Skip to content
CAI
Software that uses CAICheck a score

expressjs/express

55.2

Adequate · 25 September 2026

4.1k

lines of production code

JavaScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the Express web framework for Node.js, providing a modular architecture for building web applications and APIs. It handles core HTTP request processing, including routing, middleware stacking, and error handling, while supporting various templating engines and session management strategies. The codebase includes extensive examples demonstrating common patterns such as MVC architecture, content negotiation, and security best practices.

How it got here

2009–2011 — Express 4.0 modularization and example expansion

18 changes.

The project underwent a significant architectural shift with the Express 4.0 rewrite, moving to a modular structure that externalized middleware like body-parser and serve-static. This period also focused on comprehensive testing and documentation, adding extensive unit and acceptance tests while expanding the examples directory to demonstrate modern practices such as EJS templating, session management, and API design.

2012 — comprehensive examples expansion

15 changes.

This period focused on significantly expanding the project's example suite with diverse, standalone applications demonstrating core features like MVC architecture, routing, and middleware. The additions covered security best practices, error handling, static file serving, and integrations with Redis for search and activity tracking. These examples served as practical guides for users implementing specific patterns such as authentication, content negotiation, and subdomain routing.

2013–2017 — Example modernization and EJS migration

13 changes.

This period focused on updating the project's example applications to adhere to modern Express best practices, including the adoption of strict mode, built-in middleware, and secure coding patterns. A significant portion of the work involved migrating view templates from Jade to EJS and ensuring responsive HTML standards across all examples. Additionally, new examples were introduced to demonstrate advanced routing, resource management, and client-side interactions.

Features

Add Hello World example with strict mode

A new Hello World example has been added to the examples directory, demonstrating a basic Express application that listens on port 3000. The example code explicitly enables strict mode and includes coverage exclusion comments for the server-startup logic.

examples/hello-world · high confidence

Add MVC pet controller with EJS engine and before middleware

The examples/mvc/controllers/pet/index.js file introduces a new controller for the MVC example application. It configures the view engine to EJS and implements a 'before' middleware that validates the existence of a pet in the database before proceeding. The controller exposes actions to show, edit, and update pet details, handling the rendering of views and redirection upon successful updates.

examples/mvc/controllers/pet · high confidence

Add Redis-backed search example

A new search example has been added to the examples directory that demonstrates how to integrate Express with Redis. The example initializes a Redis client, populates sample data, and exposes a search endpoint that queries Redis sets. It also serves static assets and a client-side JavaScript file, providing a complete, runnable demonstration of Redis integration within an Express application.

examples/search · high confidence

Add Redis-based online user activity tracking example

A new example application has been added at examples/online/index.js that demonstrates how to track active users using the 'online' and 'redis' libraries. The example sets up an Express server that records user activity based on the User-Agent header and displays a list of the most recent 5 active users on the home page, requiring Redis to be installed and running.

examples/online · high confidence

A new example demonstrating how to implement cookie-based sessions in Express has been added. The example uses the \cookie-session\ middleware to track and display a visitor's view count on the home page.

examples/cookie-sessions · high confidence

Add error handling example demonstrating middleware and async error propagation

A new example at examples/error/index.js demonstrates Express error handling, including synchronous route errors, asynchronous error passing via process.nextTick, and the use of 4-argument error-handling middleware. The example uses strict mode and conditionally applies the morgan logger based on the environment.

examples/error · high confidence

Add multi-router example demonstrating versioned API routing

Added a new example in the examples/multi-router directory that demonstrates how to structure an Express application with multiple routers. The example includes separate controller modules for API v1 and API v2, mounted at /api/v1 and /api/v2 respectively, along with a root route, illustrating how to organize versioned endpoints in a single application.

examples/multi-router · high confidence

Add params example with strict mode and http-errors

The params example now uses strict mode and the http-errors library for creating error responses, improving code quality and consistency in the example application.

examples/params · high confidence

Add route-map example with input escaping

A new example application demonstrating a recursive route-map pattern has been added to the examples directory. This example illustrates how to define nested routes using a map structure and includes proper escaping of user input via the escape-html library to prevent XSS vulnerabilities.

examples/route-map · high confidence

Add route-separation example with EJS views and body parsing

A new example demonstrating route separation has been added to the examples directory. It uses EJS for templating (replacing the previous Jade setup) and includes dedicated modules for site, user, and post routes. The example now uses \express.urlencoded\ to parse request bodies, enabling user update functionality, and organizes views and static assets in a structured directory layout.

