Skip to content
CAI
Software that uses CAICheck a score

codefyphp/codefy

53.0

Adequate · 21 September 2026

18k

lines of production code

PHP

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

CodefyPHP is a lightweight, object-oriented PHP framework designed for Domain-Driven Design, supporting CQRS and Event Sourcing patterns. It provides a comprehensive suite of infrastructure components including a routing engine, dependency injection, RBAC authentication, and a scheduler. The system also features robust HTTP handling with middleware for security, caching, and validation, alongside tools for database migrations and code scaffolding.

How it got here

2022–2025 — Framework initialization and core subsystems

46 changes.

This period established the CodefyPHP framework with its initial release, featuring a comprehensive Domain-Driven Design architecture, RBAC authentication, and a robust HTTP middleware layer. It involved significant structural reorganization, including namespace rebranding and dependency upgrades, alongside the implementation of core services like scheduling, pipelines, and console scaffolding.

2026 — Security and validation infrastructure

5 changes.

This period focused on establishing core security and input handling mechanisms by introducing a firewall module with threat detection and a standardized HTTP input validation component. The work also expanded debugging capabilities through new DebugBar collectors and ensured reliability by adding comprehensive test coverage for the new security and scheduling systems.

Features

Added DebugBar data collectors for application info and routing

New data collectors have been introduced to the DebugBar integration: CodefyCollector exposes application metadata such as version, PHP version, environment, debug status, URL, timezone, and locale, while RouteCollector captures the current route name and controller for visibility during debugging.

src/DataCollector · high confidence

Added HttpRequestError exception class

A new HttpRequestError class has been introduced in the src/Http/Errors namespace to handle HTTP request-specific errors. This class extends the base Error class from the Qubus/Error library and accepts a message, a code (integer or string), and an optional context array, providing a structured way to represent HTTP-related failures within the framework.

src/Http/Errors · high confidence

Added Rbac-specific exception classes

Introduced SentinelException and UnauthorizedException classes within the Codefy Framework's RBAC module. SentinelException extends the base Qubus Exception, while UnauthorizedException extends the Qubus HttpException, providing structured error handling for authorization failures in this subsystem.

src/Auth/Rbac/Exception · high confidence

Added scaffolding stubs for common application components

The \src/Stubs\ directory now provides a comprehensive set of template files to accelerate the creation of new application elements. These include stubs for domain-driven design components (aggregates, repositories, events, commands, and query handlers), HTTP layer structures (controllers, middleware, form requests, validators, and route definitions), and framework utilities (service providers, console commands, and error classes). This allows developers to quickly scaffold boilerplate code that adheres to the framework's conventions for CQRS, event sourcing, and HTTP handling.

src/Stubs · high confidence

Console subsystem restructured with new code-generation and command infrastructure

The console subsystem has been reorganized under the \Codefy\\Framework\ namespace, introducing a new \ClassGenerator\ that creates files from stub presets with automatic namespace normalization, a \PresetRegistry\ for managing those stubs, and a new \ConsoleCommand\ base class that simplifies command implementation and adds styled terminal output helpers. The \ConsoleKernel\ now implements a dedicated \Kernel\ interface, supports automatic command loading via \addCommands\, and defers schedule definition until the application is booted, while the \ConsoleApplication\ has been updated to use the framework's application version constant and improved output buffering handling.

src/Console · high confidence

Framework support layer restructured with new service providers and middleware defaults

The \src/Support\ directory has been reorganized and expanded to provide core framework utilities and configuration defaults. This includes the introduction of \DefaultProviders\, \DefaultCommands\, and \DefaultMiddlewares\ classes that define the standard set of service providers, console commands, and HTTP middleware (such as security headers, CSRF, and firewall) available to applications. The \CodefyServiceProvider\ abstract class now manages booting callbacks and asset publishing tags, while \RegisterProviders\ handles the merging and registration of these providers. Additionally, new support classes like \ArgsParser\, \StringParser\, \SeoFactory\, and \Server\ have been added to handle argument parsing, query string processing, SEO generation, and URL/SSL detection, alongside refactored existing classes like \LocalStorage\ and \Password\ to support these new structures.

