Skip to content
CAI
Software that uses CAICheck a score

emarifer/go-echo-templ-htmx

45.0

Weak · 21 September 2026

828

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This is a Go web application that serves static assets and renders HTML templates for user authentication and task management. It leverages htmx and hyperscript to create dynamic, interactive user interfaces without custom JavaScript, while using Tailwind CSS and DaisyUI for styling. The system manages user sessions, handles routing with custom error pages, and processes client-side data like time zones.

Features

Added htmx and hyperscript client-side libraries

The project now includes the minified JavaScript libraries htmx (version 1.9.12) and hyperscript in the assets directory. These libraries enable the application to perform asynchronous HTTP requests and manipulate the DOM using declarative attributes, providing new capabilities for dynamic, interactive user interfaces without writing custom JavaScript.

assets, tailwind · high confidence

Behavioural changes

Migrate from global state to context-based state and add 404 handling

The application replaces global variables (isError, fromProtected) with context values (ISERROR, FROMPROTECTED) to improve concurrency safety and testability. The login flow now captures the client's time zone from the X-Timezone header and stores it in the session cookie, making the user's time zone available in the request context for authenticated routes. Additionally, a fallback 404 handler is introduced to return a custom error page for unmatched routes.

handlers · high confidence

Removed all generated Templ view files

The entire \views\ directory has been cleared of all generated Go files, including the \auth\_views\, \errors\_pages\, \layout\, \partials\, and \todo\_views\ packages. This removes the compiled HTML templates for the home, login, register, error pages (401, 404, 500), the base layout, navbar, flash messages, and all todo list/create/update components.

views · high confidence

Static asset serving path updated

The path for serving static assets has been changed from the root directory (/) to /static. Users accessing static files will now need to use the /static prefix for their requests.

cmd · high confidence

Dependencies

Added Tailwind CSS and DaisyUI dependencies

The project now includes a \package.json\ and \package-lock.json\ in the \tailwind\ directory, establishing a Node.js environment for frontend build tools. This adds \tailwindcss\ (v3.4.3) and \daisyui\ (v4.10.2) as development dependencies, enabling CSS processing and UI component styling for the application's frontend assets.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 42 → 45 (+3.4)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (-0.3)
  • Architecture 69 → 69 (+0.0)
  • Maturity 54 → 52 (-1.4)
  • Readiness 15 → 24 (+8.3)
  • Security 77 → 74 (-2.7)
  • Accessibility 73 (new)

Resolved (22)

  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (tailwind/package-lock.json)
  • High CVE: [GHSA redacted] (tailwind/package-lock.json)
  • High CVE: [GHSA redacted] (tailwind/package-lock.json)
  • High CVE: [GHSA redacted] (tailwind/package-lock.json)
  • High CVE: [GHSA redacted] (tailwind/package-lock.json)
  • High CVE: [GHSA redacted] (tailwind/package-lock.json)
  • High CVE: [GHSA redacted] (tailwind/package-lock.json)
  • High CVE: [GHSA redacted] (go.mod)
  • Medium CVE: [GHSA redacted] (tailwind/package-lock.json)
  • Medium CVE: [GHSA redacted] (go.mod)
  • Medium CVE: [GHSA redacted] (tailwind/package-lock.json)
  • Medium CVE: [GHSA redacted] (tailwind/package-lock.json)
  • Medium CVE: GO-2023-2041 (go.mod)
  • Medium CVE: GO-2026-5024 (go.mod)
  • Medium CVE: GO-2026-5970 (go.mod)
  • No exposed public API
  • early-stage repository — too little history to judge knowledge freshness
  • git history depth insufficient
  • …and 2 more

New (29)

  • Critical CVE: [GHSA redacted] (go.mod)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (17 lines × 2) (handlers/todo.handlers.go)
  • High CVE: [GHSA redacted] (tailwind/package-lock.json)
  • High CVE: [GHSA redacted] (tailwind/package-lock.json)
  • High CVE: [GHSA redacted] (tailwind/package-lock.json)
  • High CVE: [GHSA redacted] (tailwind/package-lock.json)
  • High CVE: [GHSA redacted] (tailwind/package-lock.json)
  • High CVE: [GHSA redacted] (tailwind/package-lock.json)
  • High CVE: [GHSA redacted] (tailwind/package-lock.json)
  • High CVE: [GHSA redacted] (tailwind/package-lock.json)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.mod)
  • Low cohesion: AuthHandler (LCOM4 4) (handlers/auth.handlers.go)
  • Medium CVE: [GHSA redacted] (tailwind/package-lock.json)
  • Medium CVE: [GHSA redacted] (go.mod)
  • Medium CVE: [GHSA redacted] (tailwind/package-lock.json)
  • Medium CVE: GO-2023-2041 (go.mod)
  • Medium CVE: GO-2026-5024 (go.mod)
  • …and 9 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

emarifer/go-echo-templ-htmx was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 8e66b6a27c61a1ed2c63acacdc2943e388b2724d — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.