Anankke/SSPanel-UIM
69.5
Adequate · 26 September 2026
20.7k
lines of production code
PHP
primary language
4
measurements over time
What this system is
This system is a self-hosted network service management platform, likely for VPN or proxy providers, built on PHP 8.2 and the Slim 4 framework. It provides a comprehensive administrative interface for managing users, nodes, products, and billing, while supporting multiple payment gateways and subscription protocols like V2Ray and Sing-Box. The application features a modern, responsive user dashboard for account management and order processing, alongside CLI tools for system maintenance and automated tasks.
How it got here
2018–2019 — Slim 4 migration and architectural modernization
17 changes.
The project underwent a significant architectural overhaul by migrating the application entry point and controllers to the Slim 4 framework, replacing the legacy Smarty engine with Twig for templating. This period established a modern, modular codebase featuring a dedicated service layer, comprehensive CLI tools, and robust middleware for authentication and security. It also introduced extensive administrative features, including a new shop system, gift cards, and detailed logging, while standardizing utility functions and dependency management.
2020–2022 — Tabler UI migration and feature expansion
14 changes.
This period focused on migrating the entire application interface to the Tabler theme, enhancing user experience with HTMX for asynchronous interactions and modernizing admin and user panels. Concurrently, significant backend features were added, including a restructured payment gateway architecture supporting multiple providers and new user-facing controllers for billing, orders, and multi-factor authentication.
2023 — Admin panel and modular service architecture
15 changes.
This period focused on rebuilding the admin interface with dedicated management views for products, orders, invoices, and system settings, alongside a comprehensive database schema overhaul. It also involved refactoring core backend services, including the subscription generator, Telegram bot, and instant messaging layer, into modular, maintainable structures.
2024–2026 — Feature expansion and test infrastructure
9 changes.
This period focused on implementing new administrative and payment features, including a multi-provider CAPTCHA system, a Cryptomus payment gateway, and a localized admin syslog interface. Concurrently, significant effort was dedicated to establishing a robust testing foundation, adding comprehensive unit, integration, and API tests to ensure the reliability of core services and new functionalities.
Features
Add Cryptomus payment gateway integration
Introduces a new Cryptomus payment gateway service, including the core Payment class for handling payment operations (create, info, history, balance, etc.), a RequestBuilder for managing API communication with the Cryptomus endpoint, and a custom exception class for error handling.
src/Services/Gateway/Cryptomus · high confidence
Initial repository structure and documentation
The repository is initialized with core project files including a comprehensive README, a MIT license, a security policy, and a contributing guide. It introduces the \xcat\ CLI entry point for executing application commands and an \update.sh\ script to manage version upgrades (master, release, and nogit modes). The setup includes a PHPUnit configuration for unit, feature, and integration tests, a PHPInsights configuration for code quality enforcement, and a \.gitignore\ file to exclude environment, vendor, and build artifacts.
(repo-wide) · high confidence
Introduces new utility classes for class loading, cookies, hashing, and responses
The src/Utils directory now includes several new helper classes: ClassHelper for retrieving classes by namespace from the Composer autoloader, Cookie for setting and getting secure cookies, Hash for handling password hashing (supporting bcrypt, argon2i, argon2id, sha256, and sha3) and cookie/IP/device hashing, and ResponseHelper for standardizing API JSON responses with optional ETag support. These utilities provide a centralized and consistent way to handle common tasks across the application.
src/Utils · high confidence
Introduces new xcat command-line tools for client updates, database migrations, and scheduled tasks
The \src/Command\ directory now contains a suite of new CLI commands (\ClientDownload\, \Cron\, \Migration\, \Test\, \Tool\, \Update\) that replace previous ad-hoc scripts. \ClientDownload\ handles client binary updates with strict user-ownership checks, \Migration\ manages database schema versions via a new \MigrationInterface\, \Cron\ centralizes scheduled jobs (orders, traffic, finance), and \Tool\ provides administrative utilities like password resets and GeoIP updates.
