexagonal-architecture-study was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit e0b6cd46085e0cb548d02e648ad6d86255e9c301 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.