Skip to content
CAI
Software that uses CAICheck a score

doctrine/lexer

63.7

Adequate · 26 September 2026

336

lines of production code

PHP

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Added project metadata, upgrade guide, and developer tooling configuration

The project now includes a \.doctrine-project.json\ file that defines the versioning and maintenance status for each release branch (3.1, 3.0, 2.1, 2.0, 1.2, 1.1, 1.0). A new \UPGRADE.md\ file documents breaking changes for versions 2.0 and 3.0, specifically noting that \Token\ no longer implements \ArrayAccess\ and that parameter type declarations have been added to \AbstractLexer\ and \Token\. Additionally, configuration files for PHP\_CodeSniffer (\phpcs.xml.dist\), PHPStan (\phpstan.neon.dist\), and PHPUnit (\phpunit.xml.dist\) have been added to standardize code quality and testing workflows.

(repo-wide) · high confidence

Introduced new Lexer and Token classes for tokenization

Added the new \AbstractLexer\ and \Token\ classes in the \src\ directory, establishing the core infrastructure for lexical analysis. The \Token\ class now supports \float\ and \bool\ value types alongside strings and integers, and the lexer provides methods to manage token streams, reset positions, and check token types.

src · high confidence

Removals

Removal of the legacy AbstractLexer base class

The \AbstractLexer\ class in \lib/Doctrine/Common/Lexer/AbstractLexer.php\ has been removed. This change eliminates the legacy array-based token representation in favor of a stricter, object-oriented token model, which may require updates to any custom lexer implementations that previously extended this base class.

lib/Doctrine · high confidence

Test coverage

Added lexer test suite and supporting test utilities

Added a new test suite for the lexer component, including AbstractLexerTest, TokenTest, and supporting test fixtures (ConcreteLexer, EnumLexer, MutableLexer) and a TokenType enum to facilitate testing of the AbstractLexer implementation.

tests · high confidence

Dependencies

Dropped support for PHP versions below 8.1 and updated dev dependencies

The package now requires PHP 8.1 or higher, dropping support for older PHP versions. Development dependencies have been updated to use PHPUnit 10.5.58 or 12.5.4, PHPStan 2, and Doctrine Coding Standard 14. The project has also migrated its autoloading from PSR-0 to PSR-4, moving the main source code to the 'src' directory and tests to 'tests'.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 49 → 64 (+14.9)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (+0.0)
  • Architecture 69 → 69 (+0.0)
  • Maturity 52 → 52 (+0.0)
  • Readiness 32 → 73 (+40.3)
  • Security 71 → 77 (+6.3)

Resolved (7)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • No artifact signing
  • No exposed public API
  • No tests found
  • Test reliability not included
  • The README links to an architecture/design doc but does not mention the DQL-lexer example in its own body, so a reader might infer the library serves both purposes without seeing it. (docs/en/simple-parser-example.rst)

New (8)

  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Naming collision and semantic ambiguity: isA is used on both the Lexer (to check if a value matches a token type) and the Token object (to check if the token matches a type). While the signatures differ, the name isA is non-standard and confusingly similar to isNextToken/isNextTokenAny on the Lexer. It suggests a type-checking operation but is overloaded with different contexts.
  • Workflow token permissions not restricted

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

doctrine/lexer was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit e96fe45e92a54233726014a7cc7340abf29bb14c — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-a15879f6f801.