src/Command · high confidence
Introduction of modular service layer for analytics, authentication, and system bootstrapping
The application now utilizes a dedicated service layer in src/Services to centralize core logic. This includes an Analytics service for retrieving system statistics (income, user counts, traffic usage), an Auth service that delegates login/logout operations to a pluggable driver (currently Cookie), and a Boot service for initializing the database connection (supporting MariaDB with optional read/write splitting), setting the timezone, and configuring Sentry error reporting. Additionally, new services handle Redis caching, multi-provider CAPTCHA verification (Turnstile, GeeTest, hCaptcha, reCAPTCHA Enterprise), Cloudflare R2 storage, and unified LLM backend integration (OpenAI, Anthropic, Google AI, Vertex AI, etc.).
src/Services · high confidence
New Epay gateway implementation with configurable signing
Added the Epay payment gateway integration, introducing three new classes: EpayNotify for verifying incoming payment notifications, EpaySubmit for constructing and submitting payment requests via HTML forms, and EpayTool for shared utility functions like parameter filtering, sorting, and string linking. The implementation uses the configured 'epay\_sign\_type' (defaulting to SHA256 based on commit context) for signing and verifying payment data, ensuring secure transaction handling.
src/Services/Gateway/Epay · high confidence
New Telegram bot commands for user interaction and account management
This change introduces a new set of Telegram bot commands in the \src/Services/Bot/Telegram/Commands\ directory, enabling users to interact with the service via Telegram. The new commands include \/checkin\ for daily check-ins and reward issuance, \/dc\ to retrieve the user's Telegram Data Center location, \/help\ to list available commands, \/menu\ for a personal center interface, \/my\ to view user profile and traffic info, \/ping\ to display user and group IDs, \/start\ for initial bot interaction, and \/unbind\ to disconnect the Telegram account from the service. These commands handle various user states, including group vs. private chat contexts, and integrate with existing configuration and reward services.
src/Services/Bot/Telegram/Commands · high confidence
New WebAPI controllers for node, user, and function endpoints
Added new controller classes (FuncController, NodeController, UserController) in src/Controllers/WebAPI to handle specific API routes. FuncController exposes a ping check and detect rules retrieval. NodeController provides node info with backward-compatible version format conversion (YY.M.P to YYYY.M.P) and checks node enablement status. UserController manages user listing with complex filtering based on node class/group, bandwidth limits, IP limits, and traffic usage, including support for SS2022 user key generation and dynamic traffic rate calculation. These controllers replace previous implementations and standardize the WebAPI response format using ResponseHelper.
src/Controllers/WebAPI · high confidence
New admin UI pages for coupons, gift cards, and audit rules
The admin interface now includes dedicated management pages for coupons, gift cards, and audit rules. These new views (coupon.tpl, giftcard.tpl, detect.tpl) provide a unified Tabler-based layout with data tables and modal dialogs for creating, deleting, and managing these resources. The coupon page specifically adds support for setting expiration times using the Flatpickr date picker. These pages rely on the newly introduced admin header and footer templates, which standardize the layout, navigation, and modal feedback system across the admin area.
resources/views/tabler/admin · high confidence
New admin log views for audit, gateway, login, money, online, payback, and subscription records
The admin interface now includes dedicated Tabler-themed pages for viewing various system logs. New templates have been added for audit collision records (detect), audit bans, gateway payment logs, user login history, balance/money logs, current online IPs, payback/referral logs, and subscription records. Each page renders a server-side DataTable that fetches data via specific AJAX endpoints (e.g., /admin/detect/log/ajax, /admin/gateway/ajax, /admin/login/ajax, /admin/money/ajax, /admin/online/ajax, /admin/payback/ajax, /admin/subscribe/ajax), allowing administrators to inspect these operational details in a consistent UI.
