Skip to content
CAI
Software that uses CAICheck a score

bwaidelich/dcb-eventstore

66.3

Adequate · 21 September 2026

1.2k

lines of production code

PHP

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a PHP-based event sourcing library that provides an in-memory implementation of an event store. It enables the storage and retrieval of domain events with support for conditional appends, sequence-based ordering, and flexible querying by type, tag, or metadata. The codebase includes comprehensive test coverage and strict code quality tooling to ensure reliability.

How it got here

2023 — EventStore implementation and tooling setup

4 changes.

This period focused on establishing the project's foundational infrastructure, including code style, static analysis, and testing tooling. The core domain logic was introduced through an EventStore interface and an in-memory implementation, supported by comprehensive integration tests to ensure reliability.

2025 — Event store domain model implementation

9 changes.

This period focused on implementing the core domain model for an event store, introducing classes for events, queries, and sequencing. The work included building the necessary infrastructure for event storage and retrieval, supported by comprehensive unit tests for all new components.

Features

Introduce EventStore interface and in-memory implementation with conditional append support

Added the core EventStore interface defining read and append operations, including support for conditional appends that validate state before writing. The in-memory implementation provides a testing/debugging tool that enforces these conditions, throwing ConditionalAppendFailed when constraints are violated. Read operations now support filtering by sequence position, limiting results, and reversing order via ReadOptions.

src · high confidence

Introduce Query and QueryItem classes for event store querying

Added src/Query/Query.php and src/Query/QueryItem.php, introducing a new Query class that supports JSON serialization, merging of query constraints, and event matching. The Query class implements IteratorAggregate and JsonSerializable, allowing queries to be iterated and serialized. The QueryItem class provides a builder for creating query items with event types, tags, and a flag for last event filtering. The merge logic combines compatible query items, and the matchesEvent method checks if an event satisfies the query constraints.

src/Query · high confidence

Introduce SequencedEvent and SequencePosition types

The codebase now includes new value objects for event sequencing: \SequencePosition\ represents a global sequence number with methods to navigate previous and next positions, and \SequencedEvent\ wraps an \Event\ with its position and recording timestamp. The \SequencedEvents\ class provides an iterator over these sequenced events, ensuring uniqueness by position and offering a \first()\ accessor.

src/SequencedEvent · high confidence

Introduce new Event domain classes for event store

Added new classes in the Event namespace (Event, EventData, EventMetadata, EventType, EventTypes, Events, Tag, Tags) that define the structure and behavior of events in the event store. These classes provide type-safe handling of event data, metadata, and tags, with support for JSON serialization and stringable representations.

src/Event · high confidence

Behavioural changes

Add AppendCondition class for event store append operations

A new AppendCondition class has been introduced to manage conditions for the EventStore::append() method. This class encapsulates a Query for failure conditions and an optional SequencePosition for ordering, providing a static create() factory method that accepts either a Query and an integer or SequencePosition for the 'after' parameter.

src/AppendCondition · medium confidence

Added project configuration and tooling files

Added configuration files for code style enforcement (\.editorconfig\, \.php-cs-fixer.dist.php\), static analysis (\phpstan.neon.dist\), and testing (\phpunit.xml\). A \check-coverage.php\ script was added to enforce 100% code coverage, and \.gitattributes\ was created to exclude development and configuration files from exports.

(repo-wide) · high confidence

Test coverage

Added integration tests for the in-memory event store; Added unit tests for AppendCondition and InMemoryEventStore; Added unit tests for Event domain classes; Added unit tests for Query and QueryItem classes; Added unit tests for SequencedEvent components; Added unit tests for exception handling, read options, and README code blocks.

Dependencies

Initial release of wwwision/dcb-eventstore package

The package now requires PHP 8.3 or higher and includes dependencies for PSR Clock, webmozart/assert (versions ^1.11.0 or ^2.0.0), PHPStan ^2, PHP CS Fixer ^3.88, and PHPUnit ^11. This establishes the foundational build configuration and tooling for the project.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 63 → 66 (+3.7)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 98 → 99 (+1.0)
  • Architecture 69 → 69 (+0.0)
  • Maturity 58 → 59 (+1.2)
  • Readiness 68 → 63 (-4.3)
  • Security 61 → 97 (+36.2)

Resolved (16)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (8 lines × 2) (src/Query/QueryItem.php)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No exposed public API
  • Small-team knowledge concentration
  • Test reliability not included
  • The Usage section is clipped mid-sentence, so the Create Event Store instance and higher-level API sections are not yet visible. (README.md)

New (18)

  • Dependency hygiene PARTLY measured — Composer dependencies read, no committed lock to grade for currency
  • Documentation: no usage examples (README.md)
  • Duplicated block (10 lines × 2) (src/Query/QueryItem.php)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Inverted test pyramid
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • No assertions: test_consistency (tests/Integration/EventStoreConcurrencyTestBase.php)
  • No dependency advisory monitoring
  • bus factor 1 — one contributor carries this repository

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

bwaidelich/dcb-eventstore was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 38bccd99f1233a1c11af729e8578fde0a0eff3c0 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.