Skip to content
CAI
Software that uses CAICheck a score

caddyserver/caddy

50.0

Weak · 24 September 2026

62.4k

lines of production code

Go

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a modular, high-performance HTTP server and reverse proxy designed for modern web infrastructure. It provides comprehensive capabilities for serving static and dynamic content, managing TLS certificates via built-in PKI and ACME protocols, and configuring complex routing, rewriting, and authentication rules. The architecture supports extensibility through a plugin system, distributed tracing, and programmatic event handling, all managed via a flexible Caddyfile or JSON configuration interface.

How it got here

2019 — Caddy v2 initial release and modular architecture

27 changes.

This period marks the initial release of Caddy v2, featuring a complete architectural rewrite with a modular plugin system, a new Caddyfile configuration adapter, and a redesigned CLI. The work established the core HTTP server, TLS automation, and reverse proxy modules, while introducing extensive new features such as directory browsing, request templating, and advanced logging capabilities.

2020–2022 — Extensive feature expansion and observability

15 changes.

This period focused on significantly expanding Caddy's capabilities by introducing core infrastructure features such as a native PKI system, an embedded ACME server, and a global eventing framework. It also added substantial observability tools, including Prometheus metrics and OpenTelemetry distributed tracing, alongside new HTTP handlers for server push and value mapping. To support these changes, the project heavily invested in integration testing and improved configuration normalization to ensure stability.

2023–2026 — modular filesystem and proxy enhancements

10 changes.

This period focused on expanding Caddy's modular architecture by introducing a global filesystem registry and a new fs directive for registering custom backends. It also added significant proxy capabilities, including PROXY protocol support and modular network proxy configuration with host validation. Additional features included dynamic log field appending, experimental response interception, and improved internal utilities for logging and configuration warnings.

Features

Add Caddyfile configuration support for the events app

Users can now configure the events application directly via the Caddyfile using the global \events\ option. This new syntax allows defining event subscriptions with the \on\ directive, specifying an event name (or \\*\ for all events) and a handler module, enabling programmatic event handling without requiring JSON configuration.

modules/caddyevents/eventsconfig · high confidence

Add PROXY protocol support via a configurable listener wrapper

Caddy now includes a built-in \caddy.listeners.proxy\_protocol\ module that wraps listeners to handle PROXY protocol headers. This allows Caddy to correctly identify the original client IP when connections are proxied through load balancers or reverse proxies that use the PROXY protocol. The wrapper supports configuring a timeout for header reception, defining allow/deny CIDR lists to control which sources are trusted, and setting a fallback policy (IGNORE, USE, REJECT, REQUIRE, or SKIP) for connections that do not match the allow/deny lists. It is designed to be loaded before the TLS listener to ensure proper handling of encapsulated TLS data.

modules/caddyhttp/proxyprotocol · high confidence

Add request body middleware with size limits and body replacement

A new \request\_body\ HTTP handler module is introduced, allowing administrators to enforce maximum body size limits (returning HTTP 413 when exceeded) and replace the incoming request body with a static string via the Caddyfile \set\ directive.

modules/caddyhttp/requestbody · high confidence

Add systemd and Windows Service status notifications

The notify package now supports sending process-manager status updates on Linux and Windows. On Linux, it implements sd\_notify to inform systemd of readiness, reloading, stopping, status, and error states via the NOTIFY\_SOCKET environment variable. On Windows, it integrates with the Service Control Manager (SCM) to report service states such as running, start/stop pending, paused, and errors, allowing the OS to properly track the service lifecycle. Non-Linux/Windows platforms receive no-op implementations.

notify · high confidence

Add warning struct for Caddyfile conversion notices

A new \Warning\ struct has been added to the \caddyconfig/warning\ package to represent warnings or notices generated during configuration conversion. This struct captures the source file, line number, directive, and message, and provides a formatted string representation for easier debugging and user feedback.