resources/views/tabler/admin/log · high confidence
New admin management pages for orders, invoices, coupons, gift cards, and system logs
The admin panel now includes dedicated controllers and UI pages for managing orders, invoices, gift cards, and coupons, as well as viewing system logs. Administrators can now view and cancel orders (with automatic refunds for paid invoices), view invoice details, and manually mark invoices as paid. A new coupon system allows creating discount codes with limits on usage, expiration, and user eligibility. Gift cards can be generated with custom values and lengths. Additionally, new log pages provide visibility into user activity, including detection/ban logs, detection rules, login history, online status, and money balance changes.
src/Controllers/Admin · high confidence
New admin order management interface
Administrators now have dedicated views to manage customer orders. The new order index page provides a searchable list of orders with options to delete or cancel them (including automatic refunds to user balance upon cancellation). The order view page displays detailed order information, including product specifics (such as duration, bandwidth, and IP limits), associated invoice content, and links to the related user and invoice records.
resources/views/tabler/admin/invoice, resources/views/tabler/admin/order · high confidence
New admin product management interface with dynamic form fields
The admin panel now includes a dedicated product management section with a list view, creation form, and edit form. The create and edit forms feature a product type selector (Time & Bandwidth, Time-only, or Bandwidth-only) that dynamically shows or hides specific configuration fields such as duration, class, bandwidth amount, node group, speed limit, and IP limit, while also updating required field validation accordingly. The list view displays products in a data table with options to delete or copy existing products.
resources/views/tabler/admin/product · high confidence
New admin setting controllers for modular configuration management
This change introduces a set of new admin controllers (Billing, Captcha, Cron, Email, Feature, IM, LLM, Ref, Reg, Sub, Support) that replace the previous monolithic approach to managing application settings. Each controller now handles a specific configuration domain (e.g., payment gateways, email services, instant messaging, subscription settings) by fetching settings from the database via the Config model and rendering dedicated admin templates. This modularization allows administrators to configure distinct system areas independently, with specific controllers like Billing and IM providing specialized actions for managing webhooks and testing integrations.
src/Controllers/Admin/Setting · high confidence
New admin syslog feature with multi-language support
Administrators can now view system logs through a new dedicated interface. This includes a list view for browsing log entries and a detail view showing specific information such as the triggering user, IP address, message content, log level, and channel. The backend service captures application logs and stores them in the database for retrieval. Additionally, the system now supports localized messages for bot notifications in English, Japanese, Simplified Chinese, and Traditional Chinese, covering events like node status changes, user join welcomes, and order creation.
resources/locale, resources/views/tabler/admin/syslog, src/Services/SysLog · high confidence
New and updated payment gateway UI templates
The payment interface now includes dedicated view templates for Cryptomus, EPay (supporting Alipay, WeChat, QQ, and USDT), PayPal, Stripe, and two Alipay Face-to-Face implementations (f2f and smogate). These templates provide the specific frontend logic and styling required for each provider, such as QR code generation for Alipay, PayPal SDK integration, and HX-based submission for Cryptomus and Stripe.
resources/views/tabler/gateway · high confidence
New audit rules and logs pages for users
Added new user-facing pages to view audit rules and audit logs. The audit rules page displays a table of rules with their ID, name, description, regex, and type (plaintext or hex matching). The audit logs page shows a table of detected events including event ID, node details, rule details, and timestamp.
resources/views/tabler/user/detect · high confidence
New client configuration service for dynamic client data retrieval
A new ClientConfig service has been introduced to manage client display information. This service reads client definitions from a JSON configuration file (config/client\_display.json) and provides a method to retrieve structured client data, including platform-specific details, descriptions, import URLs, and download URLs. The implementation includes caching of the configuration in memory and robust error handling for file access and JSON parsing issues.
