Skip to content
CAI
Software that uses CAICheck a score

egulias/EmailValidator

67.4

Adequate · 25 September 2026

2.9k

lines of production code

PHP

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Added SpoofCheckValidation for email spoofing detection

A new SpoofCheckValidation class has been introduced in the Extra validation namespace. This component leverages the PHP Intl extension's Spoofchecker to detect suspicious email addresses that may be used for spoofing or phishing attempts, returning a SpoofEmail error result when suspicious patterns are detected.

src/Validation/Extra · high confidence

Expanded email validation error reporting

The email validation library now provides a comprehensive set of specific error reasons for validation failures. New classes have been introduced in the \src/Result/Reason\ directory, including \AtextAfterCFWS\, \CRLFAtTheEnd\, \CRLFX2\, \CRNoLF\, \CharNotAllowed\, \CommaInDomain\, \CommentsInIDRight\, \ConsecutiveAt\, \ConsecutiveDot\, \DomainAcceptsNoMail\, \DomainHyphened\, \DomainTooLong\, \DotAtEnd\, \DotAtStart\, \EmptyReason\, \ExceptionFound\, \ExpectingATEXT\, \ExpectingCTEXT\, \ExpectingDTEXT\, \ExpectingDomainLiteralClose\, \LabelTooLong\, \LocalOrReservedDomain\, \NoDNSRecord\, \NoDomainPart\, \NoLocalPart\, \RFCWarnings\, \SpoofEmail\, \UnOpenedComment\, \UnableToGetDNSRecord\, \UnclosedComment\, \UnclosedQuotedString\, and \UnusualElements\. This allows users to identify the exact cause of an invalid email address with greater precision.

src/Result/Reason · high confidence

New warning classes for email validation edge cases

The email validation library now includes a comprehensive set of warning classes in the src/Warning directory, each representing a specific validation state or RFC compliance issue. These include warnings for address literals, comments, domain literals, IP address formats (IPV6), local part length, DNS MX records, and quoted strings. Each warning class defines a unique code and message, allowing users to identify and handle specific email format issues such as deprecated syntax, length limits, or structural anomalies in the email address.

src/Warning · high confidence

Removals

Removed legacy email validation classes

The \EmailValidator\, \EmailParser\, and \EmailLexer\ classes in the \src/egulias/EmailValidator\ directory have been removed. This change eliminates the previous implementation that relied on the \JMS/parser\ library, replacing it with a new architecture (likely Doctrine-based, as suggested by commit messages) to handle email validation.

src/egulias · high confidence

Behavioural changes

Documentation formatting and content updates

The documentation files have been updated to use Unix-style line endings, and the \Other.md\ file was renamed to \Other.md\ (correcting a typo from \Ohter.md\). Additionally, the HTML files for the RFC 5321 and RFC 5322 BNF grammars were updated, likely to fix encoding or formatting issues.

documentation · high confidence

Introduces structured email validation result types

The library now returns specific result objects (ValidEmail, InvalidEmail, MultipleErrors, SpoofEmail) that implement a Result interface, providing explicit methods like isValid(), isInvalid(), description(), and code() for users to inspect validation outcomes.

src/Result · high confidence

Refactored email validation architecture with new parser classes

The email validation logic has been restructured into a new set of classes: EmailLexer, EmailParser, MessageIDParser, and a shared Parser base class. This change introduces a more modular approach to parsing email addresses and message IDs, separating the lexical analysis (EmailLexer) from the syntactic parsing (EmailParser, MessageIDParser). Users will now interact with a cleaner API where validation is performed via the EmailValidator class, which delegates to specific parsers. The refactoring also includes updates to handle UTF-8 characters and invalid ASCII characters more robustly, as well as fixing type issues and improving code readability.

