Skip to content
CAI
Software that uses CAICheck a score

ankane/pghero

53.1

Adequate · 26 September 2026

3k

lines of production code

Ruby

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

PgHero is a Rails engine that provides comprehensive monitoring and tuning capabilities for PostgreSQL databases. It enables users to track system health, analyze query performance, and manage connections across multiple database instances through a centralized dashboard. The system also offers actionable insights, such as index recommendations and configuration tuning, along with tools for capturing and cleaning up historical statistics.

How it got here

2014 — PgHero 4.0 multi-database overhaul

8 changes.

This period focused on upgrading PgHero to version 4.0, introducing comprehensive multi-database support and a redesigned dashboard with enhanced monitoring capabilities. The work involved significant refactoring of the controller, layout, and library structure to support new security features, configurable settings, and modular SQL logic. Additionally, the project updated its dependencies to require Ruby 3.3 and Rails 7.2, while establishing a new test suite to ensure core reliability.

2015–2016 — modularization and stats infrastructure

6 changes.

This period focused on restructuring PgHero's internal architecture by refactoring methods into modular namespaces and normalizing query statistics into dedicated models. It also introduced Rails generators and Rake tasks to simplify configuration, migration, and data management, while updating frontend dependencies and centralizing CSS styles.

2018–2024 — Rails 8.0 support and test infrastructure

4 changes.

This period focused on extending compatibility to Rails 7.2 and 8.0, supported by the addition of dedicated CI gemfiles and an isolated internal test environment. The work also included refactoring generator templates for normalized query stats and introducing a new home helper to centralize dashboard view logic.

Features

Added generators for configuration and database migrations

New Rails generators have been introduced to simplify the setup of PgHero. Users can now run \rails generate pghero:config\ to create a \config/pghero.yml\ initializer file, and \rails generate pghero:query\_stats\, \pghero:space\_stats\, or \pghero:upgrade\_query\_stats\ to generate the necessary database migrations for tracking query performance, database space usage, and upgrading existing stats tables.

lib/generators/pghero · high confidence

Introduce PgHero home helper with safe identifier quoting and formatted time display

A new \PgHero::HomeHelper\ module has been added to centralize view logic for the home dashboard. It provides \pghero\_pretty\_ident\ to safely format table identifiers by quoting those with special characters, \pghero\_formatted\_vacuum\_times\ to display relative time durations (e.g., "2 hours ago") in a span with a full timestamp title, and \pghero\_formatted\_date\_time\ for long-format date localization. The helper also includes utilities for generating JavaScript-safe values and constructing SQL-like index removal queries.

app/helpers · high confidence

New PgHero Rake tasks for stats management and analysis

Added a new \lib/tasks/pghero.rake\ file that exposes several Rake tasks for managing PgHero data. Users can now capture query and space stats (\pghero:capture\_query\_stats\, \pghero:capture\_space\_stats\), analyze tables with optional minimum size filtering (\pghero:analyze\), autoindex tables (\pghero:autoindex\), and clean up old query or space stats based on a configurable retention period via the \KEEP\_DAYS\ environment variable (\pghero:clean\_query\_stats\, \pghero:clean\_space\_stats\).

lib/tasks · high confidence

Architecture

Refactored PgHero methods into modular namespace

The internal query and monitoring methods have been reorganized from a single monolithic module into distinct, focused modules (Basic, Connections, Constraints, Explain, Indexes, Kill, Maintenance, Queries, QueryStats, Replication, Sequences, Settings, Space, SuggestedIndexes, and System). This structural change improves code maintainability and separation of concerns without altering the external API or user-facing features.

lib/pghero/methods · high confidence

Behavioural changes

Major overhaul of the home controller with new security, authentication, and dashboard features

The home controller has been significantly refactored to support a richer dashboard and improved security posture. Authentication is now configurable via application settings rather than environment variables, and CSRF protection has been updated to raise exceptions. A new Content Security Policy (CSP) override option allows users to customize security headers. The dashboard now displays detailed connection states, replication lag, and autovacuum activity, while also introducing features for suggested indexes, duplicate index detection, and query statistics filtering. Several legacy methods and views have been removed or consolidated to streamline the interface.

app/controllers · high confidence

New application CSS and syntax highlighting styles

The application now uses a new centralized stylesheet (application.css) that establishes the base layout, typography (using system-ui fonts), and component styles. It also introduces syntax highlighting for code blocks via the Arduino Light theme and includes the necessary styles for the noUiSlider component, replacing previous inline or scattered styling approaches.

app/assets/stylesheets · high confidence

PgHero upgraded to version 4.0.1 with enhanced configuration and connection handling