src/Support · high confidence

Initial release of CodefyPHP framework and project scaffolding

This change introduces the initial version of the CodefyPHP framework, a lightweight, object-oriented PHP library designed for Domain Driven Design with CQRS and Event Sourcing support. It provides implementations for various PSR standards (PSR-3, 6, 7, 11, 12, 14, 15, 16, 17) and includes core components such as a routing engine, dependency injector, cache adapters, and an RBAC system. The release establishes the project structure with configuration files for PHP\_CodeSniffer (phpcs.xml) and PHPUnit (phpunit.xml), sets a minimum PHP version requirement of 8.4, and includes a .gitattributes file to manage repository exports.

(repo-wide) · high confidence

Introduces DTO interface contracts for validated data transformation

The src/Dto directory now includes the DataTransformer and HasDto interfaces, establishing a standardized contract for converting validated input into Data Transfer Objects. The HasDto interface defines methods to retrieve the DTO class name and perform the conversion, while DataTransformer provides a static factory method to instantiate DTOs from validated data, enabling a consistent pattern for data input handling across the framework.

src/Dto · high confidence

Introduction of new Auth and Rbac components

The src/Auth directory now contains a new authentication and authorization system. This includes an Auth class for handling user login and unauthorized responses, a Gate interface for permission checks, and a comprehensive Rbac module. The Rbac module provides role-based access control with interfaces for guards and storage resources, including a file-based storage implementation. The system also introduces a UserSession class for managing user sessions and supporting traits for immutable objects and exception handling.

src/Auth · high confidence

New CSRF protection middleware with encrypted tokens and configurable fields

The framework now includes a dedicated CSRF protection layer in \src/Http/Middleware/Csrf\. \CsrfTokenMiddleware\ generates and manages encrypted CSRF tokens (via \Defuse\\Crypto\), storing them in cookies and attaching them to the request for downstream validation. \CsrfProtectionMiddleware\ validates incoming requests by comparing the provided token against the stored one, throwing \TokenMismatchException\ or \InvalidTokenException\ on failure. The system supports configurable cookie names, header names, and form field names via configuration keys (\csrf.header\, \csrf.csrf\_token\). A helper function \csrf\_field()\ is provided to easily render the hidden input field in views.

src/Http/Middleware/Csrf · high confidence

New CsrfTokenAware trait for CSRF token management

A new CsrfTokenAware trait has been added to the CSRF middleware components, providing reusable logic for generating, storing, and validating CSRF tokens. This trait handles token generation using SHA-1 hashing, retrieves existing tokens from cookies, and creates signed encrypted cookies for new tokens to protect against XSS attacks. It integrates with the application's configuration container for settings like salt, cookie name, and lifetime, and uses the Defuse Crypto library for secure token encryption and decryption.

src/Http/Middleware/Csrf/Traits · high confidence

New DDD scaffolding and class generation commands

The framework introduces a new set of console commands under the \ddd:\ namespace to streamline Domain-Driven Design workflows. The \ddd:make\ command allows developers to generate classes from preset stubs by interactively selecting a namespace, subdirectory, and class name, while \ddd:make:domain\ scaffolds a complete domain module structure (including directories for Commands, DTOs, Events, etc.). Additionally, \ddd:uuid\ and \ddd:ulid\ commands provide quick generation of unique identifiers, and the new \GeneratorCommand\ base class handles the underlying file creation and namespace qualification logic.

src/Console/Commands/Domain · high confidence

New DtoAware trait and UseDto attribute for validated data conversion

Introduces the \DtoAware\ trait and \UseDto\ attribute to streamline the conversion of validated input (from Form Requests or Input Validators) into Data Transfer Objects. Classes using the \DtoAware\ trait can now call \toDto()\ or \toDtoArray()\ to automatically instantiate a DTO class specified via the \\#\[UseDto\]\ attribute, provided that DTO class implements the \fromValidatedData\ method.