caddyconfig/warning · high confidence

Caddy v2 CLI entry point and build helper

The Caddy v2 command-line interface is now available via a new main entry point in cmd/caddy/main.go, which initializes the Caddy application by importing the standard modules package. A setcap.sh helper script is also included to simplify setting the necessary Linux capabilities for binding to privileged ports during development or custom builds.

cmd/caddy · high confidence

Caddy v2 initial release with modular architecture and Caddyfile support

This entry marks the initial commit of Caddy v2, introducing a complete rewrite of the server with a new modular plugin system, a Caddyfile configuration adapter, and a redesigned module registration API. The diff establishes the core \caddy\ package with new \Module\ and \ModuleInfo\ interfaces, replacing the previous v1 structure, and adds the \caddyfile\ lexer to parse configuration files. It also includes the \httpcaddyfile\ adapter for mapping Caddyfile directives to HTTP handlers, defining the default directive execution order, and handling address parsing and listener management. This change represents a foundational architectural shift rather than a simple feature addition, enabling the new extensibility model and configuration syntax.

github.com/caddyserver/caddy/v2 · high confidence

Configurable Zstandard (zstd) compression with level and checksum options

The zstd encoder now allows users to configure the compression level (fastest, better, best, or default) and optionally enable or disable the 4-byte frame checksum trailer. These settings are exposed in both the JSON configuration and the Caddyfile (via the \level\ subdirective and \disable\_checksum\ flag), giving administrators control over the trade-off between compression ratio and CPU usage, as well as compatibility with clients that may not support checksums.

modules/caddyhttp/encode/zstd · high confidence

Default session ticket key rotation with automatic rotation

Caddy now includes a default module for managing TLS session ticket encryption keys (STEKs) that automatically rotates keys at configurable intervals. This change ensures that session tickets are periodically refreshed, enhancing forward secrecy for encrypted connections without requiring manual intervention.

modules/caddytls/standardstek · high confidence

Global filesystem registration via \`fs\` directive

Users can now globally declare and register named filesystem backends using the new \fs\ directive in the Caddyfile. This change introduces the \caddy.filesystems\ module, which allows administrators to map a key to a specific \fs.FS\ implementation (loaded via the \caddy.fs.\*\ namespace) and register it with the core application context, making these filesystems available for use by other modules throughout the Caddy instance.

modules/caddyfs · high confidence

Initial Caddy v2 Caddyfile adapter implementation and test coverage

This change introduces the complete Caddyfile adapter for Caddy v2, replacing the previous v1 configuration system. It adds the \httpcaddyfile\ package which parses Caddyfile syntax into Caddy's internal JSON configuration, including support for global options (such as \admin\, \log\, \tls\, \pki\, and \order\), site blocks, and directives like \tls\, \root\, \redir\, \respond\, \handle\, \handle\_errors\, \route\, \invoke\, and \log\. The implementation includes fuzz testing for address parsing (\addresses\_fuzz.go\) and comprehensive unit tests for address parsing, directive syntax, global options, and PKI app configuration. This is the foundational adapter that allows users to configure Caddy v2 using the familiar Caddyfile format.

caddyconfig/httpcaddyfile · high confidence

Initial Caddyfile adapter and parser implementation

This change introduces the core Caddyfile adapter and parser components, enabling the conversion of Caddyfile configuration into Caddy JSON. It includes the \Adapter\ struct for the adaptation process, a \Dispenser\ for tokenizing and parsing the configuration structure, and a \Formatter\ to standardize Caddyfile formatting. The implementation also adds support for environment variable expansion, import graph management to handle file imports and detect cycles, and variadic argument placeholders for imported files. Additionally, it provides fuzzing targets for the lexer and formatter to improve robustness.

caddyconfig/caddyfile · high confidence

Initial Prometheus metrics integration

Caddy now exposes gathered metrics for scraping via Prometheus. An unconfigurable admin endpoint is automatically mounted at /metrics when the admin API is active, while a configurable HTTP handler (directive: metrics) allows users to expose metrics on custom routes; this handler supports a disable\_openmetrics subdirective to toggle OpenMetrics format negotiation.