PgHero has been updated to version 4.0.1, introducing significant improvements to how database connections and configurations are managed. The new \Database\ class ensures only one connection pool is created per database by preloading the connection model during initialization, which stabilizes behavior in multi-database setups. Configuration now supports a broader range of options, including specific thresholds for cache hit rates, slow queries, and index bloat, as well as AWS and GCP credential handling via environment variables or config files. The engine initializer now correctly precompiles assets (JS, CSS, favicon) only when Sprockets is present, ensuring compatibility with Rails API mode, and respects time zone settings from the file configuration.

lib/pghero · high confidence

Redesigned dashboard with new monitoring pages and query analysis tools

The PgHero interface has been significantly updated to provide deeper database insights. The home page now features expanded health alerts for replication lag, transaction ID wraparound, sequence overflow, and invalid indexes, alongside a new Connections page that visualizes connection sources by database, user, and SSL status. Query management is enhanced with a dedicated Live Queries page for monitoring and killing running processes, and a new Show Query page that displays detailed performance charts, query origins, and associated table/index information. Additional dedicated pages have been added for Index Bloat (with SQL to recreate indexes), Relation Space growth over time, and a Tune page for PostgreSQL configuration recommendations. The main Queries table now supports sorting by total time, average time, and calls, and includes a slider for filtering historical query stats.

_app/views/pg\hero · high confidence

Redesigned navigation and layout for multi-database support

The application layout has been updated to support multiple databases, displaying the current database name in the header and providing a sidebar list to switch between databases. The navigation menu has been reorganized to include new sections such as Overview, System, Connections, Live Queries, Maintenance, Explain, and Tune, with visibility controlled by configuration flags. The layout also removes the external Bootstrap dependency in favor of internal assets and adds a favicon.

app/views/layouts · high confidence

Refactored library structure with modular methods and configurable settings

The library's internal structure has been reorganized to improve maintainability and extensibility. SQL query logic previously embedded in the main module has been extracted into separate, dedicated files under \lib/pghero/methods/\ (e.g., \basic\, \connections\, \indexes\, \queries\). The main module now uses \autoload\ for key classes and exposes a set of configurable settings via class attributes, such as \long\_running\_query\_sec\, \slow\_query\_ms\, \total\_connections\_threshold\, and \explain\_timeout\_sec\, which can be set via environment variables or configuration files. This change also introduces a \NotEnabled\ error class and a \Mutex\ for thread safety, laying the groundwork for more robust multi-database support and lazy loading.

lib · high confidence

Support for multiple databases and expanded monitoring routes

The application now supports monitoring multiple databases by scoping all routes under an optional database parameter, allowing users to switch between different database instances. Additionally, the routing structure has been significantly expanded to include new endpoints for system statistics (CPU, connections, replication lag, load, free space), query management (live queries, show specific query, explain), index analysis (bloat), tuning, and maintenance actions (kill queries, reset stats). Legacy routes for system stats and query stats have been updated to redirect to their new locations.

config · high confidence

Support for separate stats database and normalized query storage

PgHero now allows users to configure a separate database URL for storing statistics via the \stats\_database\_url\ setting, enabling better isolation of monitoring data from the main application database. Additionally, query statistics have been normalized into dedicated models (\Query\ and \QueryStats\) and tables (\pghero\_queries\, \pghero\_query\_stats\) to reduce storage space, while a new \SpaceStats\ model tracks space usage. These changes introduce a new \Stats\ base class to manage the optional separate connection and restructure how query metrics are persisted.

pghero · high confidence

Updated generator templates for configuration and schema normalization

The generator templates have been updated to provide a more comprehensive default configuration file (config.yml.tt) that includes settings for AWS, Google Cloud, basic authentication, and options to disable query killing or filter data. Additionally, the migration templates have been refined to support normalized query stats, introducing a dedicated pghero\_queries table to store distinct query text and linking it via a foreign key in pghero\_query\_stats, which helps reduce storage space. The templates also reflect changes such as using the 'primary' key for the default database, adjusting the default connection threshold to 500, and measuring unused index size in megabytes.

lib/generators/pghero/templates · high confidence

Test coverage

Added internal test environment scaffolding for PgHero; Initial test suite for PgHero core features.

Dependencies

Added CI support for Rails 7.2 and 8.0 with pg\_query 6

The gemfiles directory now includes dedicated configuration files for testing against Active Record 7.2 and 8.0. The new activerecord72.gemfile pins Active Record to version 7.2.0 and requires pg\_query version 6, while activerecord80.gemfile targets Active Record 8.0.0. These changes enable continuous integration testing for these specific framework versions.

gemfiles · high confidence

Updated Chart.js, Chartkick, noUiSlider, and Highlight.js libraries

The application's JavaScript assets have been updated to newer versions of key libraries: Chart.js is now v4.5.1, Chartkick is v5.0.1, noUiSlider is v15.8.1, and Highlight.js is v11.11.1. These updates are bundled directly into the application's asset pipeline (replacing external dependencies) to improve chart rendering, slider functionality, and code syntax highlighting.

app/assets/javascripts · high confidence

Updated dependencies and dropped support for older Ruby and Rails versions

The gem now requires Ruby 3.3 or higher and supports ActiveRecord 7.2 or newer, dropping compatibility with older versions. Development dependencies such as rake, minitest, combustion, and pg have been moved from the gemspec to the Gemfile, and the gemspec has been streamlined to include only the runtime dependency on activerecord (\>= 7.2).

