gchq/CyberChef
38.1
Weak · 25 September 2026
82.8k
lines of production code
JavaScript
primary language
4
measurements over time
What this system is
CyberChef is a client-side tool for encryption, encoding, compression, and data analysis that provides a modular engine for chaining operations on various data types. It features a modern web interface with a component-based architecture and background workers to ensure UI responsiveness during heavy processing. The system also exposes a programmatic Node.js API, allowing operations to be invoked and integrated into server-side environments.
How it got here
2016 — Build system modernization and refactoring
14 changes.
The project underwent a comprehensive overhaul of its development infrastructure, migrating the build pipeline from Grunt to Webpack and upgrading to Node.js 24. Core JavaScript modules were refactored to CommonJS syntax, and legacy CSS, HTML, and Apache-specific configurations were removed to support a modern, modular architecture.
2017–2018 — ESM migration and UI modernization
18 changes.
The project underwent a comprehensive migration from CommonJS to ES modules, restructuring both the core logic and web interface to leverage modern JavaScript standards and web workers for improved performance. This period also focused on modernizing the user experience through a component-based architecture, dynamic CSS theming, and the introduction of new cryptographic and forensic operations.
2019–2023 — Architecture modernization and test expansion
13 changes.
This period focused on restructuring the application's core architecture, including modularizing dish types, separating event handling, and offloading heavy tasks to web workers to improve performance and maintainability. Significant effort was also dedicated to expanding test coverage across Node.js and browser environments, alongside adding support for GOST cryptography and bitmap fonts.
Features
Added GOST cryptographic algorithm support
Added vendor implementations for GOST 28147-89, GOST R 34.12-2015, GOST R 34.11-94/2012, and GOST R 34.10-2012 encryption, hashing, and digital signature algorithms to the core crypto module.
src/core/vendor/gost · high confidence
Added Google Analytics, sitemap generation, and structured data for SEO
The static assets now include Google Analytics tracking via a new ga.html file, a sitemap.mjs script that generates an XML sitemap for all operations and recipes, and a structuredData.json file providing Schema.org metadata (including a search action) to improve search engine visibility.
src/web/static · high confidence
Added X86-64 disassembler, Ascon cryptographic operations, and EXIF removal tools
The vendor library now includes three new capabilities: an X86-64 binary disassembler for analyzing machine code, a full implementation of the Ascon cipher suite (Hash, MAC, Encrypt, Decrypt) compliant with NIST SP 800-232, and a utility to strip EXIF metadata from JPEG images.
src/core/vendor · high confidence
Added bitmap font variants for text-on-image operations
Added new bitmap font definitions (Roboto, Roboto Black, Roboto Mono, and Roboto Slab) in the \src/web/static/fonts/bmfonts\ directory to support the 'add text to image' feature. These files provide the necessary glyph metrics and kerning data for rendering text as images using the JIMP library.
src/web/static/fonts · high confidence
Initial release of the CyberChef web application
This entry introduces the CyberChef web application, a client-side tool for encryption, encoding, compression, and data analysis. The release includes the main HTML interface with a preloader featuring randomized loading messages, an operations search and list, a recipe configuration pane, and input/output editors. It supports downloading the application as a ZIP file for local use, provides options for saving and loading recipes, and includes a modern warning for unsupported browsers like Internet Explorer.
src/web/html · high confidence
New A1Z26 Cipher Encode and Decode operations
Users can now encode text to A1Z26 cipher numbers and decode A1Z26 numbers back to text using the new A1Z26 Cipher Encode and A1Z26 Cipher Decode operations in the Ciphers module. These operations support configurable delimiters (space, comma, semi-colon, colon, line feed, CRLF) for separating the numeric values.
src/core/operations · high confidence
New Node.js API with ESM/CJS support and REPL
The Node.js environment now features a dedicated API layer that allows operations to be invoked using named object properties instead of positional arrays, improving clarity. This update introduces a \File\ shim to emulate browser File objects for file-based operations, a \NodeRecipe\ class for chaining operations, and a \NodeDish\ subclass for better Node.js logging and type handling. The API supports both ESM and CommonJS module systems and includes a new REPL command for interactive use.