modules/metrics · high confidence

Initial implementation of the Caddy HTTP server module

This change introduces the core \caddyhttp\ module, establishing the foundational HTTP server capabilities for Caddy. It includes the main \App\ struct for managing HTTP/HTTPS servers, automatic HTTPS provisioning logic, and a new CEL-based expression matcher (\MatchExpression\) that allows complex request matching using the CEL syntax. The module also provides essential utilities like path sanitization and error handling structures, along with comprehensive test coverage for these new components.

modules/caddyhttp · high confidence

Internal utilities for logging, socket parsing, and data handling

Added several internal helper packages to support core functionality: a buffered logging core (LogBufferCore) to hold log entries before configuration is fully loaded, redaction logic for sensitive HTTP headers (cookies, authorization) in logs, a utility to limit the display size of large subject lists (e.g., domains), a list of private CIDR ranges for configuration shortcuts, and a parser for Unix socket addresses that includes permission bits in the path.

internal · high confidence

Introduce Argon2id password hashing and restructure authentication module

The caddyauth module now supports the Argon2id password hashing algorithm alongside the existing bcrypt implementation, giving users a more modern and secure option for protecting credentials. This change includes a new \hash-password\ command-line tool that allows generating hashes for both algorithms, with configurable parameters for Argon2id (time, memory, threads, key length) and bcrypt (cost). The HTTP basic authentication provider has been refactored to use a modular hashing interface, allowing easy addition of future algorithms. Additionally, the authentication middleware now sets candidate placeholders (\{http.auth.candidate.\*}\) for rejected identities to aid in debugging, and isolates provider responses to prevent cross-provider interference when multiple authentication providers are configured.

modules/caddyhttp/caddyauth · high confidence

Introduce experimental HTTP templates middleware

Adds a new \templates\ HTTP handler that executes response bodies as Go \text/template\ templates, enabling dynamic content generation within Caddy. This feature supports YAML, TOML, and JSON front-matter parsing, integrates the Sprig function library for advanced template logic, and provides custom actions such as \include\, \httpInclude\, \import\, \readFile\, and \fileStat\ to access files and make virtual requests. The implementation includes Caddyfile parsing for configuration (mime types, delimiters, root, and custom function extensions) and registers the handler as an extensible module under \http.handlers.templates.functions.\*\.

modules/caddyhttp/templates · high confidence

Introduce global eventing system for module hooks

Adds a new \events\ app module that provides a global eventing system, allowing modules to emit and subscribe to events. This enables handlers to take action when specific events occur, add metadata, and control program flow via synchronous propagation similar to HTTP middleware. The system supports hierarchical event propagation (e.g., \a.b.c\ triggers \a.b\ and \a\) and allows subscriptions to be registered during the provisioning phase.

modules/caddyevents · high confidence

Modular network proxy configuration with host validation

Users can now configure the network proxy source via a new modular system, introducing 'url' and 'none' proxy modules. The 'url' module allows specifying a proxy address that supports dynamic placeholders, enabling flexible configuration. Additionally, the system now validates that the resolved proxy URL contains a valid host; URLs that resolve to a port without a host (e.g., 'http://:80') or lack a scheme/host entirely are rejected to prevent misconfiguration.

modules/internal · high confidence

New FastCGI transport and php\_fastcgi directive for PHP applications

Caddy now includes a dedicated FastCGI transport and a convenient \php\_fastcgi\ Caddyfile directive, allowing you to serve PHP applications by proxying requests to a FastCGI responder (such as php-fpm). The \php\_fastcgi\ directive automatically configures the necessary routing, file matching, and try\_files logic for common PHP setups, while the underlying \transport fastcgi\ block exposes granular controls like \root\, \split\_path\, \env\, timeouts, and \resolve\_root\_symlink\. The implementation also enforces strict CONTENT\_LENGTH validation to prevent backend hangs and protects against null-byte injection in request paths.