src/Services/Config · high confidence
New configuration and client definition files introduced
The config directory now includes several new example and definition files: \.config.example.php\ provides a comprehensive template for environment variables including database, Redis, rate limiting, and DNS settings; \appprofile.example.php\ defines default V2Ray and Sing-Box configuration profiles; \client\_display.json\ and \clients.json\ specify supported client applications (such as Clash Verge Rev, FlClash, Hiddify, and Sing-Box) with their download sources and platform support; and \settings.json\ introduces a structured JSON-based configuration system for billing and payment gateways (including Stripe and Epay).
config · high confidence
New data models for announcements, configuration, and security features
The application now includes dedicated database models for managing system announcements (Ann), a centralized configuration store (Config), and security-related logs (LoginIp, DetectBanLog, DetectLog, DetectRule). Additionally, new models support multi-factor authentication (MFADevice), user activity tracking (OnlineLog, SubscribeLog), and financial operations (Invoice, Payback, UserMoneyLog, Order, Product, UserCoupon, GiftCard). These models provide the underlying data structure for features such as login notifications, subscription alerts, and the new shop/gift card system.
anankke/sspanel-uim · high confidence
New instant messaging service layer with Discord, Slack, and Telegram support
The application now includes a new \IM\ service layer that enables sending messages to external platforms. This update introduces concrete implementations for Discord (sending DMs via API v10), Slack (posting to channels), and Telegram (supporting MarkdownV2, HTML, and group member management). These services share a common abstract base class and retrieve their respective authentication tokens from the application configuration.
src/Services/IM · high confidence
New mail service drivers added
The mail service layer now supports sending emails via Alibaba Cloud DM, Mailchimp, Mailgun, Postal, Postmark, Resend, and AWS SES, in addition to the existing SendGrid and SMTP providers. A new NullMail driver is also available for environments where email sending should be disabled. Each driver implements the Base interface and retrieves its specific configuration from the email config class.
src/Services/Mail · high confidence
New payment gateways and gateway architecture
The payment service layer has been restructured with a new abstract Base class and introduces support for Alipay F2F, Cryptomus, EPay, PayPal, Smogate, and Stripe. Users can now select from these additional payment methods, which handle invoice creation, currency exchange (for Stripe and PayPal), and webhook notifications to update payment status and issue referral rewards.
src/Services/Gateway · high confidence
New user invoice listing and detail pages
Users can now view a paginated list of their invoices and access detailed views for each one. The invoice index page displays a table of billing records, while the view page shows order information, status, and line-item details. For unpaid or partially paid invoices, users can pay using their account balance or available payment gateways directly from the invoice detail page.
resources/views/tabler/user/invoice · high confidence
New user-facing controllers for account, billing, and support features
This change introduces a suite of new controllers in the user area to handle specific user workflows. The MFAController adds support for registering and managing multi-factor authentication devices (TOTP, FIDO, and WebAuthn). The InvoiceController and MoneyController enable users to view invoices, pay them using account balance, and apply gift cards. The OrderController and CouponController allow users to create orders and validate coupon codes with usage limits. Additionally, the ClientController provides direct download links for various client applications (such as Clash, FlClash, and Hiddify) via Cloudflare R2, while the TicketController, DocsController, and DetectLogController handle support tickets, documentation access (with optional paid-user restrictions), and security detection logs respectively.
src/Controllers/User · high confidence
New user-facing order management pages
Added three new templates for the user order workflow: a list view (index) that displays orders in a DataTable with AJAX loading, a creation view (create) that shows product details (including type-specific attributes like duration, bandwidth, and limits) and allows applying coupon codes via HTMX, and a detail view (view) that presents order metadata, product content, and associated invoice information.
resources/views/tabler/user/order · high confidence
New user-facing ticket system with HTMX-powered interactions
Users can now create and manage support tickets directly from the user dashboard. The new ticket index page displays a list of existing tickets with status indicators, while the ticket detail view allows users to add replies. Both the ticket creation and reply submission processes use HTMX for asynchronous, non-page-reload interactions, providing a smoother user experience.