src/Dto/Trait · high confidence

New FormRequest and FormDataRequest classes for structured HTTP input handling

This change introduces two new classes, FormRequest and FormDataRequest, within the src/Http/Request namespace to standardize how HTTP request data is validated and accessed. FormRequest provides a structured API for retrieving validated input, including a value() method with default support, type-specific accessors (string, integer, float, boolean) that enforce type safety, and methods to filter data (only, except). FormDataRequest extends FormRequest to automatically map validated input fields to object properties upon successful validation. These classes implement the DataValidator interface and integrate with the existing validation framework, offering a more robust and type-safe alternative to raw request parameter access.

src/Http/Request · high confidence

New FormRequest middleware for request validation and authorization

Added a new \FormRequest\ middleware component in \src/Http/Middleware/Request\ that enables declarative validation and authorization for HTTP requests. The \FormRequest\ abstract class integrates with the \Qubus\ validation library to check request inputs against defined rules and messages, returning a 422 JSON response with error details if validation fails. It also supports an \authorize\ check, returning a 401 JSON response if authorization is denied. The \FormRequestErrorResponder\ handles the formatting of these error responses, and \FormRequestHandler\ provides a wrapper to execute the middleware logic before delegating to the inner request handler.

src/Http/Middleware/Request · high confidence

New HTTP input validation component

Introduced the \DataValidator\ interface and \HttpInputValidator\ abstract class in \src/Validation\ to standardize request data handling. \HttpInputValidator\ aggregates query, body, and uploaded file data, provides methods to filter inputs via \only\ and \except\, and integrates with the existing \ValidationFactory\ to enforce rules defined in subclasses, returning validated data or errors.

src/Validation · high confidence

New HTTP middleware and throttling infrastructure

This change introduces new components for spam protection and request rate limiting within the HTTP layer. It adds HoneyPotMiddleware and ReferrerSpamMiddleware to detect and block spam form submissions, and implements a full rate-limiting system via the RateLimiter, Condition, Interval, and RateException classes to enforce request quotas using a PSR-6 cache backend. Additionally, it provides the Swoole App and BridgeManager classes to handle HTTP requests and responses when running the application on the Swoole server.

src/Http/Middleware/Spam, src/Http/Swoole, src/Http/Throttle · high confidence

New HTTP middleware components for security, caching, and optimization

The framework introduces a suite of new HTTP middleware classes in the \src/Http/Middleware\ directory to enhance request handling. Security is addressed with \FirewallMiddleware\ for threat detection and blocking, \ApiMiddleware\ for Bearer token validation, \CorsMiddleware\ for cross-origin resource sharing, and \ThrottleMiddleware\ for rate limiting. Performance and optimization are improved via \ContentCacheMiddleware\ for response caching, and dedicated minifiers for CSS (\CssMinifierMiddleware\), HTML (\HtmlMinifierMiddleware\), and JavaScript (\JsMinifierMiddleware\). Additional utilities include \BindRequestMiddleware\ for request context binding and \DebugBarMiddleware\ for development debugging.

src/Http/Middleware · high confidence

New PDO-based authentication repository implementation

The authentication layer now includes a concrete \PdoRepository\ class that implements the \AuthUserRepository\ interface. This component handles user authentication by querying a configurable database table for credentials and verifying passwords, returning a session entity upon success. It also provides functionality to retrieve user details via a stored token, enabling session validation and recovery.

src/Auth/Repository · high confidence

New Pipeline execution framework

The src/Pipeline directory now contains a new pipeline execution system, introducing the Chainable interface, the Pipeline implementation, and supporting classes like PipelineBuilder and PipelineFactory. This allows developers to construct and execute a series of processing steps (pipes) on data, with support for transactional execution, failure handling, and final callbacks. The PipeAware trait provides a convenient method to pipe objects through this system.

src/Pipeline · high confidence

New RBAC entity interfaces and implementations for permissions and roles

This change introduces the core entity layer for the Role-Based Access Control (RBAC) system. It adds the \AssertionRule\, \Permission\, and \Role\ interfaces, along with their concrete implementations \RbacPermission\ and \RbacRole\. These classes define the structure for managing hierarchical permissions and roles, including methods for adding/removing children, assigning rules, and checking access rights against a storage resource.

