Skip to content
CAI
Software that uses CAICheck a score

avwo/whistle

38.5

Weak · 1 October 2026

71.1k

lines of production code

JavaScript

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Whistle is a Node.js-based HTTP/HTTPS debugging proxy and network inspector that captures, filters, and manipulates web traffic. It provides a React-based web dashboard for viewing request details, managing firewall rules, and configuring custom SSL certificates, alongside a CLI for system-level proxy and plugin management. The system supports deep extensibility through a plugin architecture that allows for custom request/response transformations, WebSocket piping, and rule injection.

How it got here

2015 — Initial project scaffolding and core architecture

17 changes.

This period established the foundational structure of the Whistle project, introducing essential build tooling, dependency management, and repository configuration. It focused on building the core proxy engine with modular middleware, DNS resolution, and HTTPS interception capabilities. The work also delivered the initial Web UI, CLI interface, and remote debugging integrations to support development and usage.

2016–2017 — Plugin architecture and service layer overhaul

12 changes.

The project significantly restructured the plugin subsystem with a new compatibility layer and dedicated loading modules, while introducing a comprehensive service layer for session management and Fiddler file support. Concurrently, new CGI endpoints were added to the WebUI to expose plugin management and socket control capabilities, supported by extensive test infrastructure and unit coverage for these new features.

2018–2026 — WebUI modernization and plugin infrastructure

15 changes.

The project overhauled the web interface by migrating to React and Bootstrap, introducing a comprehensive CSS design system and new components like a JSON tree viewer. Concurrently, it established a robust plugin ecosystem with a dedicated bridge API and context menu support, while expanding CLI capabilities for certificate management and adding extensive test coverage for proxy and plugin functionalities.

Features

Add JSON tree viewer component with context menu and theming

The web UI now includes a new \react-json-tree\ component for displaying JSON data, featuring a collapsible tree structure, a context menu with options to copy keys, values, objects, and key paths, and support for solarized theming via CSS variables.

biz/webui/htdocs/src/js/components · high confidence

Add Web UI editor, index, and preview pages

The web interface now includes dedicated pages for editing configuration files, viewing the main dashboard, and previewing captured content. The new editor.html provides a simple text area for editing rules or data, supporting theme switching via URL hash. The preview.html page allows users to view captured HTTP responses by decoding base64-encoded content from the URL hash, handling various character sets. The index.html serves as the main entry point, loading the primary application script.

biz/webui/htdocs · high confidence

Added Weinre remote debugging integration

The application now includes a new remote debugging feature using Weinre. This change introduces a new module structure under \biz/weinre\ containing an entry point (\index.js\) that forks a server process and a server implementation (\server.js\) that initializes the Weinre service. Users can now access remote debugging capabilities through this integrated endpoint.

biz/weinre · high confidence

Added recycle bin endpoints for rules and values

New CGI endpoints have been added to support a recycle bin feature for both rules and values. Users can now list items in the recycle bin, view the content of a specific item, and permanently remove items from the recycle bin via the new /rules/recycle and /values/recycle paths.

biz/webui/cgi-bin/rules/recycle, biz/webui/cgi-bin/values/recycle · high confidence

Added webpack build configuration for web UI assets

A new webpack configuration file has been introduced to manage the build process for the web UI source code. This setup defines entry points for the main index and decode scripts, configures loaders for JavaScript (via babel-loader), CSS, and static assets (images, fonts), and sets up production optimizations including environment variable definition and code minification.

biz/webui/htdocs/src · high confidence

Initial project scaffolding and configuration setup

This change establishes the foundational configuration for the Whistle project, introducing build tooling via .babelrc and .eslintrc, code style enforcement through .editorconfig, and CI integration with .travis.yml. It also adds essential repository metadata including .gitignore, .gitattributes, and .npmignore, alongside comprehensive documentation (README, CHANGELOG) and TypeScript type definitions (index.d.ts) to support development and usage.