resources/views/tabler/user/ticket · high confidence
Support for multiple CAPTCHA providers with automatic refresh
The CAPTCHA view components now support Turnstile, GeeTest, hCaptcha, and reCAPTCHA Enterprise, rendering the appropriate widget and loading the corresponding JavaScript SDK for each provider. Additionally, the system automatically refreshes the CAPTCHA challenge after successful form submissions via htmx events, improving usability by preventing stale validation tokens.
resources/views/tabler/captcha · high confidence
Behavioural changes
Added GeoLite2 database files and Twig cache directories
The storage area now includes the MaxMind GeoLite2 City and Country database files (dated 2025-07-04) along with their respective copyright and license notices, enabling IP-based geolocation features. Additionally, new cache directories for the Twig templating engine have been created under storage/framework/twig/cache to support the recently added Twig view service.
storage · high confidence
Added placeholder for Tabler theme directory
A .gitkeep file has been added to the public/theme/tabler directory to ensure the folder is tracked in version control, likely serving as a placeholder for future theme assets or configuration.
public/theme · medium confidence
Added script to detect and redirect 360 Browser users to Firefox
A new JavaScript file (fuck.js) and its minified version have been added to the public assets. This script detects if the user is accessing the site via the 360 Browser by checking user-agent strings, MIME types, and specific browser behaviors. If detected, it displays an alert message informing the user that 360 Browser is being used and automatically redirects them to the official Firefox download page.
public/assets · high confidence
Admin ticket interface migrated to Tabler theme with HTMX and Bootstrap 5
The admin ticket management views (index and view pages) have been rewritten to use the Tabler UI theme, replacing the previous layout. The ticket list now utilizes a DataTables component for sorting and pagination, while the ticket detail view has been updated to use Bootstrap 5 modal dialogs for actions like replying and closing tickets. Additionally, the reply and close actions now leverage HTMX (via hx-post) for asynchronous submission, improving the user experience by avoiding full page reloads.
resources/views/tabler/admin/ticket · high confidence
Admin user management UI migrated to Tabler theme
The admin user interface has been redesigned using the Tabler theme, replacing the previous layout with a modern card-based structure. The user list view now utilizes a DataTable for improved sorting and filtering, while the user creation process is handled via a Bootstrap 5 modal dialog instead of a page redirect. The user edit page has been restructured into distinct sections for account information and usage limits, providing a clearer and more organized experience for administrators managing user accounts.
resources/views/tabler/admin/announcement, resources/views/tabler/admin/user · high confidence
Application entry point migrated to Slim 4
The public entry point (public/index.php) has been rewritten to initialize the application using the Slim 4 framework. This change updates the request handling pipeline to use Guzzle PSR-7 factories for creating server requests and responses, and integrates the new ErrorHandler middleware, replacing the previous bootstrapping logic.
public · high confidence
Cookie authentication now supports device binding
The cookie-based authentication service has been refactored to include a new device-binding feature. When the \enable\_login\_bind\_device\ environment variable is enabled, the system now hashes and stores the user's User-Agent string in the authentication cookie. During subsequent requests, the service validates that the current User-Agent matches the stored hash, rejecting the login if the device context has changed. This adds an extra layer of security by ensuring the session remains tied to the original device.
src/Services/Auth · high confidence
Database schema overhaul and migration updates
The database schema has been significantly updated to support new features and improve data integrity. Key changes include the introduction of dynamic traffic rate configurations for nodes, a new user money log table for tracking balance changes, and an online log table that tracks user activity per IP address. The schema also adds support for invoice IDs in payment records, coupon usage limits, and user inactivity detection. Several deprecated columns and tables have been removed, and data types across multiple tables (such as user, node, and order) have been optimized for better performance and consistency.
db · high confidence
HTMX-powered password reset and token views
The password reset and token setting pages have been rewritten to use HTMX for asynchronous interactions. The reset flow now submits the email and optional captcha via HTMX, and the token page submits the new password confirmation via HTMX, replacing previous page-refresh or standard form submission behaviors. The UI has also been updated to use the Tabler theme with the new logo and text-secondary styling.