modules/caddyhttp/reverseproxy/fastcgi · high confidence

New HTTP/2 Server Push handler

Caddy now includes a new \push\ HTTP handler that enables HTTP/2 server push. Users can configure specific resources to push via the Caddyfile (supporting inline resources, method-specific entries, and header customization) or automatically push resources indicated by \Link\ headers in upstream responses. The handler allows customizing headers on push requests and includes safeguards against recursive pushes and remote resource pushes.

modules/caddyhttp/push · high confidence

New OpenTelemetry distributed tracing module

A new \tracing\ HTTP handler module has been added to Caddy, enabling distributed tracing via OpenTelemetry. This module automatically injects and propagates trace context (trace\_id and span\_id) into outgoing requests and makes these identifiers available as placeholders (\{http.vars.trace\_id}\, \{http.vars.span\_id}\) and in access logs when tracing is active. Users can configure a custom span name and add custom span attributes (with placeholder support) via the Caddyfile \tracing\ directive. The implementation uses auto-exporters and auto-propagators based on environment variables, and includes a global tracer provider to prevent goroutine leaks during configuration reloads.

modules/caddyhttp/tracing · high confidence

New admin API endpoints for loading and adapting configuration

The Caddy admin API now exposes /load and /adapt endpoints to manage configuration remotely. The /load endpoint allows replacing the current configuration with a new one, supporting automatic adaptation of non-JSON formats (like Caddyfile) via the Content-Type header, and returns any conversion warnings. The /adapt endpoint lets users convert a configuration to Caddy JSON without applying it, returning the adapted result and warnings. This enables external tools and CI/CD pipelines to validate and transform configurations before deployment.

caddyconfig · high confidence

New built-in PKI app for local certificate authorities

Caddy now includes a native PKI application that allows you to define and manage your own certificate authorities (CAs) for issuing local certificates. You can configure root and intermediate certificates, set custom lifetimes, and control trust store installation. The app provides a command-line interface (\caddy trust\ / \caddy untrust\) to manage system trust stores and exposes an admin API (\/pki/ca/\<id\>\) to retrieve CA information and certificate chains programmatically.

modules/caddypki · high confidence

New directory browsing interface with enhanced security and performance

The file server now includes a completely rewritten directory browsing experience. The new browse template (\browse.html\) features a modern grid layout, lazy-loaded images, and specific SVG icons for various file types (images, video, audio, documents, code, etc.). Security is improved with a strict Content-Security-Policy (CSP) using nonces for scripts and styles. Performance is significantly boosted for large directories through optimized sorting algorithms and preallocation of slice capacity. The browsing logic now correctly handles symlinks (with an optional \reveal\_symlinks\ config to show targets), supports UTC timestamps for the \Last-Modified\ header, and allows limiting the number of listed files via \file\_limit\.

modules/caddyhttp/fileserver · high confidence

New distributed STEK module for cluster-wide TLS session resumption

A new \tls.stek.distributed\ module has been added to Caddy, enabling TLS Session Ticket Ephemeral Keys (STEKs) to be coordinated across a cluster of machines via a shared storage backend. This allows load-balanced environments to optimally resume TLS sessions without relying on external mechanisms like SSH, as the module handles key locking, loading, and rotation through the configured storage module.

modules/caddytls/distributedstek · high confidence

New embedded ACME server handler with policy and configuration options

This change introduces a new \http.handlers.acme\_server\ module that allows Caddy to act as an ACME server for issuing certificates. The handler supports configuring the CA ID, certificate lifetime, DNS resolvers, and specific ACME challenges (http-01, dns-01, tls-alpn-01). It includes a policy system to define allow/deny rules for domains and IP ranges, as well as an option to allow wildcard names. The server uses bbolt for storage and warns if the policy rules are unset, potentially allowing all requests. A new \acme\_server\ Caddyfile directive is provided to configure these options.