src/Auth/Rbac/Entity · high confidence

New application builder and middleware configuration components

The framework introduces a new \ApplicationBuilder\ class in \src/Configuration\ to streamline application setup, offering fluent methods like \withKernels()\, \withProviders()\, \withSingletons()\, and \withRouting()\ to register services and configure routing. It also adds a \withEncryptedEnv()\ method to control environment variable encryption and a \withMiddleware()\ method to manage middleware aliases. A new \Middleware\ helper class supports registering custom middleware aliases via an \alias()\ method, integrating with the application's configuration container to merge custom and default middleware settings.

src/Configuration · high confidence

New database, encryption, and asset management console commands

The framework now includes a comprehensive suite of new console commands for managing the application lifecycle. Database operations are expanded with \db:seed\ (supporting specific seeders, environment overrides, and deterministic Faker seeding), \migrate:fresh\ (dropping all tables and re-running migrations with optional seeding), and a full set of migration tools (\migrate\, \migrate:check\, \migrate:down\, \migrate:generate\, \migrate:redo\, \migrate:rollback\, \migrate:status\, \migrate:up\) for version control and status reporting. Security is enhanced with \encrypt:env\ (expanding and encrypting environment variables) and key generation commands (\generate:key\, \generate:key:file\). Asset management is streamlined with \asset:flush\ to clear pipeline directories, while \migrate:init\ sets up the initial migration structure and \stub:make\ generates class stubs.

src/Console/Commands · high confidence

New firewall security module with threat detection and exclusion policies

This change introduces a new firewall system in the security layer that inspects HTTP requests for threats such as SQL injection, XSS, and file traversal. It includes a ThreatDetector that scans request inputs (method, path, query, body, URI) against a registry of configurable patterns, and allows administrators to define exclusion policies to whitelist specific paths, methods, or sources. The system supports logging detected or excluded threats via pluggable loggers and returns a standardized 403 Forbidden response when a threat is matched.

src/Security · high confidence

New framework traits for validation, logging, exception handling, and encryption

Added four new traits to the framework's trait library: InputValidationAware provides a standard validation lifecycle (authorization, validation, and error handling) using the Qubus Validation library; LoggerAware offers static access to file and SMTP loggers via factory classes; ThrowableTransformAware enables mapping specific Throwable types to HTTP exceptions with a fallback to a generic 500 error; and TokenEncryptionAware provides methods to encrypt, decrypt, and compare tokens using the Defuse Crypto library.

src/Traits · high confidence

New service providers for assets, database, events, and routing

The framework now includes dedicated service providers in src/Providers to manage core infrastructure. Assets are handled via AssetsServiceProvider, which registers singleton asset managers based on configuration groups. Database connectivity is centralized through DatabaseConnectionServiceProvider and PdoServiceProvider, providing singleton instances for PDO and the Qubus Expressive Connection. Event handling is configured via EventDispatcherServiceProvider, aliasing PSR-14 interfaces to specific implementations. HTTP exceptions are managed by HttpExceptionServiceProvider, wiring up strategies for HTML, JSON, and redirect responses. Localization is supported by LocalizationServiceProvider, which loads .mo translation files. Query building is abstracted via QueryBuilderServiceProvider, and routing is configured through RouterServiceProvider and RoutingServiceProvider, which handle route loading from PHP or JSON files and set up the router with base paths and middleware.

src/Providers · high confidence

New strategy-based HTTP exception handling middleware

The framework now includes a new exception handling layer in src/Http/Middleware/Exception that replaces ad-hoc error handling with a structured, strategy-based approach. This change introduces an ExceptionHandler and several middleware classes (HtmlHttpExceptionMiddleware, JsonHttpExceptionMiddleware, RedirectionHttpExceptionMiddleware, StrategyHttpExceptionMiddleware) that intercept HTTP exceptions and unknown errors. The system uses an HttpResponseStrategy interface with concrete implementations (HtmlHttpResponseStrategy, JsonHttpResponseStrategy, RedirectHttpResponseStrategy) to determine the response format based on the request's Accept header (HTML, JSON, or redirect). This allows the application to return appropriate error responses (HTML views, JSON error objects, or redirects with flash messages) depending on the client's content negotiation, while also logging exceptions via a PSR-3 error handler.