(repo-wide) · high confidence

Initial release of the Web UI server

The Web UI server is now available, providing the HTTP endpoints and static file serving logic required for the Whistle interface. This change introduces the core Express application structure, including authentication handling (login, guest access, and cookie-based sessions), request parsing, and proxying for CGI endpoints, effectively establishing the foundation for the user-facing dashboard.

biz/webui · high confidence

Introduce React-based WebUI components and Bootstrap styling

The WebUI source code has been refactored to use React for UI components and Bootstrap for styling. New files include \back-to-bottom-btn.js\, \btn-group.js\, \close-btn.js\, \composer-list.js\, \cookies-dialog.js\, and \copy-btn.js\, all implemented as React components. The \base-css.js\ file now loads Bootstrap CSS/JS and jQuery, replacing previous styling approaches. The \cgi.js\ module provides a centralized AJAX request handler with queueing and authorization support. The \columns.js\ file defines the default network table columns (APP, Date, Result, Method, Protocol, etc.) and their display properties.

biz/webui/htdocs/src/js · high confidence

Introduce dedicated DNS resolution module with HTTPS-over-DNS and IPv6 support

The rules engine now uses a dedicated \lib/rules/dns.js\ module for hostname resolution, replacing the previous implicit reliance on Node's \dns\ module. This change introduces support for DNS over HTTPS (DoH) via the \dnsOverHttps\ configuration, adds explicit IPv6 resolution options (\dnsResolve4\, \dnsResolve6\, \ipv6Only\), and implements a configurable DNS cache with TTL management. The new module also handles fallback logic for DNS failures and ensures consistent IP resolution across the proxy's rule matching and proxy routing logic.

lib/rules · high confidence

New CGI endpoints for comprehensive Rules & Values management

The web UI now exposes a dedicated set of CGI scripts in the rules directory to manage firewall rules and values. Users can now import and export rule sets (with custom filenames), enable or disable all rules, toggle the 'back rules first' behavior, and manage the default rule set. The interface supports moving rules between groups, reordering them, and bulk operations like disabling all rules. Additionally, a recycle bin feature allows for the recovery of deleted rules, and the system now supports multi-select for rule management.

biz/webui/cgi-bin/rules · high confidence

New CGI endpoints for custom certificate management

Added four new CGI scripts (active, all, remove, upload) in the certs directory that expose the underlying CA library's capabilities to the web UI. These endpoints allow users to set an active custom certificate, retrieve the list of all custom certificates and their directory path, remove existing certificates, and upload new ones, with responses optionally returning parsed certificate info or file metadata.

biz/webui/cgi-bin/certs · high confidence

New CGI endpoints for managing Rules & Values

The WebUI now exposes a dedicated set of CGI handlers in the \biz/webui/cgi-bin/values\ directory to manage Rules and Values. This includes endpoints for listing (\list\, \list2\, \get\), adding (\add\), removing (\remove\), renaming (\rename\), and moving (\move-to\) values, as well as importing (\import\) and exporting (\export\) them. These endpoints support features such as custom export filenames, group management, and recycle bin integration, providing the backend API for the Rules & Values interface.

biz/webui/cgi-bin/values · high confidence

New CGI endpoints for plugin management and status

This change introduces a set of new CGI scripts under \biz/webui/cgi-bin/plugins/\ that expose plugin management capabilities to the WebUI. Users can now retrieve plugin lists and registry details (\get-plugins\, \list\, \registry-list\, \status\), check individual plugin enablement (\is-enable\, \plugin\), and manage plugin states by adding registries (\add-registry\), disabling individual or all plugins (\disable-plugin\, \disable-all-plugins\), uninstalling plugins (\uninstall\), and forcing rule updates (\update-rules\). These endpoints provide the backend interface required for the WebUI to display and control plugin configurations.

biz/webui/cgi-bin/plugins · high confidence

New CGI endpoints for request management, rule handling, and certificate operations

The Web UI now exposes a comprehensive set of new CGI endpoints in the \biz/webui/cgi-bin\ directory to support advanced proxy management features. Users can now abort specific network requests via \abort.js\, manage proxy rules and values with \add-rules-values.js\, and test rule matching using \get-matched-rules.js\. Certificate management is expanded with \create-cert.js\ for generating custom certificates and \get-cert.js\ for retrieving them, alongside endpoints for custom certificate info (\get-custom-certs-info.js\, \get-custom-certs-files.js\). The UI can now check for application updates (\check-update.js\), retrieve detailed server and session data (\get-data.js\, \get-session.js\), and handle file downloads (\download.js\). Additional endpoints support HTTP/2 configuration (\enable-http2.js\), HTTPS interception toggling (\intercept-https-connects.js\), and custom column settings (\set-custom-column.js\), providing the backend infrastructure for the new UI capabilities.

