Skip to content
CAI
Software that uses CAICheck a score

bencagri/symfony-ddd

48.7

Weak · 22 September 2026

1.4k

lines of production code

PHP

primary language

7

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a PHP-based web application that provides a RESTful API for managing users and articles, utilizing the Symfony framework. It implements OAuth2 authentication and serializes API responses using Fractal. The codebase includes comprehensive testing infrastructure with PHPUnit and data fixtures for development and integration testing.

Features

Add OAuth2 authorization and token endpoints

Introduced new controllers for OAuth2 flows: \OAuthAuthorizeController\ exposes the \/oauth/v2/auth\ endpoint for user authorization, and \OAuthTokenController\ exposes the \/oauth/v2/token\ endpoint for obtaining access tokens. The token controller explicitly handles the \client\_credentials\ grant type by defaulting the \grant\_type\ parameter if not provided, ensuring compatibility with client credential authentication.

src/Authorization/Controller · high confidence

Added Dockerfile and configuration for PHP 7.3 development environment

A new Dockerfile has been added to configure a PHP 7.3 CLI environment, installing essential Ubuntu packages, PHP extensions (including PDO, XML, and Xdebug), and Composer. A corresponding php.ini is provided for development settings, and a setup script is included to initialize the database schema and load fixtures.

.docker · high confidence

Added OAuth client creation command

A new console command, \oauth:client:create\, has been introduced to allow users to create new OAuth clients via the command line. The command accepts a \--redirect-uri\ option to specify redirect URIs and a \--grant-type\ option (defaulting to \client\_credentials\) to define allowed grant types, facilitating the programmatic management of OAuth clients within the authorization system.

src/Authorization/Console · high confidence

Added database seeding fixtures for articles and users

The application now includes data fixtures to populate the database with test data. A new UserFixtures class creates a static test user with a hardcoded email address ([e-mail redacted]) and password, while ArticleFixtures generates 50 sample articles linked to this user. These fixtures allow developers to quickly seed the database for testing and development purposes.

src/DataFixtures · high confidence

Adds Docker support and PHPUnit configuration for the project

The project now includes a \docker-compose.yml\ file to facilitate running the application in a Docker environment, allowing users to start the application with \docker-compose up\. Additionally, a \phpunit.xml.dist\ configuration file has been added to support running unit and integration tests using PHPUnit, configuring the test environment and test suite structure.

(repo-wide) · high confidence

Introduce article and user management with Fractal API serialization

This change adds a complete domain layer for managing Articles and Users, including entities (Article, Tag, User), services (ArticleService, UserService), and controllers (ArticleController, UserController, SearchController). It introduces a Fractal-based API response format that wraps all JSON responses in a { success: boolean, ... } envelope, and provides paginated, serialized endpoints for listing, creating, and searching articles, as well as listing and retrieving users. The existing AppEntityRepository and UserRepository are refactored to support these new domain models, and routing is configured for /api/articles, /api/article/{id}, /api/users, /api/user/{id}, and /api/search.

src/Project · high confidence

Behavioural changes

Restructures service configuration and enables testing infrastructure

The application's service configuration has been refactored to support a new 'Project' and 'Authorization' module structure, moving controller and console command registrations from the generic 'App' namespace to specific 'App\\Project' and 'App\\Authorization' paths. Additionally, the configuration now explicitly registers Doctrine Fixtures for database seeding and enables the Symfony WebProfiler and Maker bundles for development and testing environments. A new 'services\_test.yaml' file has been introduced to configure public service access during tests, and the 'services.yaml' has been updated to include fixture tags and imports, facilitating a more modular and testable architecture.

config · medium confidence

Updated Oauth2 entity mappings and references

The Oauth2 entity classes (AccessToken, AuthCode, RefreshToken) now explicitly define their database table names (e.g., oauth2\_access\_token) and update the User entity reference from App\\Aurora\\Infrastructure\\User\\User to App\\Project\\Domain\\User\\Entity\\User.

