Skip to content
CAI
Software that uses CAICheck a score

emqx/emqtt-bench

48.3

Weak · 23 September 2026

1.9k

lines of production code

Erlang

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a lightweight benchmarking tool for MQTT v5.0, implemented in Erlang, designed to measure connection, publish, and subscribe performance. It provides configurable logging backends and exposes Prometheus-compatible metrics via a REST API for monitoring. The tool also includes automation scripts for building, signing, and notarizing macOS releases.

Features

Add EMQTT logger backend with console and null options

Users can now configure the EMQTT library's logging behavior through a new \emqtt\_logger\ module. This change introduces a pluggable logging backend system that supports two modes: \console\ for standard output logging and \null\ to suppress all logging output. The \emqtt\_logger\_console\ module handles console-based logging, while \emqtt\_logger\_null\ implements a no-op logger that redirects IO requests to prevent console spam. This allows users to control log verbosity and output destination via the \log\_to\ option in the setup configuration.

src/logger · medium confidence

Add Prometheus metrics endpoint for monitoring

The benchmark tool now exposes a REST API endpoint to serve Prometheus-compatible metrics. This is enabled via the new \--restapi\ option, which can be set to an IP:Port or just a Port to listen on all interfaces. The HTTP server, implemented in \emqtt\_bench\_http\_metrics.erl\, handles GET requests and returns the current Prometheus text format output, allowing users to scrape performance and QoE data directly from the benchmark process.

src · high confidence

Added emqtt\_bench benchmarking tool

A new executable script named emqtt\_bench has been added to the bin directory. This script serves as a launcher for the emqtt\_bench escript, automatically resolving the Erlang runtime path and executing the benchmarking tool with any provided arguments.

bin · high confidence

Added macOS signing and notarization automation for EMQX Bench

New shell scripts in the scripts/ directory automate the macOS build pipeline. ensure-rebar3.sh manages rebar3 versions for OTP 25–28. macos-sign-binaries.sh handles code-signing of runtime libraries and binaries using Apple developer certificates. macos-notarize-package.sh automates the Apple notary submission process. rename-package.sh generates platform-specific package names for Linux and macOS. These scripts enable automated, signed, and notarized macOS releases.

scripts · high confidence

Initial release of emqtt-bench benchmark tool

The emqtt-bench tool is introduced as a lightweight MQTT v5.0 benchmark utility written in Erlang. This initial release provides commands for connection, publish, and subscribe benchmarks, supporting features such as TLS/SSL, QUIC transport, and Prometheus metrics. The tool includes a \topic\_spec.json\ configuration file for defining publisher topics and requires Erlang/OTP 27.2+ to build.

(repo-wide) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 52 → 48 (-3.4)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 94 → 96 (+2.5)
  • Architecture 100 → 99 (-1.0)
  • Maturity 55 → 36 (-19.4)
  • Readiness 32 → 38 (+6.4)
  • Security 73 → 65 (-7.4)

Resolved (8)

  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium IaC: CKV_DOCKER_3 (Dockerfile)
  • No exposed public API
  • PR-triggered workflow without a permissions block
  • TooManyMethods: emqtt_bench (src/emqtt_bench.erl)
  • complexity unreadable for .erl — churn × complexity hotspots could not be measured

New (18)

  • Dependency hygiene PARTLY measured — rebar3 pinning read, dependency currency not (no rebar.lock-pinned Hex declaration to grade)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Hotspot: src/emqtt_bench.erl (src/emqtt_bench.erl)
  • Medium IaC: WD-DOCKER-0003 (Dockerfile)
  • Medium IaC: WD-DOCKER-0003 (Dockerfile)
  • No ADRs found
  • No checksums published for release artifacts
  • No dependency lockfile committed (rebar.config)
  • TodoComment (src/emqtt_bench.erl)
  • Workflow holding a long-lived secret is unscoped
  • emqtt_bench.connect (cognitive 26) (src/emqtt_bench.erl)
  • emqtt_bench.connect (cyclomatic 25) (src/emqtt_bench.erl)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

emqx/emqtt-bench was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit cb86b18848da17cae1024e1d06f7e43f8f6691a1 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.