src/node · high confidence
New and refined theme definitions for the web interface
The application now includes new theme definitions for the Classic, Dark, GeoCities, Solarized Dark, and Solarized Light themes. These CSS files define the visual appearance of the interface, including fonts, colors for operations and buttons, highlighter colors, and layout styles, allowing users to switch between these distinct visual styles.
src/web/stylesheets/themes · high confidence
New audio metadata extraction operation
A new 'Extract Audio Metadata' operation has been added to the Forensics category, enabling the parsing of ID3v2, ID3v1, APEv2, RIFF/WAV, FLAC, and OGG/Opus tags. The implementation includes a schema for structured reporting, container sniffing, and support for extracting embedded objects and C2PA provenance data from audio files.
src/core/lib · high confidence
New custom error types for operation and dish handling
The application now introduces three new custom error classes—OperationError, DishError, and ExcludedOperationError—located in src/core/errors. OperationError is designed for input errors that can be handled and displayed to the user, DishError handles type translation failures, and ExcludedOperationError is thrown when an excluded operation is invoked via the API. These types are exported via the core errors index, allowing consuming applications to catch and handle these specific error scenarios distinctly from generic errors.
src/core/errors · high confidence
Removals
Legacy HTML view layer removed
The legacy HTML view layer, consisting of the \html/\ subdirectory and its associated JavaScript modules (including \HTMLApp\, \Manager\, and various \Waiter\ components), has been removed. This deletion eliminates the previous DOM-manipulation-based rendering engine, indicating a migration to a different view implementation or build system.
src/js/views · high confidence
Removal of Apache-specific build artifacts
The \build/prod\ directory no longer includes the \.htaccess\ configuration file or the \cyberchef.htm\ single-file distribution. This removes Apache-specific server directives (such as MIME type overrides, ETag fixes, and caching headers) and the bundled HTML/JS/CSS bundle that was previously generated for direct Apache deployment.
build · high confidence
Removal of legacy CSS structure files
The layout, overrides, and utility CSS files in the structure directory have been deleted. This removes the custom styling rules for the application's layout containers, Bootstrap and third-party component overrides, and utility classes, indicating a shift away from the previous styling architecture.
src/css/structure · high confidence
Removal of the 'classic' CSS theme
The 'classic' CSS theme file has been removed from the project. This eliminates the specific styling definitions for UI elements such as the banner, title, gutters, operations, and breakpoints that were previously provided by this theme, likely requiring users to switch to a different available theme or apply custom styles.
src/css/themes · high confidence
Removal of unused standalone JavaScript libraries
Several standalone JavaScript libraries that were previously bundled in the source tree have been removed, including Sortable, Blowfish (from Dojo Toolkit), Bootstrap v3.3.6, Bootstrap Colorpicker, Bootstrap Switch, bzip2, CanvasComponents, and CryptoJS v3.1.2. This cleanup reduces the application's footprint by eliminating unused code and dependencies.
src/js/lib · high confidence
Removed Apache configuration and project statistics files
The Apache-specific configuration file (.htaccess) and the project statistics file (stats.txt) have been removed from the static assets. This eliminates server-side caching, compression, and ETag handling rules previously managed by Apache, and removes the static file containing source code metrics.
src/static · high confidence
Architecture
Core engine refactored to CommonJS modules
The core CyberChef engine files (Chef, Dish, FlowControl, Ingredient, Operation, Recipe, and Utils) have been converted from global script variables to CommonJS module syntax. This change removes the dependency on the global window object and jQuery from the core logic, enabling the application to be built for both browser and Node.js environments using webpack.
src/js/core · high confidence
Project infrastructure and developer tooling overhaul
The repository has been restructured to modernize the development environment and build pipeline. Key changes include the addition of configuration files for spell checking (.cspell.json), editor consistency (.editorconfig), and Node.js version management (.nvmrc set to v24). The build system has shifted from a Grunt-centric approach to one driven by Webpack, with the Gruntfile refactored to orchestrate Webpack tasks, configuration generation, and linting via ESLint. Documentation has been expanded with new guides for agent development (AGENTS.md), code of conduct (CODE\_OF\_CONDUCT.md), and security policies (SECURITY.md). Additionally, the Docker setup has been updated to use a multi-stage build with Node 24 and an unprivileged Nginx image, and the .gitignore has been updated to exclude generated build artifacts and IDE files.