examples/route-separation · high confidence

Add search example with strict-mode client and responsive HTML

The search example now includes a client-side JavaScript file (client.js) that performs asynchronous search requests via XMLHttpRequest when the user types in the search input, updating the page with the response text. The accompanying HTML page (index.html) has been added with proper meta tags for charset and viewport to ensure correct rendering on mobile devices, uses strict mode in the script, and links to the client.js file. This provides a working, standards-compliant search interface for the example.

examples/search/public · high confidence

Add static-files example demonstrating Express static middleware usage

A new example application has been added to the examples/static-files directory to demonstrate how to serve static files using Express. The example shows how to configure the express.static() middleware to serve files from a public directory, how to mount the middleware at a specific path prefix, and how to serve files from multiple directories by calling the middleware multiple times.

examples/static-files · high confidence

Add static-files example with public assets

The static-files example now includes a public directory containing a basic CSS stylesheet, a JavaScript file, and a text file, providing the necessary frontend assets for the example.

examples/static-files/public · high confidence

Add vhost example demonstrating subdomain routing

Added a new example in the examples/vhost directory that demonstrates how to use the vhost middleware to route requests based on domain names. The example sets up two Express applications: one for the main domain (example.com) and another for all subdomains (\*.example.com), which redirects requests to a specific URL. It includes instructions for configuring the hosts file for local testing.

examples/vhost · high confidence

Add view-locals example demonstrating middleware patterns

Added a new example in the \examples/view-locals\ directory that demonstrates three approaches for passing data to views: passing locals directly in \res.render\, attaching data to the \req\ object via middleware, and using \res.locals\ in middleware to make data available across multiple routes. The example uses EJS as the view engine and includes a mock user model.

examples/view-locals · high confidence

Added content-negotiation example demonstrating response formatting

The examples/content-negotiation directory now includes a working demonstration of Express's content negotiation capabilities. The example provides a simple in-memory user database and shows two approaches for handling different response formats (HTML, text, and JSON): inline formatting within a route handler and a reusable middleware function that loads format handlers from a separate module.

examples/content-negotiation · high confidence

Added default stylesheet for the EJS example

The EJS example now includes a default CSS stylesheet that applies padding and sets the font family for the body element, ensuring consistent visual presentation for the example application.

examples/ejs/public · high confidence

Added session management examples with Redis support

New example files have been added to the session directory to demonstrate session handling. The main index.js example shows basic in-memory session usage with strict mode enabled, while redis.js demonstrates how to configure persistent sessions using the connect-redis store with express-session. Both examples include comments on required dependencies and installation steps.

examples/session · high confidence

Initial project scaffolding and configuration files

The repository is initialized with essential configuration files to standardize development and build processes. This includes an \.editorconfig\ for consistent indentation and whitespace, ESLint configuration (\.eslintrc.yml\) enforcing modern JavaScript standards and explicit Buffer imports, and a \.gitignore\ to exclude build artifacts and dependencies. Security and package management are configured via \.npmrc\ (disabling package locks and scripts by default), while the project structure is defined by \index.js\ and a comprehensive \History.md\ changelog. Documentation is updated in \Readme.md\ to reflect Node.js 18+ requirements and the new project team.

(repo-wide) · high confidence

New EJS example application added

A new example application demonstrating EJS template integration with Express has been added to the examples directory. This example configures the view engine to use .html extensions, sets up static file serving, and includes a basic route rendering a list of users, providing a reference implementation for users integrating EJS into their Express apps.

examples/ejs · high confidence

New MVC example application with automated controller routing

The examples/mvc directory now contains a complete Model-View-Controller sample application that demonstrates a convention-based routing system. The app uses a boot script to automatically scan the controllers directory, mapping exported functions (such as index, create, show, edit, and update) to HTTP routes, while supporting custom prefixes, view engines, and 'before' middleware hooks per controller. It includes a faux in-memory database, session-based flash messaging, body parsing, method overriding, and standard 404/5xx error handling.

examples/mvc · high confidence

New MVC user management example with Handlebars views

The examples/mvc/controllers/user directory now includes a complete user management example featuring a controller that implements a 'before' middleware to load user data from a database, along with Handlebars (.hbs) templates for listing, showing, and editing users. This replaces the previous Jade-based implementation, providing a modern, strict-mode JavaScript example for MVC architecture with responsive meta tags and charset definitions in the views.

examples/mvc/controllers/user · high confidence

New Markdown rendering example with security fixes

Added a new example in examples/markdown that demonstrates rendering Markdown files using the 'marked' library instead of the deprecated 'github-flavored-markdown'. The example registers a custom view engine for .md files, uses 'path.join' for robust path handling, and includes 'escape-html' to prevent XSS vulnerabilities when interpolating variables into the rendered HTML.