resources/views/tabler/password · high confidence
New Slim 4 middleware pipeline for authentication and access control
The application has migrated to Slim 4, introducing a new set of middleware classes in src/Middleware to handle request processing. The Admin middleware now enforces admin-only access by redirecting non-admins to the user dashboard, while the Guest middleware redirects logged-in users away from authentication pages. The User middleware manages session state, redirecting unauthenticated users to login (with optional return-path preservation for order creation) and restricting access for banned users. The NodeToken middleware secures the Node API by validating request keys, enforcing IP-based rate limits via Redis, verifying the web API URL, and optionally checking the node's IP address against the database. Additionally, the ErrorHandler middleware has been updated to integrate with Sentry for error reporting and to serve custom error templates for 404 and 500 errors.
src/Middleware · high confidence
New Slim 4-based controller architecture with Twig templating
The application has migrated from the legacy Smarty view engine to Twig, introducing a new Slim 4 controller structure. This change brings a new BaseController that initializes both Smarty and Twig engines, though the new controllers primarily utilize Twig for rendering. The update includes a complete rewrite of core controllers (Auth, User, Admin, Sub, Password, OAuth, Callback, Home) to support modern features such as multi-factor authentication (TOTP, FIDO, WebAuthn), Telegram/Discord/Slack OAuth integration, and a unified subscription system supporting multiple protocols (Clash, Singbox, V2Ray, etc.).
src/Controllers · high confidence
New Tabler-themed authentication views with WebAuthn support
The login, registration, and multi-factor authentication (MFA) pages have been replaced with new Tabler-themed templates. The login page now supports WebAuthn (FIDO2) login via the SimpleWebAuthn library and uses HTMX for form submissions. The MFA page supports both TOTP and FIDO2 verification methods. The registration page includes email verification code sending and captcha integration, also using HTMX for submission.
resources/views/tabler/auth · high confidence
New Tabler-themed error pages and UI components
The application now includes dedicated Tabler-styled error pages for 404, 405, and 500 status codes, providing consistent visual feedback with localized messages and a home link. Additionally, the view layer introduces a new DataTables component (v2.0.8) for data display, a centralized footer template featuring success/failure modal dialogs powered by HTMX, and a header template that enforces 'noindex' for search engines and supports automatic dark mode based on system preferences.
resources/views/tabler · high confidence
New admin setting pages for billing, email, captcha, cron, and features
The admin interface now includes dedicated configuration pages for billing (gateway selection, Stripe, Alipay F2F, PayPal, Cryptomus, Smogate), email (SMTP, Mailgun, Sendgrid, Postal, AWS SES, Mailchimp, AlibabaCloud DM, Postmark, Resend), captcha (Turnstile, Geetest, hCaptcha, reCAPTCHA Enterprise), cron jobs (daily tasks, finance reports, GFW detection, inactive user detection), and general features (audit logs, documentation visibility, check-in rewards). These new views replace previous settings layouts, providing a structured, tabbed interface for managing these specific system components.
resources/views/tabler/admin/setting · high confidence
Redesigned email templates with modern styling
The email notification templates (including new\_user, password\_reset, verify\_code, finance, traffic\_report, warn, and test) have been updated with a new visual design. The changes introduce a centered, card-based layout with a light gray background, improved typography using the 'Open Sans' font, and adjusted padding for better readability. The footer now includes a link to modify email receiving settings, and the overall appearance is more polished and consistent across all system notifications.
resources/email · high confidence
Redesigned node management interface with dynamic rate and bandwidth controls
The admin node management views (create, edit, and list) have been rewritten using the Tabler theme. Administrators can now configure new node types including TUIC and Shadowsocks2022, and set up dynamic traffic multipliers using either Logistic or Linear calculation methods. The edit page also introduces specific controls for node bandwidth limits, reset days, and a button to reset used bandwidth. Additionally, the node list page now uses a DataTable for better management, and the create/edit forms utilize a JSONEditor for custom configurations.
