Skip to content
CAI
Software that uses CAICheck a score

DefiFundr-Labs/defifundr_backend

64.0

Adequate · 21 September 2026

8.8k

lines of production code

Go

with Python

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a comprehensive financial and administrative platform that manages user identities, corporate profiles, and compliance workflows. It provides core infrastructure for authentication, email notifications, and database operations, while also supporting complex business domains such as payroll, invoicing, and tax management. The architecture includes multi-chain blockchain integration for tracking crypto holdings and utilizes modern tooling for observability, security, and deployment.

How it got here

2023–2025 — Backend infrastructure and core domain modeling

20 changes.

The project established a robust Go-based backend architecture, introducing a centralized configuration system, structured error handling, and comprehensive database access layers using sqlc. This period also focused on operational tooling, including database migration scripts, automated backups, and a database seeding utility, while simultaneously removing legacy Solidity contract drafts.

2026 — Core feature scaffolding and auth infrastructure

5 changes.

The project established the foundational structure for a wide range of business features, each initialized with domain models, DTOs, and route registrations. Simultaneously, the team implemented comprehensive authentication, session management, and user profile capabilities, supported by PASETO-based token generation and Prometheus metrics for monitoring.

Features

Add HTTP, Auth, Waitlist, and Error Metrics

The application now exposes Prometheus metrics for HTTP requests (total count, duration, and in-flight count), authentication attempts and registrations, token refreshes, waitlist signups, and application errors. This enables monitoring of request volumes, latency, and error rates across these key areas.

pkg/metrics · high confidence

Add OpenTelemetry-based distributed tracing infrastructure

The application now includes a complete OpenTelemetry tracing setup, enabling distributed trace collection and monitoring. This change introduces core tracing utilities for HTTP clients and Gin middleware, allowing requests to be tracked across service boundaries. It also provides a configurable TracerProvider that supports both stdout (for local development) and OTLP/gRPC exporters (for production), with options to disable tracing or adjust sampling rates.

pkg/tracing · high confidence

Add database migration and automated backup scripts

The scripts directory now includes automation for database management and data protection. Developers can create, apply, roll back, reset, and check the status of database migrations using the goose tool via new shell scripts (migrate.sh, migrate\_create.sh, migrate\_down.sh, migrate\_reset.sh, migrate\_status.sh). Additionally, the repository adds Python-based backup utilities (auto\_database\_backup.py, postgres-direct-backup.py, and a Docker-specific backup script) that handle database dumps, file compression, checksum generation, and retention-based cleanup, providing new capabilities for backing up and restoring the application's data.

scripts · high confidence

Add database queries for core business domains

Introduces SQL query files for multiple new features: audit and activity logging, authentication and session management, company and user management, compliance (KYC/KYB) document handling, invoice processing, notifications, payroll periods and items, system/company/user settings, timesheet tracking, and wallet/fiat transactions. These queries enable the backend to interact with the corresponding database tables for these domains.

db/query · high confidence

Add database seeding tool with CLI options

Introduced a new database seeding utility in the cmd/seed directory, providing a flexible mechanism to populate the DefiFundr database with realistic test data. The tool supports three data volume profiles (small, medium, large) and allows users to control the seeding process via command-line flags, including selecting specific tables, preserving existing data, setting random seeds for reproducibility, and adjusting user/transaction counts. A comprehensive README documents the usage, features, and entity relationships supported by the seeder.

cmd/seed · high confidence

Add email priority and attachment structures

Users can now define email attachments and specify priority levels (Low, Normal, High, Critical) for outgoing messages, enabling more granular control over email delivery and content.

pkg/utils · high confidence

Add password and data hashing utilities

A new \pkg/hash\ package provides password hashing via bcrypt and data hashing via HMAC-SHA256, along with a helper for generating random strings, enabling secure credential and token handling within the application.

pkg/hash · high confidence

Add password hashing and verification using Argon2id

The \infrastructure/hash\ package now provides \HashPassword\ and \CheckPassword\ functions using the Argon2id algorithm. The implementation enforces a 72-byte password length limit, generates cryptographically secure random salts, and supports configurable memory, iteration, and parallelism parameters via environment variables (e.g., \ARGON2\_MEMORY\). The hash format follows the standard \$argon2id$v=19$m=...,t=...,p=...$salt$hash\ structure. Tests and benchmarks are included to verify correct hashing, verification, and parameter loading.

infrastructure/hash · high confidence

Added blockchain portfolio experiment for multi-chain token balance checking

A new Go-based experiment in the documentation/experiment directory enables querying ERC20 token balances (USDT, USDC, DAI) across multiple EVM-compatible networks (Ethereum, Polygon, Base, Arbitrum, Optimism, BSC) using a connection pool for RPC endpoints. This adds a new capability to track and report multi-chain crypto holdings, including formatted balances, USD values, and performance metrics.

documentation/experiment · high confidence

Added development and deployment configuration files

The project now includes essential configuration files to support the development workflow and deployment infrastructure. A \.air.toml\ file has been added to configure hot-reloading for the Go API server during development. A \.env.example\ file provides a template for required environment variables, including database connections, authentication keys, and logging settings. The \.gitignore\ file is introduced to prevent tracking of sensitive environment files, IDE configurations, and temporary files. Additionally, a \.golangci.yml\ file configures the Go linter with specific rules and a 9-minute timeout. Deployment is supported via a \Dockerfile\ for containerized builds, a \docker-compose.yml\ for orchestrating the API, PostgreSQL, pgAdmin, Prometheus, and Grafana services, and a \koyeb.yaml\ for Koyeb cloud deployment. A \Makefile\ is added to streamline common tasks such as running migrations, generating SQL code, and managing the development environment. These changes establish the foundational tooling and environment setup for the project.