modules/caddypki/acmeserver · high confidence

New experimental response interception handler

Adds a new \intercept\ handler that allows modifying or replacing HTTP responses after they are generated. This experimental feature introduces placeholders like \{http.intercept.status\code}\ and \{http.intercept.header.\}\ to inspect the original response, enabling use cases such as X-Sendfile-like redirects or status code overrides without writing the original body to the client.

modules/caddyhttp/intercept · high confidence

New file-system storage module for certificate management

A new \caddy.storage.file\_system\ module has been added to \modules/filestorage\, providing a wrapper around CertMagic's file-based storage. This allows users to configure the local file system as the storage backend for certificates and keys by specifying a \root\ directory in the Caddyfile. The module implements the necessary interfaces to integrate with Caddy's storage system and Caddyfile parsing.

modules/filestorage · high confidence

New forward\_auth directive for Caddyfile configuration

A new \forward\_auth\ directive has been added to the Caddyfile parser, providing a simplified syntax for configuring forward authentication proxies. This directive automatically handles the necessary request rewriting (method to GET, forwarding URI and method) and response handling to copy specific headers from the authentication gateway back to the original client request, reducing the boilerplate required compared to manually configuring a \reverse\_proxy\ with response handlers.

modules/caddyhttp/reverseproxy/forwardauth · high confidence

New log\_append handler for dynamic log fields

A new \log\_append\ HTTP handler has been added to the logging module, allowing users to dynamically append custom fields to access logs. The handler accepts a key and a value, where the value can be a constant string, a variable from the request context, or a placeholder. It supports special placeholders for the request body (\{http.request.body}\) and response body (\{http.response.body}\), automatically buffering the response when necessary to capture the body content. An \early\ option allows the field to be added before the next handler in the chain executes, rather than after.

modules/caddyhttp/logging · high confidence

New logging subsystem with advanced encoding, filtering, and file rotation

The logging module has been rewritten to provide a modular, configurable logging system. Users can now choose between JSON and Console encoders, with the Console encoder defaulting to colorized output when writing to a terminal. A new FilterEncoder allows manipulating log fields using various filters, including hashing sensitive data, masking IP addresses, and filtering query parameters or cookies. Log files can be written with customizable permissions and directory modes, and support automatic rotation with configurable size, time, and compression (gzip or zstd) options. Additionally, a new NetWriter enables sending logs to a network socket with automatic reconnection, and a JournaldEncoder wraps other encoders to add systemd-compatible priority prefixes.

modules/logging · high confidence

New map handler for value mapping and transformation

A new \map\ middleware handler is introduced, allowing users to map a source placeholder value to one or more destination placeholders based on exact matches or regular expressions. The handler supports regex substitution in outputs, evaluates placeholders within output values and defaults, and applies defaults when no mapping matches or when a mapped output is explicitly set to null (using a hyphen \-\ in the Caddyfile). This enables flexible request value transformation and conditional logic directly in the configuration.

modules/caddyhttp/map · high confidence

New metrics utility functions for HTTP request sanitization

The internal/metrics package now includes helper functions to standardize HTTP metrics data. SanitizeCode normalizes HTTP status codes, treating 0 as 200, while SanitizeMethod ensures HTTP method labels are uppercase and limits cardinality by mapping unrecognized methods to 'OTHER'.

internal/metrics · high confidence

New request\_header directive and enhanced header manipulation capabilities

The headers module now supports a new \request\_header\ directive, allowing users to modify incoming request headers (add, set, delete, replace) in addition to the existing response header handling. The \header\ directive for responses has been refined with support for wildcards in delete operations, conditional setting of default values using the \?\ prefix, and deferred execution for deletions or when explicitly requested. Users can now also replace substrings in header fields using either simple string matching or regular expressions, and response header operations can be conditioned on response status codes or other header values.