resources/views/tabler/admin/node · high confidence
Refactored subscription service into modular format-specific classes
The subscription generation logic in src/Services/Subscribe has been restructured from a monolithic implementation into distinct, format-specific classes (Base, Clash, SingBox, V2Ray, V2RayJson, Trojan, SS, SIP002, SIP008, and Json). This change introduces dedicated handlers for each protocol and configuration format, allowing for more granular support of node types such as Shadowsocks 2022, TUIC, and HTTPUpgrade, while ensuring that each format's specific configuration requirements are handled in isolation.
src/Services/Subscribe · high confidence
Release version 25.1.0 "The Restoration"
This update releases version 25.1.0, codenamed "The Restoration". The change introduces the global application constants in app/predefine.php and establishes the new centralized routing configuration in app/routes.php, which defines the HTTP endpoints for the home, authentication, user, payment, and admin sections of the application.
app · high confidence
Telegram bot service refactored into dedicated handler classes
The Telegram bot logic in src/Services/Bot/Telegram has been restructured from a monolithic implementation into distinct, focused classes: Telegram.php now acts as the central entry point processing webhook updates, Callback.php handles inline button interactions, and Message.php manages direct message commands and group events (such as welcome messages and member joins). This change improves code maintainability and prepares the bot service for easier extension with new bot types or features.
src/Services/Bot/Telegram · high confidence
User center interface migrated to Tabler theme
The user-facing pages (index, profile, edit, invite, money, product, etc.) have been completely redesigned using the Tabler UI framework. This update introduces a modern, responsive layout with a dark mode toggle, replaces legacy jQuery interactions with HTMX for seamless, reload-free updates, and adds new features such as a dedicated announcements page, gift card redemption, and balance top-up functionality.
resources/views/tabler/user · high confidence
Test coverage
Added API integration tests for UserController; Added integration tests for WebAuthn compatibility; Added test fixtures for tools and configuration; Added test infrastructure and helpers for the application; Added unit tests for core services and utilities.
Dependencies
Initial dependency manifest and lock file added
The project now includes a composer.json and composer.lock file, establishing the PHP 8.2+ runtime requirements and defining the full set of third-party libraries (such as illuminate/database ^11, slim/slim ^4, and stripe/stripe-php ^20) that the application depends on.
(dependencies) · high confidence
Housekeeping
Added placeholder for public clients directory
A .gitkeep file was added to the public/clients directory to ensure the directory is tracked in version control, likely serving as a placeholder for future client-related assets or configurations.
public/clients · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 49 → 70 (+20.4)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 93 → 89 (-4.4)
- Architecture 96 → 69 (-26.3)
- Maturity 64 → 64 (-0.3)
- Readiness 32 → 72 (+40.2)
- Security 50 → 90 (+39.6)
Resolved (42)
- (anonymous) (cognitive 36) (public/assets/js/fuck.js)
- (anonymous) (cyclomatic 34) (public/assets/js/fuck.js)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- Duplicated block (11 lines × 2) (src/Services/Subscribe/Clash.php)
- Duplicated block (12 lines × 2) (src/Controllers/Admin/TicketController.php)
- Duplicated block (14 lines × 2) (src/Services/Detect.php)
- Duplicated block (15 lines × 2) (src/Services/Captcha.php)
- Duplicated block (15 lines × 2) (src/Services/Cron.php)