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 48 → 53 (+4.6)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 97 → 92 (-5.3)
  • Architecture 96 → 90 (-5.3)
  • Maturity 50 → 50 (-0.2)
  • Readiness 26 → 67 (+41.4)
  • Security 80 → 100 (+20.3)
  • Domain Modelling 100 (new)
  • Accessibility 37 (new)

Resolved (8)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No exposed public API
  • No tests found
  • Test reliability not included

New (38)

  • Ambiguous overlap between running_queries and long_running_queries. running_queries takes a min_duration argument, implying it filters by duration. long_running_queries takes no arguments, implying it uses a default threshold. It is unclear if long_running_queries is simply a convenience wrapper for running_queries with a default min_duration, or if they query different underlying data sources (e.g., pg_stat_activity vs query stats).
  • Controller actions and Module methods share identical names and intents but exist in different namespaces. While this is common in Rails, the signatures differ slightly in parameter handling (Controller actions often take request params, while Module methods take explicit arguments). Specifically, HomeController.kill likely maps to Kill.kill, but the lack of a unified naming convention for 'terminating processes' across the API surface (e.g., terminate vs kill) makes the intent clear but the structure fragmented.
  • Documentation: no project overview (README.md)
  • HackComment (lib/pghero/methods/indexes.rb)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • HomeController.explain (cognitive 29) (app/controllers/pg_hero/home_controller.rb)
  • HomeController.explain (cyclomatic 19) (app/controllers/pg_hero/home_controller.rb)
  • HomeController.index (cognitive 17) (app/controllers/pg_hero/home_controller.rb)
  • HomeController.queries (cognitive 24) (app/controllers/pg_hero/home_controller.rb)
  • HomeController.queries (cyclomatic 18) (app/controllers/pg_hero/home_controller.rb)
  • HomeController.show_query (cognitive 17) (app/controllers/pg_hero/home_controller.rb)
  • Hotspot: app/controllers/pg_hero/home_controller.rb (app/controllers/pg_hero/home_controller.rb)
  • Hotspot: lib/pghero/methods/suggested_indexes.rb (lib/pghero/methods/suggested_indexes.rb)
  • No dependency advisory monitoring
  • SuggestedIndexes.best_index_helper (cognitive 55) (lib/pghero/methods/suggested_indexes.rb)
  • SuggestedIndexes.best_index_helper (cyclomatic 17) (lib/pghero/methods/suggested_indexes.rb)
  • SuggestedIndexes.best_index_structure (cognitive 22) (lib/pghero/methods/suggested_indexes.rb)
  • SuggestedIndexes.best_index_structure (cyclomatic 18) (lib/pghero/methods/suggested_indexes.rb)
  • …and 18 more

Changes since last survey

  • 17 commits — 16 feature/other, 1 fixes

By area

  • lib/pghero — 7 commits
  • (root) — 3 commits
  • test/internal — 3 commits
  • test/sequences_test.rb — 2 commits
  • .github/workflows — 1 commit
  • app/views — 1 commit

Notable commits

  • fix: Fixed max_value for smallint columns [skip ci]
  • change: Added link to upgrade notes in changelog - closes #541 [skip ci]
  • change: Added sequences from identity columns - resolves #542
  • change: Added test for sequence not owned by table
  • change: Improved naming [skip ci]
  • change: Improved query for last values
  • change: Improved query for sequences
  • change: Improved query for sequences [skip ci]
  • change: Improved regex [skip ci]
  • change: Improved test for sequences [skip ci]
  • change: Improved tests for sequences
  • change: Improved tests for sequences [skip ci]
  • change: Removed comment [skip ci]
  • change: Removed extra space [skip ci]
  • change: Respect disabled global filter data setting (#544)
  • change: Updated checkout action [skip ci]
  • change: Version bump to 4.0.1 [skip ci]

Architecture

  • Containers 0 added · 0 removed · contexts 1 added · 0 removed · edges 0 added · 0 removed

Added bounded contexts (1)

  • pghero

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

ankane/pghero was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 0efe3327aab12e40a53ec4e2bbc90b06499c9a10 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-d0929f7ac71f.