(repo-wide) · high confidence
Waiters restructured into modular components
The application's event handling logic has been reorganized into distinct, single-responsibility modules (BackgroundWorkerWaiter, BindingsWaiter, ControlsWaiter, HighlighterWaiter, InputWaiter, OperationsWaiter, OptionsWaiter, OutputWaiter, RecipeWaiter, and SeasonalWaiter). This change replaces the previous monolithic structure, improving code maintainability and separation of concerns for features like keyboard shortcuts, input/output editing, and operation management.
src/web/waiters · high confidence
Behavioural changes
Automated generation of the Node.js API entry point
The Node.js API entry point is now automatically generated by a new script (generateNodeIndex.mjs) rather than being manually maintained. This script dynamically creates the index.mjs file, ensuring that all core operations are exported as top-level named exports and attached to the default chef object, while also handling the exclusion of specific operations and exporting error types and utility functions like help and bake.
src/node/config/scripts · high confidence
Build-time scripts rewritten to ESM and automated operation metadata generation
The build-time scripts in src/core/config/scripts have been converted from CommonJS to ES Modules (ESM) to support Node v12+ and modern tooling. This change introduces several new automated scripts: generateOpsIndex.mjs now automatically generates the operations index and test index files; generateConfig.mjs creates OperationConfig.json and module separation files based on operation metadata; generateHTMLEntities.mjs consolidates HTML entity tables into a single spec-generated source to ensure consistency between encoding and decoding operations; and newOperation.mjs provides an interactive builder for new operations. Additionally, fixCryptoApiImports.mjs and fixSnackBarMarkup.mjs patch third-party dependencies (crypto-api and snackbarjs) during the build process to fix import paths and markup compatibility issues.
src/core/config/scripts · high confidence
CSS library files removed from source tree
The standalone CSS files for several third-party libraries (bootstrap-colorpicker, bootstrap-switch, Bootstrap 3, jquery.splitter, and prettify) have been deleted from the src/css/lib directory. This change accompanies the migration of CSS packaging from Grunt to Webpack, indicating that these styles are now managed and bundled through the new build process rather than being distributed as individual source files.
src/css/lib · high confidence
Core framework refactored to ES modules with new worker architecture
The core logic has been converted from CommonJS to ES modules (\.mjs\), introducing a new \ChefWorker\ to handle baking operations in a web worker for better performance and UI responsiveness. The \Chef\ class now exposes a \bake\ method that returns the raw, unpresented dish alongside the result, allowing the application to retrieve various data types. The \Dish\ class now uses \ArrayBuffer\ as its intermediate type for improved performance on large files and supports new types like \File\, \JSON\, and \List\<File\>\. Ingredient validation has been enhanced with support for \maxLength\, \min\/\max\/\step\ constraints for numbers, and \defaultIndex\ for option/argSelector types. Comments in recipes are now treated as disabled operations to prevent interference with the Dish type.
src/core · high confidence
CyberChef web interface rewritten in ES modules with new component architecture
The web application has been converted from CommonJS to ES modules, introducing a new component-based structure for the user interface. The main entry point (index.js) now initializes the App class, which manages the entire UI state and delegates specific concerns to a suite of specialized 'Waiter' classes (e.g., InputWaiter, OutputWaiter, RecipeWaiter) via a central Manager. This refactor includes new HTML generation classes (HTMLCategory, HTMLIngredient, HTMLOperation) that handle the rendering of operations and their arguments, supporting features like dynamic theme switching, tab management, and improved input/output handling. The conversion also ensures compatibility with modern Node.js versions and improves module loading efficiency.
src/web · high confidence
Enhanced JSON formatting and diff styling
The JSON Beautify operation now supports syntax highlighting, collapsing, and formatting, with new styles for JSON documents including color-coded literals and strings, collapsible tree structures, and visual indicators for open/closed states. Additionally, diff output now uses \<ins\> and \<del\> tags with specific styling for added (underlined, highlighted) and removed (highlighted) text, improving readability of differences.