modules/caddyhttp/headers · high confidence

Refactored TLS issuance and automation into modular, pluggable components

The \modules/caddytls\ package has been restructured to replace the previous monolithic ACME client with a modular issuance system. This change introduces the \ACMEIssuer\ module for managing certificate lifecycles via ACME (including support for ZeroSSL and external account bindings), and the \AutomationPolicy\ module for defining granular policies on certificate management, renewal, and storage. Additionally, certificate selection is now handled by the pluggable \CustomCertSelectionPolicy\, and trusted CA pools are provided by a suite of modular sources (\InlineCAPool\, \FileCAPool\, \PKIRootCAPool\, etc.) that can be composed. These modules allow users to configure certificate issuance, selection, and trust roots through flexible JSON and Caddyfile configurations rather than global settings.

modules/caddytls · high confidence

Standard module bundle now includes event system and metrics support

The standard Caddy module bundle has been expanded to include the event system and Prometheus metrics integration. Users importing this module will now automatically have access to the new event handling capabilities and the ability to expose metrics, alongside the previously included HTTP, TLS, PKI, and logging modules.

modules/standard · high confidence

Removals

Removal of the caddy2 command-line entry point

The \cmd/caddy2/main.go\ file has been deleted, removing the specific command-line entry point that previously started the server on \127.0.0.1:1234\ using legacy Bitbucket import paths. This change eliminates the hardcoded startup configuration and the associated module imports for \caddyhttp\ and \dynamicconfig\ from this location.

cmd/caddy2 · high confidence

Architecture

Consolidation of standard HTTP modules into a single import package

A new \standard\ package has been introduced to aggregate imports for core Caddy HTTP modules, simplifying the process of enabling built-in features. This change bundles essential handlers and middleware—including authentication, content encoding (brotli, gzip, zstd), file serving, header manipulation, response interception, logging, mapping, proxy protocol support, HTTP/2 push, request body handling, reverse proxy (with FastCGI and forward auth), rewriting, templating, timeouts, and OpenTelemetry tracing—into a single import path, allowing users to enable the full suite of standard HTTP capabilities with one import statement.

modules/caddyhttp/standard · high confidence

Behavioural changes

Caddy CLI restructured around the Cobra command framework

The command-line interface has been refactored to use the spf13/cobra library, replacing the previous single-dash argument style with a modern, pluggable subcommand structure. This change introduces a factory-based root command setup and standardizes help text, error handling, and flag parsing across all subcommands (such as run, start, stop, and reload). Users will now interact with a consistent Cobra-driven CLI that supports standard help templates, version output, and structured error logging.

cmd · high confidence

Encode middleware adds zstd priority, SSE header flushing, and comprehensive test suite

The encode middleware now prioritizes zstd and brotli over gzip in content negotiation when no explicit preference is set, and it ensures that response headers for Server-Sent Events (SSE) are flushed immediately to the client rather than being buffered for minimum length checks. This change is accompanied by the addition of a standard benchmark and conformance test harness to verify encoder contract compliance, response semantics (including Vary, ETag, and Cache-Control handling), and the new SSE behavior.

modules/caddyhttp/encode · high confidence

Gzip compression now uses an optimized library

The gzip encoder module has been updated to use the klauspost/compress library instead of the standard library implementation. This change improves compression performance for gzip-encoded responses while maintaining the same configuration interface (compression level setting) and precompressed file support (.gz suffix).

modules/caddyhttp/encode/gzip · high confidence

Introduction of a global filesystem registry

The internal/filesystems package now provides a global registry for managing multiple filesystem implementations. A new \FileSystemMap\ allows components to register and retrieve named filesystem instances via keys, with a built-in default filesystem backed by the local OS. This replaces ad-hoc filesystem handling with a centralized, thread-safe map that supports dynamic registration and unregistration of filesystem sources.

internal/filesystems · high confidence

Reverse proxy active health checks now isolate state per configuration

Active health checks for upstreams sharing the same network address but configured with different health endpoints (e.g., different URIs) now maintain independent pass/fail counters. Previously, the health state was shared by the dial address, causing one configuration's failures to incorrectly mark another's upstream as unhealthy. Additionally, the active health check body now preserves unknown placeholders (such as JSON braces) while still replacing known ones, preventing user-supplied JSON bodies from being blanked out during checks.