biz/webui/cgi-bin · high confidence

New CLI command to install Root CA certificates

A new \w2 ca\ command has been added to the CLI, allowing users to install a Root CA certificate from a local file, a URL, or a host:port address. The command automatically detects the operating system (macOS, Windows, or Linux) and uses the appropriate system tools (security, certutil, or update-ca-certificates/update-ca-trust) to trust the certificate. It also supports an \enableHttps\ parameter for fetching certificates from local services.

bin/ca · high confidence

New CLI subcommands and programmatic API for Whistle management

The \bin\ directory now includes dedicated modules (\api.js\, \status.js\, \plugin.js\, \proxy.js\, \use.js\, \import.js\) that expose new capabilities for managing Whistle instances. Users can now check the status of running instances via the \w2 status\ command, which displays PIDs, ports, and storage paths. The \w2 proxy\ command allows configuring system proxy settings using the \set-global-proxy\ library. Plugin management is handled by \w2 install\ and \w2 uninstall\, supporting custom installation directories and peer plugin dependencies. Additionally, a programmatic API is exposed via \bin/api.js\ and \bin/plugin.d.ts\, allowing external scripts to interact with Whistle's status, capture sessions, and plugin installation logic.

bin · high confidence

New handler modules for file proxying, HTTP proxying, and error handling

The \lib/handlers\ directory now includes dedicated modules for core request handling: \file-proxy.js\ manages local file serving with support for raw file protocols, range requests (206 Partial Content), and template injection; \http-proxy.js\ handles HTTP/HTTPS proxying, including plugin-based protocol handling and custom port forwarding; and \error-handler.js\ provides a centralized mechanism for wrapping and responding with gateway errors. These modules are exported via \index.js\ to form the primary request processing pipeline.

lib/handlers · high confidence

New inspector subsystem for request/response manipulation and logging

The \lib/inspectors\ directory now contains a dedicated module structure (\data.js\, \index.js\, \log.js\, \req.js\, \res.js\, \rules.js\, \weinre.js\) that centralizes the handling of HTTP traffic inspection. This change introduces specific capabilities for injecting logging and debugging scripts (via \log\ and \weinre\ rules), modifying request and response bodies and headers (via \req.js\ and \res.js\), and managing rule resolution and codec transformations (via \rules.js\). It also adds a new \data.js\ module to manage request/response data structures, frame parsing, and size limits (e.g., \MAX\_BODY\_SIZE\, \BIG\_DATA\_SIZE\), effectively replacing or refactoring the previous inline logic for these tasks into a reusable, modular component.

lib/inspectors · high confidence

New logging, debugging, and worker infrastructure

Added three new JavaScript modules to the client-side assets: \log.js\ introduces a \window.\_whistleConsole\ API for capturing and sending console logs, including a custom JSON polyfill to handle circular structures and prevent memory leaks; \weinre.js\ dynamically loads the Weinre remote debugging server script based on the configured path prefix; and \worker.js\ establishes a Web Worker for processing network request/response data, providing lazy-loaded \body\ and \json\ properties on request and response objects to facilitate efficient parsing and inspection.

assets/js · high confidence

New plugin bridge and context menu infrastructure

The application now provides a dedicated plugin API (\whistleBridge\) and context menu system, allowing plugins to interact with the core UI. New assets (\menu.html\, \modal.html\, \tab.html\) expose methods for plugins to listen to network, rules, values, and plugin events, manage session state, access raw request/response data, and trigger UI actions like showing modals or updating the interface. This enables plugins to integrate deeply with the inspector and menu systems.

assets · high confidence

New service module for session import, export, and composer history

A new \lib/service\ module has been introduced to handle session management and request composition. This includes importing and exporting Fiddler \.saz\ files (via \extract-saz.js\ and \generate-saz.js\), managing composer history with size limits and persistence (\composer.js\, \compose-data.js\), and providing a centralized data center for saving and sharing sessions (\data-center.js\). The service also adds console logging capabilities (\console-log.js\) and handles plugin installation (\install.js\), effectively replacing or augmenting previous ad-hoc implementations with a structured service layer.

lib/service · high confidence

New socket management endpoints for aborting, status changes, and data sending

The web UI now exposes three new CGI endpoints to control socket connections: abort.js allows users to terminate specific socket requests by ID, change-status.js enables updating the status of a socket connection, and data.js provides a way to send data through the socket manager. These changes give users direct programmatic control over socket lifecycle and data transmission within the web interface.

