Skip to content
CAI
Software that uses CAICheck a score

docsifyjs/docsify

55.1

Adequate · 1 October 2026

6.8k

lines of production code

JavaScript

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Docsify is a lightweight documentation generator that renders Markdown files into static HTML sites directly in the browser. It features a modular architecture supporting virtual routes, multiple history modes, and a plugin system for search, analytics, and comments. The system includes a modernized rendering engine with native emoji support, embedded content handling, and configurable theming with dark mode.

How it got here

2016–2017 — Docsify v5 modernization and rewrite

17 changes.

This period focused on the comprehensive v5.0.0 release, which involved a complete architectural rewrite of the core library to support ES Modules, TypeScript, and modern build tooling. The work introduced significant new features such as virtual routes, a modular rendering engine, and enhanced search capabilities, while simultaneously removing legacy code and dependencies to improve developer experience and code quality.

2020–2025 — modular compiler and test infrastructure

10 changes.

The project refactored the Markdown rendering engine into modular components and overhauled the theme system to support dark mode and GitHub-style callouts. Concurrently, a comprehensive testing infrastructure was established using Jest and Playwright, introducing extensive unit, integration, and end-to-end test suites to verify core functionality and type definitions.

Features

Add front matter parsing plugin

Introduces a new front-matter plugin that parses YAML metadata (delimited by \---\ or \= yaml =\) from the top of markdown files. The plugin exposes parsed attributes via \vm.frontmatter\ for use in templates or logic, and automatically strips the front matter block from the content passed to the markdown renderer. It also registers a \parseMarkdown\ hook to handle front matter removal for embedded pages.

src/plugins/front-matter · high confidence

New and updated documentation plugins

This release introduces several new plugins to extend Docsify's capabilities: a Disqus plugin for comment integration, a Gitalk plugin for GitHub-based comments, a Google Analytics gtag.js plugin (replacing the legacy ga plugin), a Matomo analytics plugin, an external-script plugin to handle inline script tags, and a zoom-image plugin powered by medium-zoom for image enlargement. Additionally, the existing emoji plugin has been deprecated as of v4.13, with a console notice informing users of its removal.

src/plugins · high confidence

New modular rendering engine with native emoji and embedded content support

The \src/core/render\ module has been restructured into a modular architecture, introducing a new \Compiler\ class that orchestrates Markdown processing via \marked\ and a suite of specialized sub-compilers (for headings, links, code, images, and tables). This update adds support for embedding external files (Markdown, code, Mermaid, HTML, video, and audio) directly into pages using the \:include\ syntax, with logic to resolve relative paths and strip front matter. It also introduces native Unicode emoji rendering as an alternative to image-based fallbacks, controlled by the \nativeEmoji\ configuration, and improves heading slug generation by normalizing to NFC and stripping emoji variation selectors.

src/core/render · high confidence

Removals

Removal of core application files

The core application files \src/ajax.js\, \src/index.js\, and \src/render.js\ have been deleted. This removes the original implementation of the Docsify class, including its AJAX-based markdown loading, DOM rendering logic, and the custom marked/Prism configuration for headings and code highlighting.

src · high confidence

Removal of legacy lib/docsify.js and lib/docsify.min.js files

The bundled source and minified JavaScript files for Docsify in the lib directory have been deleted. This removes the legacy implementation that relied on marked and Prism (or highlight.js) for rendering Markdown content directly in the browser, indicating a shift away from this specific build artifact.

lib · high confidence

Architecture

Refactored history router into modular ES classes

The history router implementation has been restructured from a monolithic script into three distinct ES modules: a base \History\ class in \base.js\ containing shared logic (aliasing, file resolution, URL generation), a \HashHistory\ class in \hash.js\ handling hash-based routing, and an \HTML5History\ class in \html5.js\ handling HTML5 push-state routing. This change improves code maintainability and separation of concerns without altering the external API or user-facing behavior.

src/core/router/history · high confidence

Behavioural changes

Complete theme system overhaul with new dark mode and sidebar controls

The theme architecture has been restructured into modular, shared CSS files (e.g., \\_sidebar.css\, \\_markdown.css\) and a new \core-dark.css\ addon that provides a complete dark mode palette and forces light mode for embedded iframes. This update introduces configurable sidebar behaviors, including collapsible root groups, customizable chevron positioning (left/right), and visual group styles (box/underline). It also adds GitHub-style callouts with distinct color coding for caution, important, note, tip, and warning states, alongside a new Vue-themed addon with specific typography and syntax highlighting.