src/web/stylesheets/operations · high confidence
Enhanced output handling with CodeMirror, control character copy fixes, and file details panel
The input and output editors now use CodeMirror, enabling a new File Details side panel that displays file name, size, type, and loading progress (with optional image thumbnails). Copying text from the output now correctly restores original control characters that were visually rendered as Unicode Private Use Area or Control Picture symbols, preventing data corruption when pasting elsewhere. Additionally, the status bar now provides interactive controls for setting character encoding and end-of-line sequences, and HTML output widgets properly escape text nodes to handle control characters and prevent rendering issues.
src/web/utils · high confidence
Exclude specific operations from the Node API
The Node API now excludes a set of operations that are either redundant in a JavaScript environment, incompatible with the ES module system, or irrelevant for console usage. Specifically, flow control operations (Fork, Merge, Jump, ConditionalJump, Label, Comment) are excluded as they can be handled more easily using native JavaScript. Operations relying on the esprima library (JavaScriptBeautify, JavaScriptMinify, JavaScriptParser) are excluded because esprima does not work in .mjs files. Additionally, SyntaxHighlighter is excluded as it is irrelevant in the Node console context.
src/node/config · high confidence
Introduction of CSS utility files for theming and vendor overrides
New utility stylesheets have been added to the project to support dynamic theming and consistent UI behavior. The \\_general.css\ file defines core typography, layout helpers (such as \.hidden\ and \.blur\), and theme-aware scrollbar styling using CSS custom properties. The \\_overrides.css\ file ensures that vendor components, particularly Bootstrap elements like buttons, form controls, tables, and popovers, correctly inherit the application's theme variables and apply Material Design iconography.
src/web/stylesheets/utils · high confidence
Layout styles migrated to CSS custom properties for dynamic theming
The layout stylesheets (banner, controls, I/O, modals, operations, recipe, and structure) have been rewritten to use CSS custom properties (variables) instead of static values. This change enables dynamic theme switching, allowing the application to update colors, fonts, and borders across the entire interface—such as the banner, input/output tabs, and control buttons—without requiring a page reload.
src/web/stylesheets/layout · high confidence
New component stylesheets for workspace UI elements
Added dedicated CSS files for key workspace components: buttons, operation lists, individual operations, and panes. These styles define the visual appearance and layout of the operation list (including category titles and operation counts), operation arguments (using flexbox for ingredient layout, styling form controls, labels, and checkboxes), and workspace panes (defining title bars and control positioning). The styles rely on CSS custom properties for theming and include specific adjustments for input fields, toggles, and disabled/breakpoint states within operations.
src/web/stylesheets/components · high confidence
New dedicated web workers for input, output, and file operations
The application now offloads heavy tasks to dedicated background workers to prevent UI freezing. InputWorker manages input tabs, storage, and baking processes; LoaderWorker handles large file loading in chunks to maintain responsiveness; ZipWorker compresses outputs for download; and DishWorker performs dish conversions and buffer-to-string decoding. This separation ensures that intensive operations like file I/O, encoding, and compression no longer block the main thread.
src/web/workers · high confidence
New modular dish type system for data translation
The \src/core/dishTypes\ directory has been restructured into a modular system of ES modules (\.mjs\) to handle data translation between internal formats and ArrayBuffers. This change introduces specific translation classes for various data types—including \DishString\, \DishNumber\, \DishJSON\, \DishBigNumber\, \DishByteArray\, \DishFile\, \DishHTML\, and \DishListFile\—all extending a common \DishType\ base. This architecture allows the application to consistently convert user-facing data (such as strings, numbers, JSON objects, and file contents) into a standardized binary format and back, with specific handling for environment differences (e.g., Node.js vs. browser) in file operations.
src/core/dishTypes · high confidence
Operations refactored to CommonJS module syntax
The operations in src/js/operations have been converted from global variable assignments to CommonJS module syntax. This change modernizes the codebase's module system, allowing for better dependency management and compatibility with modern build tools like webpack, while maintaining the same operational logic for users.
src/js/operations · high confidence
Preloader UI and theme styling overhaul
The preloader screen has been redesigned with a new multi-ring spinning animation and added support for dynamic loading messages and error states. The styling has been migrated to use CSS custom properties, allowing the preloader's colors to adapt to the active theme (Classic, Dark, GeoCities, Solarized Light, and Solarized Dark). Additionally, the entry point now imports Bootstrap Material Design and highlight.js styles, integrating these UI frameworks into the application's visual presentation.
