avoidwork/tenso
48.6
Weak · 21 September 2026
6.2k
lines of production code
JavaScript
primary language
4
measurements over time
What this system is
Tenso is a Node.js web framework that provides a structured API for building HTTP services, featuring a modular middleware architecture for handling authentication, security, and request processing. It supports a wide range of data formats through dedicated parsers and renderers, including JSON, XML, CSV, and HTML, while offering flexible response serialization strategies. The system includes a browsable API interface with dark mode support and integrates Prometheus metrics for monitoring. The codebase is heavily typed with TypeScript definitions and validated by comprehensive unit tests.
How it got here
2014–2017 — Framework modernization and UI overhaul
5 changes.
This period focused on modernizing the project's build infrastructure and dependency management while introducing a new Tenso framework class for server-side logic. Concurrently, the frontend was significantly updated with a browsable API interface featuring dark mode and syntax highlighting, supported by updated CSS frameworks and build tooling.
2019–2023 — Middleware and renderer expansion
9 changes.
This period focused on expanding the application's capabilities by introducing support for multiple data formats, including CSV, XML, and JSONL, alongside a new dark mode UI template. The core architecture was significantly refactored to include modular middleware for security, metrics, and request handling, while utility functions were added to support authentication, serialization, and data processing.
2024–2025 — framework standardization and testing
5 changes.
This period focused on standardizing the Tenso framework by introducing centralized configuration, comprehensive TypeScript type definitions, and strict coding rules for AI-assisted development. The team also established a robust testing suite for core modules and middleware, while adding performance benchmarks to evaluate the framework's capabilities.
Features
Add HTML template for dark mode support
A new HTML template file (template.html) has been added to the www directory. This template includes a footer with a 'Dark' mode toggle link, indicating the introduction of a dark mode feature for the HTML renderer. The template also includes references to CSS and JavaScript assets (bulma.min.css, style.css, app.js, dom-router.min.js) and defines the structure for displaying request and response data.
www · high confidence
Added TypeScript type definitions for the Tenso framework
Added new TypeScript declaration files (\.d.ts\) that define the types for the Tenso web framework. These include core interfaces for HTTP requests and responses, middleware functions, and specific handlers for parsing, rendering, and serializing data. The \types/index.d.ts\ file re-exports these types, providing a complete type system for the framework's API, including the main \Tenso\ class and factory function.
types · high confidence
Added custom and plain response serializers
Users can now choose between two serialization strategies for API responses. The new 'custom' serializer returns a structured object containing data, error, links, and status fields, while the 'plain' serializer returns the raw data or error information directly. Both serializers support an optional 'stack' parameter to include error stack traces.
src/serializers · high confidence
Added new parsers for JSON, JSONL, and URL-encoded form data
The src/parsers directory now includes three new modules: json.js for parsing JSON strings, jsonl.js for parsing JSON Lines format (leveraging the tiny-jsonl library), and xWwwFormURLEncoded.js for parsing URL-encoded form data (leveraging the tiny-coerce library). These additions provide standardized parsing utilities for common data formats.
src/parsers · high confidence
Added renderers for CSV, HTML, JavaScript, JSON, JSONL, plain text, XML, and YAML
The src/renderers directory now includes new renderers for CSV, HTML, JavaScript, JSON, JSONL, plain text, XML, and YAML. Each renderer converts data into its respective format, with HTML rendering using template replacement, JSON using configurable indentation, and XML handling array node names and entity processing. These additions expand the supported output formats for API responses.
src/renderers · high confidence
Centralized configuration and constants for the Tenso framework
The Tenso framework now provides a centralized configuration object and a dedicated constants module to standardize default settings and reusable values. The new \src/core/config.js\ file defines the \TensoConfig\ structure, allowing users to customize authentication, security, logging, caching, and other framework behaviors. Additionally, \src/core/constants.js\ introduces a comprehensive set of constants for HTTP methods, status codes, headers, authentication schemes, and other framework-specific values, replacing scattered string and numeric literals with named exports for improved maintainability and consistency.
src/core · high confidence
Introduction of the Tenso framework class
A new \Tenso\ class has been added in \src/tenso.js\, extending \Woodland\ to provide a structured web framework. This class manages server initialization, request connection handling, and response processing, including support for Prometheus metrics, CSRF protection, and CORS headers.
src · high confidence
New browsable API interface with dark mode and response formatting
A new JavaScript application (app.js) and a DOM router (dom-router.min.js) are introduced to power a browsable API interface. The interface allows users to submit requests, view formatted JSON/XML responses with syntax highlighting, and toggle a dark mode that persists via localStorage. The implementation includes sanitizing innerHTML to prevent XSS, handling CSRF tokens, and managing UI states like loading and error handling.
www/assets/js · high confidence
New performance benchmarks for the Tenso framework
Added a comprehensive suite of performance benchmarks for the Tenso framework, covering authentication (basic, bearer, JWT), basic HTTP, hypermedia, load testing, memory usage, parsers, rate limiting, renderers, and serializers. These new benchmark scripts allow developers to measure and compare the performance of various framework features and components.