src/themes · high confidence

Docsify v5 core restructured with virtual routes and plugin error handling

The core library has been restructured for v5, introducing a new \Docsify\ class that composes lifecycle, router, render, fetch, and event modules. A key addition is Virtual Routes support, allowing users to define dynamic content via the \routes\ configuration option using regex patterns and handlers. The configuration system now supports function-based initialization and includes new options like \catchPluginErrors\ to gracefully handle plugin failures, \pageTitleFormatter\, and \navbarPreservePath\. Deprecated configuration properties such as \themeColor\ and \topMargin\ now emit warnings directing users to CSS custom properties instead.

src/core · high confidence

Docsify v5.0.0 release with modernized build and testing infrastructure

Docsify has released version 5.0.0, introducing a comprehensive style overhaul and migrating the build system from the legacy buble/Rollup v2 setup to a modern ES Modules architecture using Rollup v4, Babel, and TypeScript for type definitions. The project has also replaced its legacy test suite with a robust Jest and Playwright testing infrastructure, adding configuration files for ESLint (flat config), Prettier, and PostCSS, while removing deprecated IE10 support and legacy CommonJS traces to improve developer experience and code quality.

(repo-wide) · high confidence

Enhanced fetch logic with virtual routes, 404 handling, and security fixes

The fetch module now supports virtual routes by attempting to match content before falling back to file fetching, and introduces configurable 404 page handling via the \notFoundPage\ option. It also prevents loading remote content via URL hashes for security, exposes the HTTP response object on the route for debugging, and allows custom request headers for all fetch operations.

src/core/fetch · high confidence

Husky pre-commit hook and installation script updated

The project now uses a new installation script (.husky/install.mjs) that skips Husky setup in production and CI environments, and a new pre-commit hook that runs Prettier and lint-staged. This ensures consistent code formatting and linting before commits while avoiding unnecessary overhead in non-development environments.

.husky · high confidence

Modernized event handling with IntersectionObserver and keyboard bindings

The event management system has been rewritten as an ES class mixin, replacing legacy logic with modern browser APIs. This introduces an IntersectionObserver to accurately track and highlight the active sidebar item based on heading visibility, while also managing sticky cover behavior. Additionally, the system now supports configurable keyboard bindings via the \keyBindings\ configuration option, allowing users to define custom shortcuts for navigation and actions.

src/core/event · high confidence

New build scripts for release automation, emoji data, and type declarations

The build process now includes several new Node.js scripts to automate specific tasks. The release script (build/release.sh) handles versioning, building, testing, and publishing, including a step to build legacy v4 assets for backwards compatibility. A new emoji build script (build/emoji.js) fetches the latest emoji data from GitHub and updates both the documentation page and the internal emoji data module. Additionally, a cover page script (build/cover.js) automatically injects the current version number into the documentation's cover page, and a types script (build/types.js) generates TypeScript declaration files for distribution. These changes streamline the release workflow and keep documentation assets up to date.

build · high confidence

Plugin error handling is now configurable

The lifecycle hook execution system in \src/core/init/lifecycle.js\ now respects a new \catchPluginErrors\ configuration option. When enabled, errors thrown by plugins during lifecycle hooks (such as \beforeEach\ or \afterEach\) are caught and logged to the console instead of crashing the application, allowing the rendering process to continue. If disabled, errors are re-thrown as before.

src/core/init · high confidence

Refactored Markdown rendering into modular compiler components

The rendering logic in the core compiler has been restructured from a monolithic implementation into distinct, modular files (blockquote, code, heading, image, link, media, paragraph, tableCell, taskList, and taskListItem). This change introduces GitHub-style callouts (e.g., \[!TIP\]) that render as styled divs instead of standard blockquotes, adds support for custom CSS classes and IDs on images and links, and improves the handling of embedded content within table cells and paragraphs. Code highlighting now uses a sanitized language detection process with Prism.js, and heading generation includes improved accessibility features like programmatic focus management.