src/web/stylesheets · high confidence
Removal of legacy HTML entry point
The legacy \src/html/index.html\ file has been deleted, indicating a migration away from the previous single-page HTML structure. This change removes the original markup for the main application interface, including the banner, operations list, recipe controls, and input/output panes, suggesting the application is now served or managed through a different entry mechanism.
src/html · high confidence
Removal of legacy operation configuration files
The static configuration files \Categories.js\ and \OperationConfig.js\ have been deleted from the source tree. These files previously defined the application's operation categories (such as Data format, Encryption, and Networking) and the metadata for individual operations (including descriptions, input/output types, and argument configurations). Their removal indicates a shift away from this centralized, static configuration approach, likely in favor of a dynamic or modular registration system.
src/js/config · high confidence
Fixes
Removed JSHint configuration file
The JSHint configuration file (.jshintrc) has been removed from the src/js directory. This change eliminates the previous linting rules and global variable definitions (such as Chef, Dish, Recipe, and various Waiter components) that were previously enforced by JSHint, aligning with the project's migration to ESLint.
src/js · high confidence
Test coverage
Added Node.js consumer tests for CJS and ESM module support; Comprehensive browser-based UI and integration tests; Expanded Node.js API test coverage; Expanded test coverage for operations and validation framework; New test fixtures for audio, cipher, executable, and image formats; Refactored Node.js test runner infrastructure; Refactored test runner infrastructure and added Node.js 22+ WASM polyfill.
Dependencies
CyberChef updated to version 11.5.0 with modernized build tooling and Node.js support
CyberChef has been upgraded to version 11.5.0, introducing a comprehensive overhaul of the build system and runtime environment. The application now requires Node.js version 24 or higher and utilizes Webpack 5.110+ for bundling, replacing the previous Grunt-based build process. This update brings significant dependency changes, including the adoption of ESLint 10 for linting, Codemirror 6 for the code editor, and Bootstrap 4.6.2 for the user interface. Additionally, the package now exposes Node.js entry points (\src/node/index.mjs\ and \src/node/wrapper.js\), enabling programmatic usage of CyberChef operations in server-side environments.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 31 → 38 (+7.4)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 33 → 40 (+6.4)
- Architecture 86 (new)
- Maturity 67 → 62 (-5.5)
- Readiness 14 → 27 (+13.0)
- Security 60 → 69 (+8.1)
- Accessibility 41 (new)
Resolved (73)
- (anonymous) (cognitive 16) (src/node/api.mjs)
- (anonymous) (cognitive 20) (src/web/waiters/OutputWaiter.mjs)
- (anonymous) (cognitive 48) (src/core/operations/YARARules.mjs)
- (anonymous) (cyclomatic 17) (src/web/waiters/OutputWaiter.mjs)
- (anonymous) (cyclomatic 26) (src/core/operations/YARARules.mjs)
- Change coupling: BLAKE2b.mjs ↔ BLAKE2s.mjs (src/core/operations/BLAKE2b.mjs)
- Change coupling: HeatmapChart.mjs ↔ HexDensityChart.mjs (src/core/operations/HeatmapChart.mjs)
- Change coupling: HeatmapChart.mjs ↔ ScatterChart.mjs (src/core/operations/HeatmapChart.mjs)
- Change coupling: JSONtoYAML.mjs ↔ YAMLToJSON.mjs (src/core/operations/JSONtoYAML.mjs)
- Change coupling: JWTSign.mjs ↔ ParseTLSRecord.mjs (src/core/operations/JWTSign.mjs)
- Change coupling: JWTVerify.mjs ↔ ParseTLSRecord.mjs (src/core/operations/JWTVerify.mjs)
- Change coupling: ParseTLSRecord.mjs ↔ generateNodeIndex.mjs (src/core/operations/ParseTLSRecord.mjs)