src/Http/Middleware/Exception · high confidence

New view rendering components and default error page

The framework now includes dedicated view renderers for the Fenom and Foil template engines, along with a new ErrorViewRenderer that generates HTML responses for HTTP errors using a default error template (error.phtml). This allows the application to render views using either Fenom or Foil and to display a styled, configurable error page when exceptions occur.

src/View · high confidence

Removals

Removal of BaseController class

The \Http/BaseController.php\ file has been deleted, removing the \BaseController\ class that previously provided a foundation for HTTP controllers. This class previously handled dependency injection for request, response, router, and view instances, along with a \redirect\ method for handling HTTP redirects. Its removal indicates a shift in how HTTP controllers are structured or instantiated within the application.

Http · high confidence

Removal of FileLoggerSendmailFactory

The FileLoggerSendmailFactory class has been removed from the codebase. This factory previously configured a combined logging system that wrote to local files and sent emails via SwiftMailer when specific environment variables were set; this capability is no longer available through this component.

Factory · high confidence

Removal of Scheduler Processor interface and Stack class

The \Processor\ interface and the \Stack\ class within the Scheduler component have been removed. This eliminates the previous mechanism for managing task execution stacks, including the logic for dispatching task lifecycle events (started, failed, completed) and handling mutex locking and email notifications during task runs.

Scheduler · high confidence

Removal of legacy core helper functions

The \Helpers/core.php\ file has been deleted, removing the \app\, \config\, \getFreshBootstrap\, \env\, and \db\ helper functions from the \Codefy\\Foundation\\Helpers\ namespace. This eliminates the previous logic for resolving the application bootstrap path, accessing configuration, retrieving environment variables, and instantiating the database ORM builder via static application methods.

Helpers · high confidence

Removed Console command infrastructure

The \ConsoleCommand\ base class and the \MakeCommand\ stub-generator command have been deleted from the codebase. This removes the ability to define custom console commands via the \ConsoleCommand\ abstraction and eliminates the \stub:make\ command that previously generated classes like controllers, models, and forms from predefined stubs.

Console · high confidence

Behavioural changes

Added HTTP cache middleware and relocated console exception

The framework now includes new HTTP middleware classes for managing browser caching behavior: CacheExpiresMiddleware (configurable via 'http-cache' settings), CacheMiddleware, CachePreventionMiddleware, and ClearSiteDataMiddleware (configured via 'http-cache.types'). Additionally, the MakeCommandFileAlreadyExistsException class has been moved from the Foundation package to the Framework package.

src/Console/Exceptions, src/Http/Middleware/Cache · medium confidence

Application bootstrapping and service provider registration restructured

The core Application class has been refactored to improve how the framework initializes and loads components. Service providers are now registered and booted in a specific order to ensure the service provider is loaded before views, addressing previous initialization issues. The application now supports automatic loading of commands and service providers with minimal manual configuration, while also ensuring that assets service providers are correctly scoped and not incorrectly added to the base Application. Additionally, the basePath handling has been fixed to resolve previous issues, and the bootstrapping process now correctly manages the registration state of providers to prevent duplicate or missed registrations.

src · high confidence

Factory classes migrated to Framework namespace and updated for PHP 8.5 compatibility

The factory classes in src/Factory have been moved from the Codefy\\Foundation namespace to Codefy\\Framework, updating all internal imports and namespace declarations accordingly. To address PHP 8.5 deprecations, global namespace classes like SplObjectStorage, ReflectionException, and Exception are now explicitly referenced with leading backslashes, and the SwiftMailer-based logger has been replaced with PHPMailer in the FileLoggerSmtpFactory. Additionally, docblock types have been refined to use strict array syntax and explicit type hints, improving static analysis compliance.

src/Factory · high confidence

HTTP layer refactored with new middleware, base controller, and request handling

The \src/Http\ directory has been restructured to introduce a new \BaseController\ for common HTTP operations, a custom \HttpClient\ extending Guzzle with filterable request arguments, and a \SecureHeaders\ middleware system (including Content Security Policy) for improved security. The \Kernel\ has been moved to \src/Http\, updated to the \Codefy\\Framework\ namespace, and now uses \SapiEmitter\ for response emission instead of the previous \HttpPublisher\. Additionally, a \RequestContext\ class was added to store the current server request.