src/Authorization/Entity · medium confidence

Test coverage

Added PHPUnit test infrastructure and integration tests

Added a new test suite for the application, including a base UnitTest class that loads data fixtures and an integration test for the ArticleService. The test setup boots the Symfony kernel in the 'test' environment and loads fixtures from src/DataFixtures. The ArticleServiceTest verifies that articles can be created via the service layer.

tests · high confidence

Dependencies

Update project dependencies and add new libraries

The project's composer dependencies have been updated and expanded. New packages added include nelmio/api-doc-bundle, pagerfanta/pagerfanta, samj/fractal-bundle, sensio/framework-extra-bundle, stof/doctrine-extensions-bundle, symfony/asset, symfony/translation, symfony/validator, and symfony/var-dumper. In the development dependencies, doctrine/doctrine-fixtures-bundle, symfony/browser-kit, symfony/maker-bundle, fzaninotto/faker, symfony/phpunit-bridge, and symfony/profiler-pack have been added. Several existing dependencies, such as doctrine/cache and doctrine/collections, have been updated to newer versions.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 46 → 49 (+2.4)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 99 (+0.1)
  • Architecture 69 → 69 (+0.0)
  • Maturity 50 → 50 (+0.0)
  • Readiness 26 → 31 (+4.9)
  • Security 87 → 88 (+1.0)

Resolved (22)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (composer.lock)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (6 lines × 3) (src/Project/App/Support/FractalService.php)
  • Duplicated block (8 lines × 2) (src/Project/Domain/Article/ArticleService.php)
  • High CVE: [GHSA redacted] (composer.lock)
  • High CVE: [GHSA redacted] (composer.lock)
  • High CVE: [GHSA redacted] (composer.lock)
  • Low CVE: [GHSA redacted] (composer.lock)
  • Low CVE: [GHSA redacted] (composer.lock)
  • Low CVE: [GHSA redacted] (composer.lock)
  • Medium CVE: [GHSA redacted] (composer.lock)
  • Medium CVE: [GHSA redacted] (composer.lock)
  • Medium CVE: [GHSA redacted] (composer.lock)
  • Medium CVE: [GHSA redacted] (composer.lock)
  • Medium CVE: [GHSA redacted] (composer.lock)
  • Medium CVE: [GHSA redacted] (composer.lock)
  • Medium CVE: [GHSA redacted] (composer.lock)
  • Medium vulnerability: [GHSA redacted] (composer.lock)
  • No exposed public API
  • …and 2 more

New (28)

  • Abandoned package: samj/fractal-bundle
  • Abandoned package: sensio/framework-extra-bundle
  • Critical CVE: [GHSA redacted] (composer.lock)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (13 lines × 2) (src/Project/Domain/Article/ArticleService.php)
  • Duplicated block (6 lines × 3) (src/Project/App/Support/FractalService.php)
  • End-of-life framework: Symfony 4
  • High CVE: [GHSA redacted] (composer.lock)
  • High CVE: [GHSA redacted] (composer.lock)
  • High CVE: [GHSA redacted] (composer.lock)
  • High IaC: WD-DOCKER-0001 (.docker/php/Dockerfile)
  • Low CVE: [GHSA redacted] (composer.lock)
  • Low CVE: [GHSA redacted] (composer.lock)
  • Low CVE: [GHSA redacted] (composer.lock)
  • Low IaC: DS-0026 (.docker/php/Dockerfile)
  • Medium CVE: [GHSA redacted] (composer.lock)
  • Medium CVE: [GHSA redacted] (composer.lock)
  • Medium CVE: [GHSA redacted] (composer.lock)
  • Medium CVE: [GHSA redacted] (composer.lock)
  • …and 8 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

bencagri/symfony-ddd was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 65a3baef893222b6565733b1c746399d4af44c72 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.