filp/whoops
65.6
Adequate · 25 September 2026
3.9k
lines of production code
PHP
primary language
4
measurements over time
What this system is
This system is a PHP error and exception handling library that provides customizable handlers for displaying and processing error details in various formats. It supports outputting structured data as JSON, XML, or plain text, alongside a rich, interactive HTML page for debugging stack traces and code context. The library allows developers to register, order, and filter handlers to manage how exceptions are inspected and rendered in both web and CLI environments.
Features
New handler classes and base infrastructure for error output
The handler subsystem now includes a new abstract base class (Handler) and interface (HandlerInterface) that standardize how handlers interact with the exception inspector and run context. This infrastructure supports several new output handlers: PlainTextHandler for command-line and logging output (including Monolog integration), JsonResponseHandler for JSON API responses (with optional json:api compliance), XmlResponseHandler for XML responses, and CallbackHandler to allow custom closures to be used as handlers. PrettyPageHandler has been updated to use this new base class and now supports additional editor integrations (VSCode, Cursor, Espresso, NetBeans, Atom) and improved superglobal masking.
src/Whoops/Handler · high confidence
Removals
Removal of legacy Handler and Run classes
The legacy \Handler\ and \Run\ classes have been removed from the codebase. This eliminates the previous mechanism for registering error/exception handlers and managing a handler stack with priority-based execution, indicating a structural shift in how error handling is wired and executed within the application.
src/DamnIt · high confidence
Behavioural changes
Redesigned Pretty Page error handler with new layout and features
The error display interface has been completely overhauled to improve usability and aesthetics. The new layout splits the view into a left panel (listing stack frames with application filtering) and a right details panel (showing code context, arguments, and environment variables). Key additions include a 'Hide' button to dismiss the error overlay, a 'Copy' button for exception details, and inline SVG icons for searching the exception on Google, Stack Overflow, DuckDuckGo, and the PHP manual. The code view now highlights the specific error line, displays frame arguments, and shows comments associated with the frame. Environment details are presented in a cleaner table format, and the header now displays previous exceptions in a chain.
src/Whoops/Resources/views · high confidence
Redesigned exception page layout and syntax highlighting
The exception handler's user interface has been completely overhauled with a new stylesheet (whoops.base.css) and the integration of PrismJS for code syntax highlighting (prism.css). This change introduces a fixed-position, two-panel layout where the stack trace is displayed in a left panel and detailed exception information in a right panel. Key visual improvements include a dark header for exception titles, distinct styling for application vs. framework frames, and enhanced readability through PrismJS-based code blocks with line numbers and highlighting. The layout is responsive, stacking panels on smaller screens, and includes interactive features like hover effects on frames and an expandable header for long exception messages.
src/Whoops/Resources/css · high confidence
Refactored error handling utilities and added optional Symfony VarDumper support
This change consolidates scattered utility functions into dedicated classes within the Util namespace: \Misc\ now holds static helpers for environment checks (e.g., \canSendHeaders\, \isAjaxRequest\) and error code translation; \SystemFacade\ wraps native PHP functions (error handlers, output buffering, HTTP status codes) to allow mocking in tests; and \TemplateHelper\ manages template rendering and variable dumping. Additionally, the error handler configuration has been updated to use \E\_ALL\ instead of \E\_ALL \| E\_STRICT\, and the \TemplateHelper\ now optionally uses Symfony's VarDumper for pretty-printing variables, including a new \HtmlDumperOutput\ class to capture the dump output. These changes improve testability, code organization, and the visual presentation of error details.
src/Whoops/Util · high confidence
Refactored exception inspection and frame handling into dedicated classes
The exception handling logic in src/Whoops/Exception has been reorganized into a structured set of classes: Inspector, Frame, FrameCollection, and Formatter. The Inspector now manages the inspection of exceptions and their chained predecessors, while FrameCollection provides a fluent interface for filtering and mapping stack frames. The new Formatter class exposes static methods to convert exception data into structured arrays or plain text, enabling programmatic access to error details. This change also includes the migration of the codebase from the 'DamnIt' to the 'Whoops' namespace and the introduction of an InspectorFactory for creating inspector instances.
src/Whoops/Exception · high confidence
Refined handler execution order and configurable exit codes in Whoops\\Run
The Whoops error handler now provides explicit control over handler execution order and CLI exit behavior. Users can use the new appendHandler and prependHandler methods to clearly define whether a handler should run first or last, replacing the previous implicit reverse-execution order. Additionally, the sendExitCode method allows customization of the exit code sent in CLI contexts (defaulting to 1), and the handler stack management includes new removeFirstHandler and removeLastHandler methods for precise cleanup.