src/Http · high confidence

Introduction of Codefy proxy class with typed static property

A new \Codefy\ class has been added to the \src/Proxy\ directory, serving as a proxy that holds a static reference to the \Application\ instance. The class defines a strongly-typed static property \$PHP\ of type \Application\, replacing the previous loose typing or nullability associated with the \$PHP\ property to ensure it is always an instance of the Application class.

src/Proxy · high confidence

New encrypted, non-cached user session and authorization middleware pipeline

The framework introduces a new set of authentication and authorization middlewares in src/Http/Middleware/Auth that replace previous session handling. UserSessionMiddleware now manages user sessions without relying on server-side caching, instead encrypting the session token and storing it in an HTTP cookie (configurable via auth.cookie\_name) with support for 'remember me' persistence. UserCookieDecryptMiddleware safely decrypts these cookies using the app's crypto key, attaching the token to the request for downstream use. UserAuthorizationMiddleware verifies that the decrypted cookie token matches the session token, redirecting guests if they are not logged in. GateMiddleware provides configurable access control based on permissions, supporting custom redirect URIs and JSON responses for unauthorized access. ExpireUserSessionMiddleware allows explicit session expiration by clearing the session cookie. These changes enhance security by ensuring session data is encrypted in transit and at rest in the client, and remove the dependency on cached user sessions.

src/Http/Middleware/Auth · high confidence

Refactored path helper functions and added database path support

The path helper functions (such as base\_path, src\_path, config\_path, etc.) have been refactored to use a new join\_paths utility, which standardizes how directory segments are combined. Additionally, a new database\_path helper has been added to retrieve the path to the application's database directory. These changes also include moving the helpers into the src/Helpers directory and updating the namespace from Codefy\\Foundation\\Helpers to Codefy\\Framework\\Helpers.

src/Helpers · high confidence

Scheduler module relocated and refactored for immutability and event dispatching

The Scheduler module has been moved from the Codefy\\Foundation namespace to Codefy\\Framework\\Scheduler. This change introduces immutable task configuration by cloning objects in methods like withOptions, adds a new TaskSkipped event, and updates task lifecycle events (TaskStarted, TaskCompleted, TaskFailed) to implement the legacy Event interface. Processor classes now enforce overlapping locks and dispatch before/after callbacks, while expression classes have been updated with stricter type hints for scheduling parameters.

src/Scheduler · high confidence

Fixes

Introduce NodeQueue implementation with lease-time fix

Added a new NodeQueue implementation for the queue system, including the core NodeQueue class and supporting interfaces (Queue, ReliableQueue, QueueGarbageCollection) and traits (QueueAware). The implementation uses a NoSQL node store to manage queue items and fixes a bug where the lease time was not correctly derived from the queue's configuration, ensuring that task expiration respects the intended lease duration rather than using an arbitrary value.

src/Queue · high confidence

Test coverage

Added test coverage for HTTP middleware and exception handling; Added test coverage for scheduler expression classes; Added test coverage for the security firewall and threat detection system; Added tests for FormRequest validation and authorization; Added tests for the Auth module; Added tests for the Pipeline component; Added unit tests for the Task scheduler; Initial test suite for Application, Helpers, and Firewall infrastructure.

Dependencies

Major framework dependency upgrade and namespace restructure

The project has been rebranded from 'codefyphp/foundation' to 'codefyphp/codefy' and restructured as a library with its main namespace moved from 'Codefy\\Foundation' to 'Codefy\\Framework' under the 'src/' directory. This update requires PHP 8.4 and introduces significant dependency upgrades, including Symfony Console and Options Resolver moving to version 7, and multiple Qubus packages (cache, error, event-dispatcher, exception, expressive, filesystem, injector, mail, router, security, support, validation, view) upgrading to major versions 3, 4, or 5. New dependencies added include 'codefyphp/domain-driven-core', 'forxer/gravatar', 'melbahja/seo', 'paragonie/csp-builder', 'php-debugbar/php-debugbar', and several 'middlewares' packages, while dev dependencies now include 'foil/foil' and 'qubus/qubus-coding-standard'.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 52 → 53 (+0.8)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 93 → 95 (+2.3)
  • Architecture 100 → 87 (-13.1)
  • Maturity 58 → 59 (+1.1)
  • Readiness 24 → 26 (+1.4)
  • Security 100 → 100 (+0.0)
  • Domain Modelling 100 (new)