modules/caddyhttp/reverseproxy · high confidence

Rewrite module gains granular URI manipulation and query string operations

The rewrite handler now supports detailed URI modifications beyond simple path rewrites. Users can strip prefixes or suffixes from the path, perform substring replacements, apply regular expression replacements to the path, and mutate query strings (including adding, replacing, or removing keys). The \uri\ Caddyfile directive consolidates these capabilities (strip\_prefix, strip\_suffix, replace, path\_regexp, query), while the \method\ directive allows changing the HTTP verb. The handler also correctly handles URI fragments and preserves non-canonical path encoding during replacements.

modules/caddyhttp/rewrite · high confidence

Fixes

Admin API host allow-list comparison is now case-insensitive

The admin endpoint's host allow-list check now correctly treats host names as case-insensitive, aligning with RFC 3986. This ensures that requests with mixed-case Host headers (e.g., \Example.com\) are no longer incorrectly rejected when the allow-list contains a different case (e.g., \example.com\).

(repo-wide) · high confidence

Test coverage

Added dummy TLS client certificate verifier mock; Added test fixtures for Caddyfile parser edge cases and placeholder expansion; Expanded Caddyfile adapt test coverage for ACME, TLS, and HTTP features; Expanded integration test coverage for Caddy modules; New test fixtures and configuration normalization in caddytest.

Dependencies

Update Go dependencies and minimum version to 1.25.1

The project's dependency manifest has been updated to require Go 1.25.1 and includes upgrades to key libraries such as CertMagic (v0.25.4), quic-go (v0.60.0), OpenTelemetry (v1.44.0), and golang.org/x/crypto (v0.55.0).

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 50 → 50 (+0.1)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 55 → 71 (+16.0)
  • Architecture 100 → 99 (-0.1)
  • Maturity 64 → 63 (-0.9)
  • Readiness 47 → 58 (+11.7)
  • Security 76 → 73 (-3.5)
  • Accessibility 43 → 33 (-9.4)

Resolved (108)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (caddyconfig/httpcaddyfile/builtins.go)
  • Duplicated block (10 lines × 2) (caddyconfig/httpcaddyfile/builtins.go)
  • Duplicated block (10 lines × 2) (cmd/packagesfuncs.go)
  • Duplicated block (10 lines × 2) (modules/caddyhttp/celmatcher.go)
  • Duplicated block (10 lines × 2) (modules/caddyhttp/celmatcher.go)
  • Duplicated block (10 lines × 2) (modules/caddyhttp/reverseproxy/caddyfile.go)
  • Duplicated block (10 lines × 2) (modules/caddyhttp/reverseproxy/caddyfile.go)
  • Duplicated block (10 lines × 2) (modules/caddyhttp/reverseproxy/caddyfile.go)
  • Duplicated block (10 lines × 2) (modules/caddyhttp/reverseproxy/caddyfile.go)
  • Duplicated block (10 lines × 2) (modules/caddyhttp/reverseproxy/caddyfile.go)
  • Duplicated block (10 lines × 2) (modules/caddyhttp/reverseproxy/upstreams.go)
  • Duplicated block (10 lines × 2) (modules/caddytls/acmeissuer.go)
  • Duplicated block (10 lines × 2) (modules/caddytls/matchers.go)
  • Duplicated block (10 lines × 3) (modules/caddyhttp/matchers.go)
  • Duplicated block (10 lines × 3) (modules/caddyhttp/reverseproxy/caddyfile.go)
  • Duplicated block (11 lines × 2) (caddy.go)
  • Duplicated block (11 lines × 2) (caddyconfig/httpcaddyfile/options.go)
  • Duplicated block (11 lines × 2) (cmd/storagefuncs.go)
  • …and 88 more

New (365)