- Change coupling: Protocol.mjs ↔ ParseTLSRecord.mjs (src/core/lib/Protocol.mjs)
- Change coupling: Recipe.mjs ↔ OperationError.mjs (src/core/Recipe.mjs)
- Change coupling: SM2Decrypt.mjs ↔ SM2Encrypt.mjs (src/core/operations/SM2Decrypt.mjs)
- Dimension evaluation failed
- FileTooLong: browser/02_ops.js (tests/browser/02_ops.js)
- FileTooLong: tests/CRCChecksum.mjs (tests/operations/tests/CRCChecksum.mjs)
- FileTooLong: tests/Crypt.mjs (tests/operations/tests/Crypt.mjs)
- High CVE: [GHSA redacted] (package-lock.json)
- …and 53 more
New (283)
- AESDecrypt.run (cognitive 16) (src/core/operations/AESDecrypt.mjs)
- AddTextToImage.run (cyclomatic 24) (src/core/operations/AddTextToImage.mjs)
- App.loadURIParams (cognitive 18) (src/web/App.mjs)
- AudioMetaSchema.sniffContainer (cognitive 32) (src/core/lib/AudioMetaSchema.mjs)
- AudioMetaSchema.sniffContainer (cyclomatic 42) (src/core/lib/AudioMetaSchema.mjs)
- AudioParsers.parseWmaAsf (cognitive 35) (src/core/lib/AudioParsers.mjs)
- AudioParsers.parseWmaAsf (cyclomatic 26) (src/core/lib/AudioParsers.mjs)
- AudioParsers.processId3v2 (cyclomatic 16) (src/core/lib/AudioParsers.mjs)
- AudioParsers.processRiffChunk (cognitive 18) (src/core/lib/AudioParsers.mjs)
- Banned license: openpgp
- Banned license: ua-parser-js
- Base64.fromBase64 (cognitive 43) (src/core/lib/Base64.mjs)
- Base64.fromBase64 (cyclomatic 33) (src/core/lib/Base64.mjs)
- Bech32.decode (cognitive 43) (src/core/lib/Bech32.mjs)
- Bech32.decode (cyclomatic 32) (src/core/lib/Bech32.mjs)
- Bech32.encode (cognitive 19) (src/core/lib/Bech32.mjs)
- Bech32.encode (cyclomatic 16) (src/core/lib/Bech32.mjs)
- BindingsWaiter.parseInput (cognitive 37) (src/web/waiters/BindingsWaiter.mjs)
- BindingsWaiter.parseInput (cyclomatic 30) (src/web/waiters/BindingsWaiter.mjs)
- BitwiseOp.bitOp (cognitive 16) (src/core/lib/BitwiseOp.mjs)
- …and 263 more
Changes since last survey
- 54 commits — 42 feature/other, 12 fixes
By area
- (root) — 31 commits
- src/core — 11 commits
- .github/workflows — 4 commits
- src/web — 2 commits
- tests/operations — 2 commits
- src/node — 1 commit
- tests/browser — 1 commit
- tests/lib — 1 commit
- tests/node — 1 commit
Notable commits
- fix: Apply npm audit fix (non-breaking security updates) (#2841)
- fix: Revert "Use webpack native CSS and HTML support" (#2816)
- fix: Safari drag/drop fixes (#2271)
- fix: fix(ParseIPRange): mask host bits in Network output for CIDR ranges (#2694)
- fix: fix: accept hexadecimal values for Disassemble x86 address arguments (#2721)
- fix: fix: preserve anchor tags with pre-existing target attribute in RenderMarkdown (#2767)
- fix: fix: prevent LM Hash crash on inputs that expand when uppercased (#1807) (#2787)
- fix: fix: remove duplicate RandomPrime operation file (#2764)
- fix: fix: support Webpack 5.110+ worker builds (#2779)
- fix: fix: treat numeric 0 input as a value, not an empty dish, in the Node API (#2759)
- fix: fix: use OperationError instead of bare Error in MOD, LuhnChecksum, a… (#2766)
- fix: fix: use defaults for blank number ingredients (#2707)
- change: Add "Parse PGP Key" Operation (#2734)
- change: Add XPRESS (MS-XCA) decompression operations (#2722)
- change: Bump v11.4.0 (#2733)
- change: Bump v11.5.0 (#2845)
- change: Feat/node 26 support (#2699)
- change: Report byte offsets for Protobuf decode errors (#2834)
- change: SECURITY: prevent autobake on loaded recipe if any operation has manualBake set
- change: Security: patch XSS in Regular expression module
- …and 34 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
gchq/CyberChef was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit fb95859b4e57acf42c448ec1a07a4b9221a4e9e9 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-dd72cc24c749.