src · medium confidence

Refactored email validation into modular parser classes

The email validation logic has been restructured into a set of dedicated parser classes (e.g., \Comment\, \DomainPart\, \LocalPart\, \DomainLiteral\) that handle specific parts of the email address. This change introduces a \CommentStrategy\ interface and specific implementations (\DomainComment\, \LocalComment\) to manage comment parsing, allowing for more granular validation and warning generation for each component of the email address.

src/Parser · high confidence

Reimplemented email validation with dedicated DNS check and new validation classes

The email validation logic has been refactored into a new set of classes under the \src/Validation\ directory. This includes a dedicated \DNSCheckValidation\ class that handles DNS record verification (A, MX, AAAA) using a new \DNSGetRecordWrapper\ and \DNSRecords\ helper, separating DNS concerns from standard RFC validation. Additionally, the codebase introduces new validation implementations for \MessageID\, \MultipleValidationWithAnd\ (supporting both stop-on-error and collect-all-errors modes), and specific validators like \NoRFCWarningsValidation\ and \RFCValidation\. This change alters how email validation is structured and executed, particularly regarding DNS lookups and multi-validator orchestration.

src/Validation · high confidence

Updated project documentation and configuration files

The README.md was significantly updated to reflect the current state of the EmailValidator library, including supported RFCs, PHP version requirements (PHP 8.1), and usage examples. Additionally, new configuration files were added: CONTRIBUTING.md for contribution guidelines, phpunit.xml.dist for PHPUnit configuration, and psalm.xml for static analysis. The .gitattributes file was added to manage export-ignore rules, while .travis.yml was removed, indicating a shift away from Travis CI. The .gitignore and LICENSE files were also updated.

(repo-wide) · high confidence

Test coverage

Added comprehensive test coverage for email validation components; Added tests for MultipleErrors validation logic; Added tests for SpoofCheckValidation; Added unit tests for email validation components; Removed legacy lexer and parser tests; Removed legacy test suite files; Removed performance benchmark script for email validation.

Dependencies

Upgrade to PHP 8.1 and modernize dependencies

The project now requires PHP 8.1 or higher, replacing the previous minimum PHP version requirement. The dependency on jms/parser-lib has been removed and replaced with doctrine/lexer (versions 2.0 or 3.0) and symfony/polyfill-intl-idn. Additionally, the package name was updated from egulias/EmailValidator to egulias/email-validator, and the autoloading was migrated from PSR-0 to PSR-4.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 52 → 67 (+15.1)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 98 (-0.9)
  • Architecture 94 → 100 (+5.9)
  • Maturity 59 → 49 (-10.3)
  • Readiness 35 → 74 (+39.0)
  • Security 61 → 90 (+29.7)

Resolved (13)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No exposed public API
  • No tests found
  • Test reliability not included
  • The 'Requirements' section mentions PHP 8.1 and Composer but does not state the exact Composer version or dependency requirements needed to install the package. (README.md)

New (24)

  • Dependency hygiene PARTLY measured — Composer dependencies read, no committed lock to grade for currency
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • DomainLiteral.parse (cognitive 17) (src/Parser/DomainLiteral.php)
  • DomainPart.doParseDomainPart (cognitive 23) (src/Parser/DomainPart.php)
  • DoubleQuote.parse (cognitive 17) (src/Parser/DoubleQuote.php)
  • Duplicated block (14 lines × 2) (src/Validation/MessageIDValidation.php)
  • Duplicated block (5 lines × 2) (src/Parser/DomainPart.php)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • LocalPart.parse (cognitive 28) (src/Parser/LocalPart.php)
  • LocalPart.parse (cyclomatic 17) (src/Parser/LocalPart.php)
  • Orphaned files with no living knowledge
  • Skipped (documented): testDNSWarnings (tests/EmailValidator/Validation/DNSCheckValidationTest.php)
  • …and 4 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

egulias/EmailValidator was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit d42c8731f0624ad6bdc8d3e5e9a4524f68801cfa — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-a9cd699f3cd5.