biz/webui/cgi-bin/socket · high confidence

New utility modules for file management, logging, and performance monitoring

The lib/util directory has been expanded with several new modules to support core proxy and plugin functionality. A new file manager (file-mgr.js) handles reading and decoding local files with size limits and encoding fallbacks, while a file-writer-transform stream allows raw HTTP data to be persisted to disk. A dedicated logger module provides a circular buffer for system logs with severity levels, and a performance monitor (perf.js) tracks CPU, memory, and request throughput (QPS) in real-time. Additionally, new utilities include a safe URL parser (parse-url-safe.js) for robust address handling, a UTF-8 detection helper (is-utf8.js), and various stream transforms for replacing patterns/strings, adjusting network speed/delay, and packing/unpacking data frames.

lib/util · high confidence

Behavioural changes

Complete UI redesign with CSS variables and new components

The web interface has been completely restyled to use a modern, consistent design system. This introduces a comprehensive set of CSS custom properties (variables) in \base.css\ for colors, z-indexes, and spacing, replacing hardcoded values. The visual appearance of core components like the Composer, Network inspectors, context menus, and dialogs has been refined, including updated button states, scrollbar styling, and modal layouts. New UI elements have been added to support features such as the About dialog, file management, and custom network columns.

biz/webui/htdocs/src/css · high confidence

HTTPS interception and certificate management refactored into modular components

The lib/https module has been restructured into four distinct files—ca.js, h2.js, index.js, and load-cert.js—to separate concerns for certificate authority management, HTTP/2 proxying, core HTTPS handling, and SNI-based certificate loading. This change introduces a new certificate caching system using LRU caches, supports SNI callbacks for dynamic certificate resolution via plugins, and implements a dedicated HTTP/2 client with SOCKS proxy support and connection pooling. Users benefit from improved stability in HTTPS interception, better handling of WebSocket and HTTP/2 traffic, and the ability to customize certificate generation and loading through plugin hooks.

lib/https · high confidence

Introduce new business logic module for request routing and UI server initialization

This change introduces the \biz\ directory, containing \index.js\ and \init.js\, which centralize the core request handling logic and UI server setup. The new \index.js\ module manages the routing of incoming requests, distinguishing between Web UI traffic, internal applications (like weinre and logs), and plugin requests, while also handling local rule resolution and proxy transformations. The \init.js\ module initializes the proxy and conditionally starts a separate HTTP server for the UI if a custom UI port is configured. This refactors the previous monolithic or scattered request handling into a dedicated business logic layer.

biz · high confidence

New proxy server architecture with Express and modular middleware

The core proxy server has been refactored to use Express for HTTP request handling and introduces a modular middleware pipeline (loading init, biz, inspectors, handlers, and custom middlewares). This change centralizes request processing, adds robust client error handling (returning 400/431 for bad requests), and integrates new subsystems including a SOCKS v5 server, WebSocket upgrade handling, and a data server. The server now supports separate HTTP and HTTPS ports, configurable timeouts, and SNI-based certificate loading for the HTTPS server.

lib · high confidence

Plugin system refactored with new architecture and compatibility layer

The plugin subsystem has been significantly restructured to support a more robust and extensible plugin architecture. A new compatibility layer (lib/plugins/compat.js) has been introduced to map internal plugin properties to specific HTTP headers (e.g., mapping 'fullUrl' to 'x-whistle-full-url'), ensuring consistent data passing between the core and plugins. Plugin discovery and loading have been separated into dedicated modules (get-plugins.js, get-plugins-sync.js, module-paths.js) that handle path resolution, priority sorting, and metadata extraction from package.json more reliably. The core plugin manager (index.js) and the plugin runtime environment (load-plugin.js) have been rewritten to support advanced features such as custom socket parsers, WebSocket piping, shared storage, and dynamic rule injection via headers. This change also introduces new configuration options for plugin paths, priority, and UI customization, while removing legacy loading mechanisms.

lib/plugins · high confidence

Test coverage

Add test infrastructure and configuration; Added test assets for values and template string scenarios; Added test coverage for Whistle plugin rule configuration; Added test fixture for Whistle plugin rules server; Added test fixtures for storage, remote keys, and script rules; Added test fixtures for the whistle plugin; Added test fixtures for whistle.test3 plugin scenarios; Added test suite for Whistle proxy plugins; Added test suite for the whistle pipe WebSocket plugin; Added test suite for whistle.test2 plugin; Added test suites for HTTP and tunnel pipe plugins; Added tests for Whistle plugin request/response transformation; Added tests for proxy enable and disable functions; Expanded unit test coverage for proxy and network features; Regenerated test certificates with 2048-bit keys.

