Skip to content
CAI
Software that uses CAICheck a score

emarifer/goCMS

55.4

Adequate · 21 September 2026

2.1k

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Added Docker environment for local development and testing

The project now includes a complete Docker-based development environment. A new Dockerfile sets up the Go 1.22.0 build environment with dependencies like Goose and Air. A docker-compose.yml file defines the application and MariaDB services, configuring ports 8080 and 8081, and linking the app to the database. A start-app.sh script handles database migrations and starts the application. Additionally, an .air.toml file configures the Air hot-reload tool for development, and a gocms\_config.toml provides database and server configuration. The previous docker-compose.yml was renamed to docker/mariadb.yml, and the root-level docker-compose.yml was replaced with the new multi-service setup.

docker · medium confidence

Added support for image and table shortcodes in posts

Users can now use shortcode-like syntax to insert images and tables in their posts. The new image shortcode allows specifying an image source and optional alt text, while the table shortcode generates a formatted markdown table structure.

plugins · high confidence

Admin API for posts and images with shortcode support

The admin application now exposes a RESTful API for managing posts and images, including handlers for creating, retrieving, updating, and deleting posts and images. The API supports uploading images with metadata and processes posts by transforming content using Lua-based shortcodes, allowing dynamic content rendering through a plugin-like system.

internal · high confidence

Behavioural changes

Added in-memory HTML response caching and Lua plugin support

The application now caches HTML responses in memory for 10 minutes to improve performance, as evidenced by benchmark results showing significantly higher requests per second with caching enabled. Additionally, the system now supports user-supplied Lua plugins for runtime customization, allowing users to add shortcodes and other features via Lua scripts. Configuration has been migrated from YAML to TOML to support these advanced features.

(repo-wide) · high confidence

Database schema extended with posts and images tables

The application's database schema has been updated to support a new content model. A 'posts' table is now created to store title, content, and excerpt fields, along with a default timestamp. A separate 'images' table has been added to store image metadata including a UUID, name, and alt text. Additionally, an initial post titled 'Gofiber Templ Htmx' is inserted into the database upon migration.

migrations · high confidence

Introduce command-line config flag and structured logging

The application now accepts a --config flag to specify the path to a TOML configuration file, replacing the previous method of loading settings. Additionally, the codebase has been updated to use Go's standard library log/slog for structured logging, with the logger injected via the fx dependency injection container. The main entry points for both the API and admin applications now initialize the logger and parse the config path at startup.

cmd · high confidence

Migrate settings configuration from YAML to TOML and add shortcode support

The application's configuration format has changed from YAML to TOML, requiring users to update their settings files. The new \gocms\_config.toml\ file supports additional configuration options, including a separate port for the admin webserver, explicit database connection details, and a new \shortcodes\ array that allows users to register Lua plugins for handling shortcodes like \img\ and \table\. The Go code in \settings.go\ has been updated to parse the TOML format and load settings from environment variables as a fallback, enabling more flexible configuration management.

settings · high confidence

Migrate views to Templ for improved type safety and performance

The project has migrated its view templates from Go's text/template (HTML) to the Templ templating engine. This change replaces the previous HTML templates with .templ files, providing compile-time type safety and improved performance. The migration includes new templated components for the home page, contact form, post details, and error pages, alongside a refactored layout template that now uses Templ's component model.

views · high confidence

Updated MariaDB connection string to use utf8mb4 charset

The database connection initialization in database/database.go was modified to explicitly specify the utf8mb4 charset in the MySQL connection string. This change ensures proper support for 4-byte UTF-8 characters (such as emojis and certain CJK characters) in the database, addressing potential character encoding issues.

database · medium confidence

Updated database schema in mariadb\_init

The database initialization script was modified to remove the 'inventory' database and its 'users' and 'products' tables, replacing them with a 'cms\_db' database containing a 'posts' table and a new 'images' table for storing image metadata.

_mariadb\init · medium confidence

Test coverage

Added end-to-end tests for post creation and retrieval

Added new system tests for the admin application's post creation and retrieval endpoints, as well as the public application's home page and post retrieval endpoints. The tests verify that posts can be created via the admin API and subsequently retrieved, and that the home page and individual post pages return expected HTTP status codes and content.

_tests, tests/system\tests · high confidence

Dependencies

Updated Go dependencies and upgraded to Go 1.22.1

The project's Go version is upgraded from 1.21.0 to 1.22.1. Several dependencies are updated, including the MySQL driver (v1.7.1 to v1.8.0) and various indirect dependencies. New dependencies are added, including BurntSushi/toml, google/uuid, pressly/goose/v3, yuin/gopher-lua, and dolthub/go-mysql-server, alongside numerous indirect dependencies.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 56 → 55 (-0.3)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 98 → 98 (-0.0)
  • Architecture 100 → 66 (-34.3)
  • Maturity 67 → 67 (-0.1)
  • Readiness 32 → 41 (+8.8)
  • Security 99 → 90 (-8.9)
  • Domain Modelling 70 → 70 (+0.0)
  • Accessibility 65 (new)

Resolved (14)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (18 lines × 3) (internal/admin_app/api/images.handlers.go)
  • Duplicated block (22 lines × 3) (internal/admin_app/api/images.handlers.go)
  • Duplicated block (23 lines × 2) (internal/admin_app/api/posts.handlers.go)
  • Duplicated block (9 lines × 2) (cmd/gocms/main.go)
  • No exposed public API
  • OSV Dependency Vulnerabilities not included (check did not complete)
  • Test reliability not included
  • The README does not state how to install or run the application, which is critical for new users. (README.md)
  • early-stage repository — too little history to judge knowledge freshness
  • git history depth insufficient
  • git history depth insufficient
  • single-maintainer — knowledge-concentration (bus factor) risk

New (39)

  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency pinned to a stale untagged commit: github.com/zutto/shardedmap
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (10 lines × 2) (internal/repository/image.repository.go)
  • Duplicated block (14 lines × 2) (cmd/gocms/main.go)
  • Duplicated block (17 lines × 3) (internal/admin_app/api/images.handlers.go)
  • Duplicated block (23 lines × 3) (internal/admin_app/api/images.handlers.go)
  • Duplicated block (27–28 lines × 2) (internal/admin_app/api/posts.handlers.go)
  • Duplicated block (31 lines × 2) (internal/admin_app/api/images.handlers.go)
  • HackComment (internal/app/api/api.go)
  • High CVE: [GHSA redacted] (go.mod)
  • Hotspot: internal/repository/post.repository.go (internal/repository/post.repository.go)
  • Medium CVE: [GHSA redacted] (go.mod)
  • Medium CVE: [GHSA redacted] (go.mod)
  • Medium CVE: GO-2024-2687 (go.mod)
  • Medium CVE: GO-2026-4503 (go.mod)
  • Medium CVE: GO-2026-5024 (go.mod)
  • Medium CVE: GO-2026-5970 (go.mod)
  • …and 19 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

emarifer/goCMS was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 91de8019bfb0f19943f5eeac83130d17443f91d6 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.