Skip to content
CAI
Software that uses CAICheck a score

emqx/emqtt

65.1

Adequate · 23 September 2026

5.2k

lines of production code

Erlang

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is an Erlang-based MQTT v5.0 client library that supports TCP, WebSocket, and QUIC transports. It provides core publish/subscribe APIs, reconnection logic, and a command-line interface for interacting with MQTT brokers. The project includes comprehensive test coverage for protocol behaviors and transports, along with packaging infrastructure for Debian and RPM distributions.

Features

Add Debian packaging infrastructure for emqtt

This change introduces the build system and metadata required to create .deb packages for the emqtt Erlang MQTT client. It adds a Makefile to orchestrate the build, a debian/rules file to define the build and install steps, a control file specifying the package name, dependencies, and description, a changelog, copyright, and a post-installation script that sets permissions and creates symlinks for the emqtt and emqtt\_cli binaries in /usr/bin.

packages/deb · high confidence

Added RPM packaging infrastructure for emqtt

Introduced a new Makefile and emqtt.spec file in the packages/rpm directory to automate the build and installation of RPM packages for the emqtt Erlang MQTT client. This change enables users to generate versioned RPM artifacts and handles the installation of the emqtt and emqtt\_cli binaries to the system path during package installation.

packages/rpm · high confidence

Added public type definitions and structured logging macros

The library now exposes public Erlang record and macro definitions in the include directory, allowing users to directly reference MQTT protocol constants (such as QoS levels, packet types, and V5 reason codes) and internal packet structures like \mqtt\_packet\_connect\. Additionally, a new \logger.hrl\ header introduces structured logging macros (\SLOG\) that integrate with the Erlang/OTP logger, providing automatic metadata injection (module, function, line) for library log messages.

include · high confidence

Initial release of the Erlang MQTT v5.0 client library

This change introduces the emqtt library, an Erlang MQTT v5.0 client that supports TCP, WebSocket, and QUIC transports. It provides a full set of publish/subscribe APIs, handles reconnection logic, and includes a command-line interface (CLI) for connecting, publishing, and subscribing. The implementation relies on the gun library for HTTP/WebSocket handling and the quicer library for QUIC support.

src · high confidence

Behavioural changes

emqtt now requires Erlang/OTP 27 and upgrades WebSocket dependencies

The minimum supported Erlang/OTP version has been raised to 27.0, enforced in rebar.config, which also drops support for older OTP releases in the build matrix. To support this requirement and improve compatibility, the project has upgraded its WebSocket dependencies: cowlib is pinned to \~\> 2.13 and gun to \~\> 2.1, allowing emqtt to coexist with other packages requiring newer 2.x releases. Additionally, the build system now bundles rebar3 3.27.0 and includes a pre-compile script to dynamically manage the gun dependency based on WebSocket support flags.

(repo-wide) · high confidence

Test coverage

Added release upgrade testing and helper scripts; Expanded test coverage for MQTT client features and transports.

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 61 → 65 (+4.0)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 93 → 92 (-0.6)
  • Architecture 100 → 100 (+0.0)
  • Maturity 57 → 59 (+2.5)
  • Readiness 63 → 68 (+5.5)
  • Security 54 → 60 (+6.1)

Resolved (16)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No exposed public API
  • Test reliability not included
  • TooManyMethods: emqtt (src/emqtt.erl)
  • TooManyMethods: emqtt_frame (src/emqtt_frame.erl)
  • complexity unreadable for .erl, .hrl — churn × complexity hotspots could not be measured

New (45)

  • Coverage not measured — no coverage collector is wired up
  • Dependency hygiene PARTLY measured — rebar3 pinning read, dependency currency not (no rebar.lock-pinned Hex declaration to grade)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (11 lines × 2) (src/emqtt.erl)
  • Duplicated block (11 lines × 2) (src/emqtt_quic.erl)
  • Duplicated block (5 lines × 2) (src/emqtt.erl)
  • Duplicated block (7 lines × 2) (src/emqtt.erl)
  • High IaC: DS-0002 (Dockerfile.test)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 25 more

Changes since last survey

  • 11 commits — 10 feature/other, 1 fixes

By area

  • (root) — 4 commits
  • (repo) — 3 commits
  • .github/workflows — 3 commits
  • src/emqtt.erl — 1 commit

Notable commits

  • fix: fix: try the hosts list in the configured order
  • change: Add ws_upgrade_options option
  • change: Merge pull request #316 from zmstone/260820-shuffle-hosts
  • change: Merge pull request #317 from lhoguin/loic-ws_upgrade_options
  • change: Merge pull request #318 from zmstone/260910-min-otp-27
  • change: build: require OTP 27
  • change: ci: build macOS packages on OTP 27 instead of 26
  • change: ci: bump actions/checkout to v4
  • change: ci: install erlang@28 for the macOS OTP 28 job
  • change: docs: add changelog entry for ws_upgrade_options
  • change: feat: add shuffle_hosts option

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

emqx/emqtt was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 400e8c8b298782aca661f86156b321cf803e0791 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.