Dependencies

Initial release of Whistle v2.10.10 with dependency manifest

This commit introduces the initial package.json and package-lock.json for Whistle version 2.10.10, establishing the project's dependency tree. It defines the core runtime dependencies required for the HTTP/HTTPS/WebSocket debugging proxy, including express, body-parser, node-forge, and various internal modules like hagent and pipestream. It also lists development dependencies for building the UI (webpack, babel, react) and running tests, while setting the minimum supported Node.js version to 14.0.0.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 37 → 39 (+1.3)
  • Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 32 → 31 (-0.4)
  • Architecture 91 → 79 (-11.9)
  • Maturity 59 → 59 (-0.4)
  • Readiness 40 → 35 (-4.5)
  • Security 39 → 63 (+23.9)
  • Accessibility 37 → 37 (+0.0)
  • Performance 100 (new)

Resolved (59)

  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
  • Hotspot: bin/api.js (bin/api.js)
  • Hotspot: bin/util.js (bin/util.js)
  • Hotspot: biz/webui/htdocs/src/js/cgi.js (biz/webui/htdocs/src/js/cgi.js)
  • Hotspot: biz/webui/htdocs/src/js/req-data.js (biz/webui/htdocs/src/js/req-data.js)
  • Hotspot: biz/webui/htdocs/src/js/request-rule.js (biz/webui/htdocs/src/js/request-rule.js)
  • Hotspot: biz/webui/htdocs/src/js/response-rule.js (biz/webui/htdocs/src/js/response-rule.js)
  • Hotspot: lib/inspectors/req.js (lib/inspectors/req.js)
  • Hotspot: lib/rules/rules.js (lib/rules/rules.js)
  • Hotspot: lib/socket-mgr.js (lib/socket-mgr.js)
  • Hotspot: lib/tunnel.js (lib/tunnel.js)
  • Hotspot: lib/upgrade.js (lib/upgrade.js)
  • Hotspot: lib/util/index.js (lib/util/index.js)
  • Medium CVE: [GHSA redacted] (package-lock.json)
  • _transform (cyclomatic 17) (lib/util/whistle-transform.js)
  • addPluginMenus (cyclomatic 17) (biz/webui/htdocs/src/js/util.js)
  • addRules (cognitive 54) (lib/rules/util.js)
  • addRules (cyclomatic 25) (lib/rules/util.js)
  • compareVersion (cognitive 16) (biz/webui/htdocs/src/js/util.js)
  • compareVersion (cognitive 17) (lib/util/common.js)
  • …and 39 more

New (113)

  • FunctionTooLong: log.patchJSON (assets/js/log.js)
  • FunctionTooLong: rules-hint.CodeMirror.registerHelper("hint","rulesHint") (biz/webui/htdocs/src/js/rules-hint.js)
  • FunctionTooLong: rules-mode.CodeMirror.defineMode("rules") (biz/webui/htdocs/src/js/rules-mode.js)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • Hotspot: biz/webui/htdocs/src/js/rules-mode.js (biz/webui/htdocs/src/js/rules-mode.js)
  • Hotspot: lib/inspectors/res.js (lib/inspectors/res.js)
  • Medium: security finding (details withheld)
  • Outdated (npm): body-parser
  • Outdated (npm): colors
  • Outdated (npm): express
  • Outdated (npm): iconv-lite
  • Outdated (npm): lru-cache
  • Outdated (npm): mime
  • Outdated (npm): xml2js
  • Projects may be oversized for their cohesion
  • add.default (cognitive 16) (biz/webui/cgi-bin/values/add.js)
  • add.default (cognitive 18) (biz/webui/cgi-bin/rules/add.js)
  • cli.default (cognitive 27) (bin/ca/cli.js)
  • cli.default (cyclomatic 22) (bin/ca/cli.js)
  • …and 93 more

Changes since last survey

  • 1 commits — 1 feature/other, 0 fixes

By area

  • (root) — 1 commit

Notable commits

  • change: chore(deps): bump adm-zip from 0.6.0 to 0.6.1

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

avwo/whistle was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 33820c617df12894bb38a5e8ea9019b96b3c955e — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.