- Duplicated block (15 lines × 2) (src/Services/Subscribe/V2RayJson.php)
- Duplicated block (8 lines × 2) (src/Controllers/OAuthController.php)
- Duplicated block (8 lines × 2) (src/Services/Bot/Telegram/Callback.php)
- Duplicated block (8 lines × 2) (src/Services/Subscribe/V2RayJson.php)
- Duplicated block (9 lines × 2) (src/Controllers/Admin/ProductController.php)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 22 more
New (167)
- (anonymous) (cognitive 32) (public/assets/js/fuck.js)
- (anonymous) (cyclomatic 36) (public/assets/js/fuck.js)
- AnnController.add (cognitive 16) (src/Controllers/Admin/AnnController.php)
- AuthController.registerHandle (cognitive 19) (src/Controllers/AuthController.php)
- AuthController.registerHandle (cyclomatic 17) (src/Controllers/AuthController.php)
- Boundary-crossing change coupling: AnnController.php ↔ Detect.php (src/Controllers/Admin/AnnController.php)
- Callback.userCenter (cognitive 16) (src/Services/Bot/Telegram/Callback.php)
- Callback.userEdit (cognitive 26) (src/Services/Bot/Telegram/Callback.php)
- Callback.userEdit (cyclomatic 16) (src/Services/Bot/Telegram/Callback.php)
- Captcha.verify (cognitive 24) (src/Services/Captcha.php)
- Change coupling: AuthController.php ↔ InfoController.php (src/Controllers/AuthController.php)
- Change coupling: AuthController.php ↔ PasswordController.php (src/Controllers/AuthController.php)
- Change coupling: Clash.php ↔ SingBox.php (src/Services/Subscribe/Clash.php)
- Change coupling: Cron.php ↔ Detect.php (src/Services/Cron.php)
- Change coupling: FuncController.php ↔ NodeController.php (src/Controllers/WebAPI/FuncController.php)
- Change coupling: FuncController.php ↔ UserController.php (src/Controllers/WebAPI/FuncController.php)
- Change coupling: InvoiceController.php ↔ OrderController.php (src/Controllers/User/InvoiceController.php)
- Change coupling: PayPal.php ↔ Stripe.php (src/Services/Gateway/PayPal.php)
- Clash.getContent (cognitive 19) (src/Services/Subscribe/Clash.php)
- ClassTooLong: Callback (src/Services/Bot/Telegram/Callback.php)
- …and 147 more
Changes since last survey
- 15 commits — 9 feature/other, 6 fixes
By area
- (root) — 5 commits
- resources/views — 3 commits
- config/appprofile.example.php — 2 commits
- src/Services — 2 commits
- .github/dependabot.yml — 1 commit
- config/.config.example.php — 1 commit
- tests/Unit — 1 commit
Notable commits
- fix: Fix loading of nested locale translation keys (#2585)
- fix: fix(config): apply override_android_vpn only for sing-box Android clients
- fix: fix(gateway/stripe): correct 100x overcharge in checkout amount
- fix: fix: resolve Telegram welcome message translations (#2586)
- fix: fix: skip JSON parsing for HX-Redirect responses (#2584)
- fix: fix: submit cryptomus_currency in billing settings form
- change: Replace jQuery modal calls with Bootstrap 5 dialogs (#2583)
- change: Use a valid default locale in the config example (#2587)
- change: chore(deps): bump aws/aws-sdk-php from 3.371.4 to 3.389.3 (#2570)
- change: chore(deps): bump lcobucci/jwt from 5.5.0 to 5.6.0 (#2590)
- change: chore(deps): bump the composer group across 1 directory with 2 updates (#2588)
- change: chore(deps): bump vectorface/googleauthenticator from 3.4 to 3.5 (#2589)
- change: chore(deps): check composer updates weekly instead of monthly
- change: chore(deps-dev): bump dg/bypass-finals from 1.9.0 to 1.11.0 (#2569)
- change: refactor(config): drop putenv indirection for sing-box UA detection
Architecture
- Containers 0 added · 0 removed · contexts 1 added · 0 removed · edges 0 added · 0 removed
Added bounded contexts (1)
- anankke/sspanel-uim
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
Anankke/SSPanel-UIM was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit c2ab3003cc4bf70237eb6ae82b3c65f31fb1f051 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-a15879f6f801.