Resolved (14)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (11 lines × 2) (src/Console/Commands/DatabaseSeedCommand.php)
  • Duplicated block (12 lines × 2) (src/Console/Commands/MigrateCommand.php)
  • Duplicated block (12 lines × 2) (src/Console/Commands/VendorPublishCommand.php)
  • Duplicated block (12 lines × 2) (src/Http/Request/FormRequest.php)
  • Duplicated block (14 lines × 2) (src/Security/Firewall/ThreatPatternRegistry.php)
  • Duplicated block (20 lines × 2) (src/Security/Firewall/ThreatPatternRegistry.php)
  • Duplicated block (8 lines × 2) (src/Console/Commands/MigrateDownCommand.php)
  • Duplicated block (9 lines × 2) (src/Scheduler/Traits/ExpressionAware.php)
  • Duplicated block (9 lines × 3) (src/Scheduler/Expressions/Daily.php)
  • No exposed public API
  • Small-team knowledge concentration
  • Test reliability not included

New (31)

  • ClassTooLong: ThreatPatternRegistry (src/Security/Firewall/ThreatPatternRegistry.php)
  • Dependency hygiene PARTLY measured — Composer dependencies read, no committed lock to grade for currency
  • Documentation: no contributor guidance (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicate accessors for database components with inconsistent naming and return types. getDbConnection and core.dbal both return Connection, while getDb and core.queryBuilder return QueryBuilder. The naming convention is inconsistent between the Application class (get*) and the helper (dbal/queryBuilder), and the distinction between 'Connection' and 'QueryBuilder' is not clearly aligned across the API surface.
  • Duplicate authentication logic across multiple classes. Auth and Sentinel both expose an authenticate method with the same signature and likely similar implementation (handling the request). Similarly, AuthUserRepository and PdoRepository both implement authenticate with identical signatures, suggesting PdoRepository is an implementation of AuthUserRepository but is exposed as a distinct public type with the same method name.
  • Duplicated block (11 lines × 2) (src/Http/Middleware/Auth/UserAuthorizationMiddleware.php)
  • Duplicated block (11 lines × 3) (src/Console/Commands/MigrateDownCommand.php)
  • Duplicated block (12 lines × 2) (src/Http/Request/FormRequest.php)
  • Duplicated block (13 lines × 2) (src/Console/Commands/DatabaseSeedCommand.php)
  • Duplicated block (13 lines × 2) (src/Console/Commands/MigrateCommand.php)
  • Duplicated block (13 lines × 2) (src/Http/Request/FormRequest.php)
  • Duplicated block (13 lines × 2) (src/Http/Request/FormRequest.php)
  • Duplicated block (13 lines × 2) (src/Http/Request/FormRequest.php)
  • Duplicated block (13 lines × 2) (src/Http/Request/FormRequest.php)
  • Duplicated block (13 lines × 2) (src/Http/Request/FormRequest.php)
  • Duplicated block (16 lines × 2) (src/Console/Commands/VendorPublishCommand.php)
  • Duplicated block (19 lines × 2) (src/Security/Firewall/ThreatPatternRegistry.php)
  • Duplicated block (28–31 lines × 2) (src/Security/Firewall/ThreatPatternRegistry.php)
  • …and 11 more

Changes since last survey

  • 2 commits — 1 feature/other, 1 fixes

By area

  • (repo) — 1 commit
  • src/Http — 1 commit

Notable commits

  • fix: Fixed vulnerable CSRF token middleware.
  • change: Merge branch 'main' into 3.3.x

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

codefyphp/codefy was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 9d47b6f6b07e327b68252faa4c28855149ba6631 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.