(repo-wide) · high confidence

Adds core infrastructure for logging, authentication, and request tracking

The application now includes a structured logging system (using zerolog) with configurable output, level, and format, alongside middleware for HTTP request/response logging, Prometheus metrics, rate limiting, and JWT-based authentication. This introduces request tracking via unique IDs, device tracking, and MFA enforcement hooks, providing the foundation for observability and security across the platform.

infrastructure/middleware · high confidence

Asynchronous email delivery via an internal queue

The mail infrastructure now supports asynchronous email sending. An in-memory queue (AsyncQueue) and worker pool process email messages, allowing SendEmail and SendEmailWithAttachment to enqueue messages for background delivery rather than sending them synchronously. The EmailService layer (providing password reset, waitlist confirmation, and batch update emails) and the EmailWorker (handling template rendering and SMTP sending) are introduced to support this new async flow.

infrastructure/mail · high confidence

Centralized application configuration via Viper

The application now uses a centralized configuration system powered by Viper, loading settings from a .env file with sensible defaults for database connections, HTTP server settings, token durations, logging, and email services. This allows users to easily manage environment-specific settings and credentials without modifying code.

config · high confidence

Initial API server setup with comprehensive service and feature integration

The API server entry point (cmd/api/main.go) has been established, wiring together the core application components. This includes the initialization of database connections, repositories, and services for authentication, user management, and waitlist management. The server also integrates an asynchronous email service for notifications and implements OpenTelemetry for distributed tracing and observability. Additionally, HTTP middleware for logging and CORS is configured, and the application is set up to serve Swagger documentation for the API.

cmd/api · high confidence

Initial database query layer for core business domains

The application's database access layer has been established using sqlc v1.29.0, generating Go code for SQL queries across multiple domains. This includes models and query functions for user authentication and sessions, company and KYB (Know Your Business) verification, compliance and KYC (Know Your Customer) document management, invoicing, payroll, and notifications. The generated code provides the data access methods required to support the waitlist, company, and user tracking features.

db/sqlc · high confidence

Initial database schema for user, company, and compliance management

The database schema is expanded to support core platform features, including user and company profiles, KYC/KYB verification workflows, wallet and payment infrastructure, payroll and timesheet management, invoicing, HR (leave and expenses), tax calculations, notifications, and audit logging. This establishes the foundational data structures for identity, financial transactions, and compliance tracking.

db/migrations · high confidence

Initial domain, DTO, and router scaffolding for multiple business features

The application now includes the foundational structure for a wide range of business capabilities, including HR, KYC, Tax, Admin, Wallet, Company, Invoice, Network, Payroll, Blockchain, Compliance, and Transaction features. Each feature is scaffolded with domain models, request and response Data Transfer Objects (DTOs), and HTTP route registrations that enforce authentication. Currently, all endpoints return a 'coming soon' placeholder response, indicating that the core implementation for these features is pending.

(repo-wide) · high confidence

Introduce comprehensive authentication and session management capabilities

The authentication feature now supports full user lifecycle management, including email/password and OAuth (Web3Auth) login, registration, and session handling. Users can now link blockchain wallets, manage active devices and sessions, and secure their accounts with multi-factor authentication (MFA). The system also supports password resets via OTP, tracks security events, and provides profile completion status. These changes are reflected in the new domain models, DTOs, handlers, and repository implementations within the auth feature.

internal/features/auth · high confidence

Introduce structured application error handling and utility packages

The application now includes a structured error handling system in \pkg/apperrors\, defining an \AppError\ type that wraps standard Go errors with specific HTTP status codes and error types (such as validation, not found, conflict, unauthorized, forbidden, and internal server errors). This allows for consistent error responses across the API. Additionally, new utility packages \pkg/pagination\ and \pkg/random\ have been added to support pagination logic and generate random test data (e.g., strings, OTPs, phone numbers).

pkg/apperrors · high confidence

Introduce user profile management and waitlist sign-up capabilities

Users can now update their profile, change their password, and sign up for the waitlist. The user feature adds endpoints to retrieve, update, and manage user profiles, including personal and company information, as well as KYC data. The waitlist feature allows users to join the waitlist, with automatic generation of referral codes and email confirmations. Administrators can view waitlist statistics, list entries, and export data to CSV.

internal/features/user, internal/features/waitlist · high confidence

Introduction of PASETO-based token generation and validation

The system now supports creating and verifying JSON Web Tokens using the PASETO protocol. The new token package includes a Maker interface and PasetoMaker implementation that encrypts payloads containing the user's email, user ID, issue/expiry times, and a new 'userType' field. Users can now authenticate via tokens that carry the user's type, enabling role-based access control for different user categories.