src/core/render/compiler · high confidence

Refactored core utility modules into a new modular structure

The core utility logic has been reorganized into distinct, dedicated files within the \src/core/util\ directory. This change introduces a new \ajax.js\ module that handles HTTP requests with built-in caching and optional progress bar support, while \core.js\ now centralizes helper functions like \isExternal\ and \cached\. DOM manipulation utilities have been extracted into \dom.js\, environment detection (such as mobile breakpoint checks) is now in \env.js\, and syntax highlighting dependencies are managed via a new \prism.js\ module. These modules are re-exported through \index.js\, providing a cleaner, more maintainable structure for internal core functionality.

src/core/util · high confidence

Router refactored to support multiple history modes

The router implementation has been refactored to support both 'hash' and 'history' modes, allowing users to configure the routing strategy via the \routerMode\ configuration option. This change introduces a new \Router\ class that initializes either a \HashHistory\ or \HTML5History\ instance based on the selected mode, and updates the rendering logic to handle navigation state changes consistently across both modes.

src/core/router · high confidence

Search plugin rewritten with IndexedDB storage and breadcrumb result sources

The search plugin has been completely rewritten to use Dexie.js (IndexedDB) instead of localStorage for indexing, improving performance and storage capacity. A new \resultSource\ configuration option allows users to display the origin of search results as either the page title or a sidebar breadcrumb path. The UI now features a redesigned input with keyboard shortcuts (/, Ctrl+K), a clear button, and CSS variables for theming, while the indexing engine now supports embedded content via \:include\ links and handles table/list content more robustly.

src/plugins/search · high confidence

Test coverage

Added ESM type-consumption test example; Added integration tests for Docsify core features; Added test helper utilities for Docsify initialization and DOM waiting; Added unit tests for core utilities, rendering, routing, and search plugins; New Playwright end-to-end test suite for Docsify; New test infrastructure for Jest and Playwright; Updated integration test snapshots for docsify 5.0.0; Updated test documentation and removed legacy test assets.

Dependencies

Docsify v5 release with ESM support and modernized tooling

Docsify has been upgraded to version 5.0.0, introducing native ES Module support via the new 'type': 'module' field and explicit package exports. The runtime dependencies have been significantly updated, including major version jumps for 'marked' (to ^18.0.3) and 'dexie' (to ^4.0.11), while 'medium-zoom' has been added. The development toolchain has been modernized with upgrades to ESLint (to ^9.3.0), Prettier (to ^3.2.5), and Rollup (to ^4.17.2), and the project now requires Node.js \>=20.11.0. A new 'test/consume-types' directory has been added to verify TypeScript type consumption.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 62 → 55 (-7.4)
  • Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 72 → 72 (+0.1)
  • Architecture 96 → 80 (-16.4)
  • Maturity 56 → 51 (-4.3)
  • Readiness 61 → 47 (-13.8)
  • Security 74 → 77 (+3.2)
  • Accessibility 65 (new)
  • Performance 100 (new)

Resolved (13)

  • Change coupling: config.js ↔ html5.js (src/core/config.js)
  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
  • Documentation: no architecture or design documentation (docs/configuration.md)
  • Documentation: no contributor guidance (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Documentation: written for insiders (docs/_sidebar.md)
  • Events (cyclomatic 108) (src/core/event/index.js)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • Hotspot: src/core/render/embed.js (src/core/render/embed.js)
  • Off-boarding risk: anonymized user #1

New (22)

  • Documentation: no installation or build instructions (docs/v5-upgrade.md)
  • Documentation: no project overview (docs/README.md)
  • Events::onNavigate (cyclomatic 16) (src/core/event/index.js)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • Low cohesion: Compiler (LCOM4 4) (src/core/render/compiler.js)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Off-boarding risk: anonymized user #1
  • Outdated (npm): dexie
  • Outdated (npm): docsify
  • Outdated (npm): marked
  • …and 2 more

Changes since last survey

  • 4 commits — 1 feature/other, 3 fixes

By area

  • src/core — 3 commits
  • src/plugins — 1 commit

Notable commits

  • fix: fix(a11y): preserve sidebar focus after navigation (#2740)
  • fix: fix(a11y): set aria-expanded on sidebar links that toggle a sub-sidebar (#2809)
  • fix: fix(sidebar): complete loading when nested sidebar is missing (#2801)
  • change: fix(search): parse inline formatting inside bold text (#2815)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

docsifyjs/docsify was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit d823dbe51c1b2dea4c2091e2b952ded0d1e16616 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.