examples/markdown · high confidence

New error-pages example with verbose error settings and content negotiation

Added a new error-pages example that demonstrates how to handle HTTP errors (404, 403, 500) using Express. The example introduces a 'verbose errors' application setting, enabled by default but disabled in production, which allows templates to display detailed error information. It also showcases content negotiation using \res.format\ to serve different responses (HTML, JSON, or plain text) for 404 errors based on the client's Accept header, and uses the EJS view engine.

examples/error-pages · high confidence

New example demonstrating custom view constructors with GitHub-hosted templates

Added a new example in the view-constructor directory that shows how to register a custom view constructor to render templates directly from a GitHub repository. The example uses the 'marked' library to parse Markdown files fetched from the 'expressjs/express' repository, allowing users to render views like 'index.md' or 'Readme.md' without local template files.

examples/view-constructor · high confidence

New resource example demonstrating range queries and deletion

The examples/resource directory now includes a new index.js file that demonstrates an ad-hoc resource method for Express. This example allows users to interact with a fake user list via GET requests for single items, lists, and ranges (e.g., /users/1..3), as well as DELETE requests to remove items. It serves as a practical reference for implementing resourceful routing patterns with range support and format handling (JSON/HTML).

examples/resource · high confidence

New route-middleware example demonstrating user authentication and authorization

Added a new example in examples/route-middleware/index.js that illustrates how to implement middleware for faux authentication and role-based authorization. The example shows how to load user data, restrict access to the current user (andRestrictToSelf), and restrict actions to specific roles like admin (andRestrictTo), covering GET and DELETE routes for user resources.

examples/route-middleware · high confidence

New web-service example demonstrating API key validation and error handling

Added a new example application in examples/web-service that demonstrates how to build a web service with Express. The example implements API key validation via middleware for /api routes, serves mock data for users and repositories, and includes custom error handling middleware for status codes and a 404 handler.

examples/web-service · high confidence

Behavioural changes

Add EJS-based error page views for the examples app

The error-pages example now uses EJS templates to render its custom error pages. New view files (404.ejs, 500.ejs, error\_header.ejs, footer.ejs, and index.ejs) provide the HTML structure, including proper viewport and charset meta tags, and the 500 error page conditionally displays detailed stack traces when verbose errors are enabled.

examples/error-pages/views · high confidence

Added default styling for the MVC example

The MVC example now includes a default stylesheet (style.css) that applies a 50px padding to the body, sets the font to 16px Helvetica Neue, and styles links with a specific blue color (\#107aff) and hover underline effects.

examples/mvc/public · high confidence

Auth example now uses modular EJS view templates

The authentication example's user interface has been restructured to use separate EJS partials for the page head, footer, and login form. This change introduces a consistent layout structure with proper HTML5 semantics, including viewport and charset meta tags, accessible label associations for form inputs, and basic styling for error and success messages, improving the overall presentation and accessibility of the example application.

examples/auth/views · high confidence

Express 4.0 core library restructure

The \lib\ directory has been completely rewritten for Express 4.0, replacing the legacy \lib/express.core.js\ with a new modular architecture. The application entry point (\lib/express.js\) now exposes \express.json\, \express.urlencoded\, \express.text\, and \express.static\ middleware, which are implemented using the \body-parser\ and \serve-static\ packages. The core application logic (\lib/application.js\) has been refactored to use the \router\ package for routing and \finalhandler\ for error handling, while request and response behaviors are defined in separate \lib/request.js\ and \lib/response.js\ files. This change introduces a new dependency on \body-parser\ and \serve-static\ and removes the previous internal implementations of these features.

lib · high confidence

Migrate view-locals example from Jade to EJS with responsive meta tags

The view-locals example now uses the EJS templating engine instead of Jade, updating the view file to use EJS syntax for rendering the title and user list. The template also includes explicit meta tags for charset (utf-8) and viewport (width=device-width, initial-scale=1) to ensure proper character encoding and responsive mobile display.

examples/view-locals/views · high confidence

Pet example views switch to EJS with responsive meta tags

The pet management example views (edit and show) have been converted to the EJS templating engine. These new templates include standard HTML5 structure with charset and viewport meta tags to ensure proper rendering on mobile devices, and they display pet details and edit links using EJS syntax.

examples/mvc/controllers/pet/views · high confidence

Refactored EJS example to use modular HTML templates

The EJS example application has been restructured to use separate, reusable HTML partials for the page header and footer. The main content view now includes these components, ensuring consistent document structure across pages. The header template includes standard meta tags for charset and viewport, along with a link to the stylesheet, while the footer provides the closing body and html tags.