pkg/token · high confidence

Removals

Removal of the CrowdFunding smart contract

The CrowdFunding contract, which previously allowed users to create, manage, and donate to crowdfunding campaigns, has been removed from the codebase. This change eliminates all associated functionality, including campaign creation, donation processing, and donor tracking.

contract · high confidence

Behavioural changes

Cleanup of incomplete and empty Solidity contract drafts

The \crowd-funding\ Solidity contract history was cleaned up by removing multiple incomplete or empty draft files. This includes the removal of empty placeholder files and the deletion of the \voteRequest\ function, which was previously incomplete or partially implemented. The remaining contract retains the core crowdfunding logic, including contribution, refund, and request creation features.

.history · high confidence

Test coverage

Added synthetic transaction generator and alert testing utilities

Added new test files to support observability and validation workflows. The \test/alerts/alert\_tester.go\ file introduces a utility for simulating high error rates and high latency conditions to trigger corresponding alerts. The \test/synthetic/transaction\_generator.go\ file provides a synthetic transaction generator that continuously creates and sends random transaction data to a local endpoint, enabling validation of transaction processing and system health.

test · high confidence

Dependencies

Update Go dependencies and module configuration

The project's Go module configuration (go.mod) and dependency manifest (go.sum) have been updated. The module path was changed from 'github.com/demola234/defiraise' to 'github.com/demola234/defifundr', and the Go version was upgraded from 1.20 to 1.23.0 (with toolchain 1.23.2). A significant number of dependencies were added or updated, including the Ethereum client library (go-ethereum v1.15.11), the JWT library (golang-jwt/jwt/v4 v4.5.2), the PASETO library (o1egl/paseto v1.0.0), and various OpenTelemetry and Gin-related packages.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 58 → 64 (+6.2)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 96 → 92 (-4.0)
  • Architecture 100 → 86 (-13.6)
  • Maturity 71 → 77 (+5.7)
  • Readiness 66 → 67 (+1.5)
  • Security 39 → 52 (+12.2)
  • Domain Modelling 83 → 83 (+0.0)

Resolved (55)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (internal/features/auth/repository/auth_repository.go)
  • Duplicated block (10 lines × 2) (internal/features/auth/repository/auth_repository.go)
  • Duplicated block (10 lines × 2) (internal/features/user/handler/user_handler.go)
  • Duplicated block (10 lines × 2) (internal/features/waitlist/handler/waitlist_handler.go)
  • Duplicated block (10 lines × 3) (internal/features/user/handler/user_handler.go)
  • Duplicated block (11 lines × 2) (internal/features/auth/usecase/auth_usecase.go)
  • Duplicated block (11 lines × 2) (internal/features/user/handler/user_handler.go)
  • Duplicated block (13 lines × 3) (internal/features/auth/handler/auth_handler.go)
  • Duplicated block (5 lines × 2) (internal/features/auth/handler/auth_handler.go)
  • Duplicated block (5 lines × 2) (internal/features/auth/handler/auth_handler.go)
  • Duplicated block (5 lines × 2) (internal/features/auth/repository/auth_repository.go)
  • Duplicated block (6 lines × 2) (documentation/experiment/main.go)
  • Duplicated block (7 lines × 2) (internal/features/auth/handler/auth_handler.go)
  • Duplicated block (7 lines × 2) (internal/features/auth/handler/auth_handler.go)
  • Duplicated block (7 lines × 2) (internal/features/auth/usecase/auth_usecase.go)
  • …and 35 more

New (142)

  • CI installs an unverified third-party binary (.github/workflows/defifundr-ci.yml)
  • ClassTooLong: Handler (internal/features/auth/handler/auth_handler.go)
  • ClassTooLong: authUseCase (internal/features/auth/usecase/auth_usecase.go)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency pinned to a stale untagged commit: gopkg.in/gomail.v2
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no licence statement (docs/observability/MONITORING_PROCEDURES.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (11 lines × 2) (internal/features/auth/handler/auth_handler.go)
  • Duplicated block (11 lines × 2) (internal/features/auth/repository/auth_repository.go)
  • Duplicated block (11 lines × 2) (internal/features/user/handler/user_handler.go)
  • Duplicated block (12 lines × 3) (internal/features/auth/handler/auth_handler.go)
  • Duplicated block (12 lines × 3) (internal/features/user/handler/user_handler.go)
  • Duplicated block (14 lines × 2) (internal/features/auth/handler/auth_handler.go)
  • Duplicated block (14 lines × 2) (internal/features/auth/usecase/auth_usecase.go)
  • Duplicated block (14 lines × 2) (internal/features/user/repository/user_repository.go)
  • Duplicated block (15 lines × 2) (internal/features/auth/repository/auth_repository.go)
  • Duplicated block (2–6 lines × 3) (internal/features/auth/handler/auth_handler.go)
  • …and 122 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

DefiFundr-Labs/defifundr_backend was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 72aae90046a1a17c64a981285a46512adfaf0d3c — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.