src/Whoops · high confidence
Updated Whoops 2 example files with new handler features
The examples directory now includes updated demonstration files for Whoops 2. The new example-ajax-only.php shows how to configure JsonResponseHandler with the setJsonApi() method for JSON:API compliance. The example.php file demonstrates PrettyPageHandler enhancements including addDataTable for custom data display, setApplicationPaths for path filtering, and addDataTableCallback for dynamic inspector data. It also illustrates the new FrameCollection::map method for modifying stack frames. These examples reflect the current Whoops 2 API and provide users with working code samples for common error handling scenarios.
examples · high confidence
Upgrade syntax highlighting to Prism.js and replace clipboard library
The error page interface now uses Prism.js (v1.30.0) for syntax highlighting instead of the previous tool, providing improved code rendering with line numbers and highlighting. Additionally, the copy-to-clipboard functionality has been updated to use clipboard.js (v2.0.11) in place of the older ZeroClipboard integration, ensuring reliable copying of code snippets without requiring Flash or legacy plugins.
src/Whoops/Resources/js · high confidence
Test coverage
Added test coverage for Whoops\\Run handler management; Added test fixtures for TemplateHelper::render; Added unit tests for Whoops error handlers; Added unit tests for Whoops utility classes; Added unit tests for exception handling components; Removed legacy test infrastructure files; Updated test bootstrap configuration.
Dependencies
Update composer.json with modern PHP and dependency requirements
The composer.json manifest has been updated to require PHP 7.1 or 8.0 (dropping support for older versions) and to include psr/log as a required dependency. Development dependencies for PHPUnit, Mockery, and Symfony Var-Dumper have been expanded to support newer major versions, and the autoloading has been migrated from PSR-0 to PSR-4 with the namespace Whoops.
(dependencies) · high confidence
Housekeeping
Initial repository structure and documentation
This change establishes the foundational project structure by adding essential configuration and documentation files. It introduces an .editorconfig for consistent code formatting, a .gitattributes file to exclude non-distribution artifacts (such as docs, tests, and CI configs) from package exports, and a .mailmap to standardize contributor identities. Additionally, it provides the initial README, CHANGELOG, CONTRIBUTING, LICENSE, and SECURITY policy files, along with a Scrutinizer CI configuration and a PHPUnit test suite definition that targets the src/Whoops directory.
(repo-wide) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 48 → 66 (+17.7)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 99 → 98 (-1.5)
- Architecture 96 → 100 (+4.4)
- Maturity 59 → 54 (-4.7)
- Readiness 25 → 60 (+34.7)
- Security 61 → 85 (+24.3)
Resolved (11)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- LLM evaluation failed
- No exposed public API
- No tests found
- Test reliability not included
New (37)
- (anonymous) (cognitive 25) (src/Whoops/Resources/js/whoops.base.js)
- (anonymous) (cyclomatic 22) (src/Whoops/Resources/js/whoops.base.js)
- Dependency hygiene PARTLY measured — Composer dependencies read, no committed lock to grade for currency
- Further orphaned files (smaller)
- Further sole-owners (lower concentration)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Inspector.getFrames (cognitive 32) (src/Whoops/Exception/Inspector.php)
- No assertions (empty test): test_it_delegates_error_handling_to_the_native_implementation (tests/Whoops/Util/SystemFacadeTest.php)
- No assertions (empty test): test_it_delegates_error_handling_with_level_to_the_native_implementation (tests/Whoops/Util/SystemFacadeTest.php)
- No assertions (empty test): test_it_delegates_exception_handling_to_the_native_implementation (tests/Whoops/Util/SystemFacadeTest.php)
- No assertions (empty test): test_it_delegates_registering_a_shutdown_function_to_the_native_implementation (tests/Whoops/Util/SystemFacadeTest.php)
- No assertions: testSimpleValidFile (tests/Whoops/Handler/XmlResponseHandlerTest.php)
- No assertions: testSimpleValidLine (tests/Whoops/Handler/XmlResponseHandlerTest.php)
- No assertions: testSimpleValidType (tests/Whoops/Handler/XmlResponseHandlerTest.php)
- No assertions: test_it_delegates_cleaning_output_buffering_to_the_native_implementation (tests/Whoops/Util/SystemFacadeTest.php)
- No assertions: test_it_delegates_ending_the_current_buffer_to_the_native_implementation (tests/Whoops/Util/SystemFacadeTest.php)
- …and 17 more
Changes since last survey
- 4 commits — 2 feature/other, 2 fixes
By area
- src/Whoops — 2 commits
- (repo) — 1 commit
- docs/sponsors — 1 commit
Notable commits
- fix: Merge pull request #794 from dualfroz/dualfroz/fix-escapeuris-scheme-allowlist
- fix: fix(template-helper): restrict escapeButPreserveUris to http/https schemes
- change: Escape some HTML values that were not escaped
- change: readme: update sponsors
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
filp/whoops was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit baec851ad6ae00db8bd0fdd30d208afc1b71c56e — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-a9cd699f3cd5.