examples/ejs/views · high confidence

Route separation example now uses EJS templates with proper HTML structure

The route-separation example has been updated to use EJS instead of Jade for its view templates. The new views include a header partial that sets the document language to English, defines the viewport and charset meta tags for mobile responsiveness, and links the stylesheet. The index view now includes navigation links to both the users and posts pages, ensuring the example correctly demonstrates route separation with a complete HTML5 structure.

examples/route-separation/views · high confidence

Route-separation example updated to use EJS templates

The route-separation example has migrated its view layer from Jade to EJS. This change includes new EJS template files for the users section (index, view, and edit pages) and the posts index page, ensuring the example application renders correctly with the updated templating engine.

examples/route-separation/views/users · high confidence

Update MVC example views with HTML5 standards and EJS syntax

The MVC example's error page views (404 and 5xx) have been updated to use the EJS templating engine instead of the previous format. These views now include essential HTML5 meta tags for character encoding (charset) and responsive viewport settings, ensuring better rendering on mobile devices and consistent character display across browsers.

examples/mvc/views · high confidence

Updated auth and cookies examples to use modern Express middleware and strict mode

The auth and cookies examples have been updated to use 'use strict' mode and modern Express built-in middleware (express.urlencoded) instead of external dependencies like body-parser. The auth example now uses the pbkdf2-password module for hashing and handles session management with express-session, while the cookies example uses cookie-parser. These changes reflect current best practices for Express application structure and security.

examples/auth · high confidence

Updated downloads example to use strict mode and secure path handling

The downloads example has been rewritten to use strict mode and the updated res.download API. It now uses path.join for constructing file paths and includes a root option to prevent path traversal vulnerabilities, ensuring safer file downloads.

examples/downloads · high confidence

Test coverage

Added acceptance tests for example applications; Added test fixtures for static file serving and template rendering; Added unit tests for core routing and application components; New test support utilities and environment configuration; Removal of legacy JSpec test runner files.

Dependencies

Express 5.2.1 release with updated dependencies and Node 18 requirement

This release updates the Express framework to version 5.2.1, enforcing Node.js 18 as the minimum supported runtime. The dependency list has been refreshed to include major version bumps for several core modules, including accepts, content-disposition, content-type, fresh, mime-types, router, serve-static, and type-is, alongside updates to body-parser, cookie, debug, depd, encodeurl, finalhandler, http-errors, merge-descriptors, on-finished, proxy-addr, qs, send, and statuses. Dev dependencies such as ejs, marked, mocha, and nyc have also been updated to their latest versions.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 39 → 55 (+15.9)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 47 → 44 (-3.4)
  • Architecture 99 (new)
  • Maturity 60 → 59 (-1.3)
  • Readiness 23 → 61 (+37.6)
  • Security 72 → 76 (+3.9)

Resolved (30)

  • Dimension evaluation failed
  • High: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • …and 10 more

New (44)

  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no committed lockfile, so no resolved version to grade)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • No SBOM
  • No assertions (empty test): should not stack overflow with many registered routes (test/Router.js)
  • No assertions (empty test): should not throw if all callbacks are functions (test/Router.js)
  • …and 24 more

Changes since last survey

  • 12 commits — 10 feature/other, 2 fixes

By area

  • .github/workflows — 5 commits
  • (root) — 4 commits
  • lib/response.js — 2 commits
  • .github/dependabot.yml — 1 commit

Notable commits

  • fix: deps: bump body-parser to ^2.3.0 to fix [CVE redacted] (#7390)
  • fix: fix(res.send): preserve ETag generation with Transfer-Encoding (#7459)
  • change: build(deps): bump actions/checkout from 7.0.0 to 7.0.1 (#7403)
  • change: build(deps): bump coverallsapp/github-action from 2.3.7 to 2.3.8 (#7399)
  • change: build(deps): bump github/codeql-action/upload-sarif (#7400)
  • change: build(deps): bump the github-actions group with 5 updates (#7462)
  • change: build(deps-dev): bump hbs from 4.2.1 to 4.3.0 (#7450)
  • change: build(deps-dev): bump morgan from 1.11.0 to 1.12.0 (#7461)
  • change: chore: group github actions updates (#7460)
  • change: ci: add npm staged publication with dist-tag support (#7464)
  • change: docs(res.location): clean up deprecated back string references (#7406)
  • change: docs: fix capitalization of GitHub Discussions in Readme (#7426)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

expressjs/express was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 9a34acf03cb818ff3f8bc40e44176e277a25cbb9 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-dd72cc24c749.