  • ClassTooLong: Handler (modules/caddyhttp/reverseproxy/reverseproxy.go)
  • ClassTooLong: Server (modules/caddyhttp/server.go)
  • ClassTooLong: ServerType (caddyconfig/httpcaddyfile/httptype.go)
  • ClassTooLong: TLS (modules/caddytls/tls.go)
  • Dependency advisory scan runs only on code events
  • Dependency pinned to a stale untagged commit: github.com/aryann/difflib
  • Dependency pinned to a stale untagged commit: github.com/yuin/goldmark-highlighting/v2
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no project overview (README.md)
  • Duplicated block (10 lines × 2) (caddyconfig/httpcaddyfile/httptype.go)
  • Duplicated block (10 lines × 2) (modules/caddyhttp/proxyprotocol/module.go)
  • Duplicated block (10 lines × 2) (modules/caddyhttp/reverseproxy/caddyfile.go)
  • Duplicated block (10 lines × 2) (modules/caddyhttp/reverseproxy/caddyfile.go)
  • Duplicated block (10 lines × 2) (modules/caddyhttp/reverseproxy/caddyfile.go)
  • Duplicated block (10 lines × 2) (modules/caddyhttp/reverseproxy/healthchecks.go)
  • Duplicated block (10 lines × 2) (modules/caddyhttp/reverseproxy/healthchecks.go)
  • Duplicated block (10 lines × 2) (modules/caddyhttp/staticerror.go)
  • Duplicated block (10 lines × 2) (modules/caddytls/acmeissuer.go)
  • Duplicated block (10 lines × 2) (modules/caddytls/acmeissuer.go)
  • Duplicated block (10 lines × 2) (modules/caddytls/matchers.go)
  • …and 345 more

Changes since last survey

  • 56 commits — 44 feature/other, 12 fixes

By area

  • modules/caddyhttp — 24 commits
  • (root) — 14 commits
  • caddytest/integration — 4 commits
  • caddyconfig/httpcaddyfile — 3 commits
  • caddyconfig/caddyfile — 2 commits
  • cmd/packagesfuncs.go — 2 commits
  • modules/caddytls — 2 commits
  • caddyconfig/httploader.go — 1 commit
  • modules/caddyevents — 1 commit
  • modules/caddypki — 1 commit
  • modules/internal — 1 commit
  • modules/logging — 1 commit

Notable commits

  • fix: admin: fix host allow-list comparison to be case-insensitive (#7993)
  • fix: admin: fix origin allow-list host comparison to be case-insensitive (#7973)
  • fix: admin: fix warnings and status code in /load API (#7267)
  • fix: caddyfile: fix importGraph self-loop and stale-edge bugs (#7971)
  • fix: caddyhttp: fix url_pattern authorization bypass via encoded-slash traversal (#7941)
  • fix: chore: fix lint errors from newer golangci-lint (#7958)
  • fix: core: fix ParseNetworkAddress port-range span off-by-one (#7975)
  • fix: fastcgi: fix HTTPoxy vulnerability (#7934)
  • fix: fix: close resources on error paths (#7940)
  • fix: fix: require module path boundaries when matching packages (#7957)
  • fix: rewrite: fix URI splitting when a query or fragment arrives via a placeholder (#7947)
  • fix: rewrite: fix strip_path_suffix ignoring percent-encoding (#7877)
  • change: Merge commit from fork
  • change: Merge commit from fork
  • change: Merge commit from fork
  • change: acmeserver: say when the CA database is locked by another process (#8007)
  • change: admin: normalize request path in remote admin access-control check (defense-in-depth) (#7910)
  • change: admin: stabilise log redaction test (#7942)
  • change: build(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.1 (#7984)
  • change: build(deps): bump google.golang.org/grpc from 1.83.1 to 1.83.2 (#8028)
  • …and 36 more

Architecture

  • Unchanged — 0 containers · 1 contexts · 0 edges

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

caddyserver/caddy was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 7ee4441f9261d649eed215f27331352c1ab5a746 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-923689c465cf.