benchmarks · high confidence
New utility functions for authentication, serialization, and data processing
The application now includes a comprehensive set of utility functions in the src/utils directory to support core features. Authentication is handled by a new auth.js module that configures session management, security headers (CSP, X-Frame, HSTS), and various auth strategies (JWT, OAuth2, Basic, Bearer). Data serialization is managed by serializers.js and serialize.js, which map content types to specific serializers for JSON, YAML, XML, CSV, HTML, and JSONL formats. Additional utilities include chunk, clone, delay, empty, explode, hasBody, hasRead, hypermedia, id, indent, isEmpty, marshal, parsers, random, regex, renderers, sanitize, scheme, and sort, each providing specific functionality for data processing, HTTP method checking, and response formatting.
src/utils · high confidence
Behavioural changes
Added Node.js API service coding rules
A new coding rule file has been added to configure the AI assistant's behavior for Node.js API services. The rules enforce JSDoc standards, camelCase for functions, UPPER\_CASE for constants, and specific testing patterns using node-assert and mocha. It also mandates adherence to Node.js community best practices, DRY/KISS/YAGNI/SOLID principles, and OWASP security guidance.
.cursor · high confidence
Added pre-commit hook to run tests
A new pre-commit hook has been added to the project, configured to automatically run 'npm test' before each commit. This ensures that tests are executed as part of the version control workflow, helping to catch regressions early.
.husky · high confidence
Refactored and expanded middleware architecture
The middleware layer has been refactored into individual, modular files (asyncFlag, bypass, csrf, exit, guard, parse, payload, prometheus, rate, redirect, and zuul) to improve maintainability and separation of concerns. This change introduces new capabilities including Prometheus metrics collection for HTTP requests, enhanced CSRF protection, and a more granular control over which requests are protected or bypassed. The main 'zuul' middleware now coordinates authentication checks and rate limiting, while specific concerns like body parsing, payload handling, and exit conditions are handled by dedicated middleware functions.
src/middleware · high confidence
Updated Bulma CSS and added source maps
The Bulma CSS framework has been updated, with the compiled \bulma.css.map\ source map file added to \www/assets/css\. This update likely includes styling changes for the UI, such as the flexbox layout for templates and color state adjustments mentioned in the commit history.
www/assets/css · medium confidence
Updated bundled distribution files for version 17.3.2
The \dist/tenso.cjs\ and \dist/tenso.js\ files have been updated to version 17.3.2. This release includes the addition of a \/metrics\ endpoint for Prometheus monitoring, the removal of the 'keymaster' middleware, and the removal of deprecated methods such as \this.renderer()\ and \this.serializer()\. The build also reflects updated dependencies and internal refactoring, including the introduction of \this.init()\, \this.signals()\, and \req.exit()\ for controlling the middleware pipeline.
dist · medium confidence
Fixes
Added sample page for /sample route
A new HTML file has been added at www/sample/index.html, providing a basic page structure with title and content placeholders for the /sample route. This change supports the fix for issue \#107 by ensuring the server has a valid HTML response to serve for that path.
www/sample · medium confidence
Test coverage
Added unit tests for core configuration and middleware modules
Added comprehensive unit tests for the core configuration module, verifying that all expected configuration properties (auth, security, session, webroot, logging, prometheus, rate limiting, SSL, hypermedia, and common defaults) are present and correctly typed. Additionally, added unit tests for multiple middleware modules including asyncFlag, bypass, csrf, exit, guard, parse, payload, prometheus, rate, redirect, and zuul, as well as parsers for JSON, JSONL, and x-www-form-urlencoded data. These tests validate the behavior of request processing, protection logic, and data parsing.
tests · high confidence
Dependencies
Updated dependencies and build configuration
The project's dependency tree has been updated, including rollup, eslint, and various utility packages, as reflected in the regenerated CHANGELOG.md. Additionally, the build system has been modernized with a new rollup.config.js for bundling, an eslint.config.js for linting, and a benchmark.js runner, while the .gitignore and LICENSE files have been updated to reflect the current year and project name.
(repo-wide) · high confidence
Updated project dependencies and lock file
The project's \package.json\ and \package-lock.json\ have been updated to reflect the current state of dependencies. Key updates include \eslint\ to version 9.30.1, \mocha\ to 11.7.1, \rollup\ to 4.44.2, and \woodland\ to 20.1.8, among others. These changes ensure the project uses the latest compatible versions of its dependencies.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 50 → 49 (-1.1)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 66 → 60 (-6.1)
- Architecture 90 → 90 (-0.6)
- Maturity 71 → 66 (-5.8)
- Readiness 51 → 65 (+14.2)
- Security 56 → 69 (+12.5)
- Accessibility 39 → 31 (-8.4)
Resolved (36)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High vulnerability: [GHSA redacted] (package-lock.json)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Low CVE: [GHSA redacted] (package-lock.json)
- …and 16 more
New (61)
- (anonymous) (cognitive 19) (www/assets/js/app.js)
- (anonymous) (cyclomatic 19) (www/assets/js/app.js)
- Coverage not measured — JavaScript/TypeScript suite
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Documentation: no contributor guidance (README.md)
- FunctionTooLong: auth.auth (src/utils/auth.js)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High vulnerability: [GHSA redacted] (package-lock.json)
- High: security finding (details withheld)
- …and 41 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
avoidwork/tenso was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit df3ba985504ddf14da2c376bc0edb858ca2aa1b9 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.