Skip to content
CAI
Software that uses CAICheck a score

edgurgel/poxa

54.6

Adequate · 23 September 2026

1.7k

lines of production code

Elixir

with JavaScript

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Poxa is a Pusher-compatible WebSocket server built on Elixir that manages real-time channel subscriptions, user presence, and event broadcasting. It provides a REST API for channel and user management, a debugging console UI, and a configurable webhook dispatcher for event delivery. The system is containerized for modern deployment and includes comprehensive test coverage for its core protocols and adapters.

How it got here

2013 — Modernization and Docker support

5 changes.

This period focused on modernizing the codebase by upgrading to Elixir 1.16 and replacing legacy configuration and logging mechanisms with contemporary APIs. The team introduced Docker support, refactored the registry and channel handling using an adapter pattern, and expanded test coverage to ensure stability.

2014 — Console UI and test coverage

6 changes.

This period focused on enhancing the Poxa service's debuggability and reliability by introducing a web-based console interface for monitoring WebSocket events. The team also expanded test coverage for both the console and core WebSocket functionality, while refactoring the console handler to use modern Cowboy 2.x APIs and centralizing configuration management.

2016–2019 — Webhook refactoring and release configuration

4 changes.

The project refactored the webhook implementation into a dedicated supervision tree with batching and deduplication, supported by comprehensive unit tests for the new components. Additionally, the codebase was enhanced with release environment configuration templates for both Windows and Unix systems.

Features

Add Docker support and update configuration methods

The project now supports running via Docker, with a new Dockerfile and .dockerignore file, allowing users to build and run the application in a containerized environment. Additionally, the README has been updated to reflect modern configuration methods, including support for environment variables (e.g., POXA\_APP\_KEY, PORT) and removal of older configuration styles, while also adding pronunciation tips and updated feature lists.

(repo-wide) · high confidence

Add Poxa Console UI for debugging events

A new web interface for the Poxa Console has been added, providing a user-facing dashboard to connect to the WebSocket server using an App Key and Secret. The UI includes fields for credentials, a Connect/Disconnect button, and a table to display incoming events (Type, Socket, Details, Time). This enables users to visually monitor and debug WebSocket connections and events directly through the browser.

priv · high confidence

Added Bootstrap 3.1.1 CSS and configuration assets

The application now includes the full Bootstrap 3.1.1 CSS framework (both standard and minified versions) along with the associated \config.json\ containing Bootstrap's design variables. This provides a comprehensive set of pre-built styles for components like buttons, forms, and navigation, enabling a consistent visual theme across the interface.

priv/static · high confidence

Added release environment configuration templates

The project now includes new environment configuration templates for the release, including scripts for Windows (env.bat.eex) and Unix (env.sh.eex) as well as VM argument files (vm.args.eex and remote.vm.args.eex). These files provide commented-out examples for configuring the release mode, node distribution, and VM flags, allowing users to easily customize their deployment environment.

rel · high confidence

Behavioural changes

Centralize Poxa configuration via environment variables

The application's configuration for the Poxa service has been consolidated into the new config/config.exs and config/runtime.exs files. Users can now control key runtime settings—including the server port, SSL settings, registry adapter, webhook handler, and payload/activity timeouts—via environment variables such as PORT, POXA\_SSL, and ACTIVITY\_TIMEOUT, with sensible defaults provided.

config · medium confidence

Modernizes configuration loading and adds console and channel endpoints

The application now uses the modern \Application.fetch\_env/2\ API instead of the deprecated \:application.get\_env/3\, and switches logging from \Lager\ to the built-in \Logger\. A new \:registry\_adapter\ configuration option is introduced to decouple the registry implementation. Additionally, the router is updated to serve a static index page and static assets, and new endpoints are added for a console WebSocket, channel listings, and user lists, while SSL configuration now requires an explicit \enabled\ flag to start the HTTPS listener.

lib · medium confidence

Refactor console WebSocket handler to use Cowboy 2.x API

The console WebSocket handler has been refactored to implement the :cowboy\_websocket behaviour, replacing the previous GenEvent-based approach. This change updates the internal implementation of the console interface to use modern Cowboy 2.x APIs, ensuring that connection events (such as connected, disconnected, subscribed, and unsubscribed) are correctly routed and formatted for the console UI.

lib/poxa/console · medium confidence

Refactor registry and channel handling with a new adapter pattern

The codebase introduces a registry abstraction (Poxa.Registry) with a GProc adapter (Poxa.Adapter.GProc) to manage channel subscriptions and user data, replacing direct gproc calls. This enables swapping the underlying storage mechanism. New modules (Poxa.Channel, Poxa.PresenceChannel, Poxa.SubscriptionHandler) and handlers (ChannelsHandler, UsersHandler) are added to support the Pusher REST API endpoints for listing channels and users. The authentication process is simplified using the Signaturex library, and the WebSocket handler is updated to use a State struct for tracking socket IDs and timeouts.

lib/poxa · high confidence

Refactored web hook implementation with dedicated supervisor and GenServer processes

The web hook functionality has been restructured into a dedicated supervision tree. A new \Poxa.WebHook.Supervisor\ manages two GenServer processes: \Poxa.WebHook.Handler\, which subscribes to internal Poxa events and queues them into an ETS-based \EventTable\, and \Poxa.WebHook.Dispatcher\, which periodically sends the queued events to the configured web hook URL. This replaces the previous \GenEvent\-based implementation, introducing a 1.5-second delay for most events to allow for batching and deduplication of opposite events (e.g., \member\_added\ cancels a pending \member\_removed\).

_lib/poxa/web\hook · medium confidence

Test coverage

Add integration tests for WebSocket connections, channels, and event triggering; Added tests for the GProc adapter; Added tests for the console WebSocket handler; Added unit tests for the WebHook module; Comprehensive test coverage for core Poxa modules.

Dependencies

Upgrade to Elixir 1.16 and modernize dependencies

The project has been upgraded to require Elixir 1.16, replacing the previous 0.x/1.0/1.1/1.2/1.5/1.16 version constraints. Dependencies have been migrated from git-based sources to Hex packages, with specific updates including Cowboy to \~\> 2.6, Jason to \~\> 1.0, SignatureX to \~\> 1.3, Gproc to \~\> 1.0, HTTPoison to \~\> 2.0, Ex2MS to \~\> 1.5, and Dialyxir to \~\> 1.0. The configuration has been simplified by removing environment-specific options and applications, and the lockfile now reflects these modernized, versioned dependencies.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 57 → 55 (-2.1)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 96 (-4.3)
  • Architecture 100 → 98 (-1.9)
  • Maturity 48 → 48 (+0.0)
  • Readiness 68 → 75 (+6.5)
  • Security 70 → 87 (+16.3)
  • Accessibility 52 → 41 (-10.5)

Resolved (19)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — no supported dependency manifest was read
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium IaC: CKV_DOCKER_2 (Dockerfile)
  • No exposed public API
  • Test reliability not included
  • The Development section states Elixir 1.16 and Erlang 26.0 but does not mention which Erlang OTP release or how to upgrade. (README.md)
  • dormant codebase — no living knowledge left to concentrate

New (31)

  • Documentation: no contributor guidance (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • FileTooLong: js/bootstrap.js (priv/static/js/bootstrap.js)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High CVE: [GHSA redacted] (mix.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium IaC: WD-DOCKER-0003 (Dockerfile)
  • Medium IaC: WD-DOCKER-0003 (Dockerfile)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • …and 11 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

edgurgel/poxa was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 141c3107761405801fb03a6a1632075e3819b680 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.