Skip to content
CAI
Software that uses CAICheck a score

giacomomasseron/php-clean-architecture

70.6

Strong · 20 September 2026

1.2k

lines of production code

PHP

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a PHP library and CLI tool designed to scaffold, enforce, and maintain Clean Architecture in PHP projects. It provides command-line utilities to generate boilerplate code for entities, repositories, use cases, and controllers, while automatically applying static analysis rules to ensure architectural boundaries are respected. Additionally, it manages the execution lifecycle of use cases through an event-driven model, replacing previous callback-based hooks with explicit start and completion events.

Features

Added clean-architecture stubs and configuration templates

The package now includes a set of stub files in the \stubs/\ directory to help scaffold clean-architecture components. These include PHP class templates for Controller, Entity, Repository, Service, and UseCase that implement the library's specific interfaces (e.g., \ControllerInterface\, \UseCaseInterface\). Additionally, configuration stubs for Deptrac (\deptrac.yaml.stub\) and Rector (\rector.php.stub\) are provided, pre-configured with the library's layer rules and rector classes to enforce architectural boundaries and code quality standards out of the box.

stubs · high confidence

Added event classes for use-case lifecycle tracking

Introduced a base \Event\ class and two specific event types, \UseCaseStartedEvent\ and \UseCaseCompletedEvent\, to signal the beginning and end of use-case execution. The base event extends Symfony's event dispatcher event and implements the PSR-14 stoppable event interface, carrying the executed use-case instance for context.

src/Events · high confidence

Introduce CLI scaffolding and architecture enforcement for Clean Architecture

The package now includes a CLI tool (\vendor/bin/php-clean-architecture\) that allows users to scaffold project structure and enforce architectural boundaries. Users can run commands to install configuration files (\deptrac.yaml\, \php-clean-architecture.yaml\), check for layer dependency violations, auto-add marker interfaces via Rector, and generate boilerplate classes for Entities, Repositories, UseCases, Controllers, and Services. This change shifts the package from a passive library to an active scaffolding and validation tool, requiring users to run the \install\ command after installation to publish the necessary configuration files.

(repo-wide) · high confidence

Introduction of core clean architecture interfaces

The src/Contracts directory now defines the foundational contracts for the application's clean architecture. New interfaces have been added for Command, Controller, Entity, Repository, and Service components, establishing the structural boundaries for these layers. Additionally, the existing UseCaseExecutor and UseCase interfaces have been updated to enforce strict typing via the declare(strict\_types=1) directive, ensuring type safety for use case execution.

src/Contracts · high confidence

New CLI commands for scaffolding and architecture enforcement

This change introduces a new set of command-line tools in the src/Commands directory to help developers scaffold and maintain a clean architecture. The InstallCommand now automates the setup of configuration files (deptrac.yaml, php-clean-architecture.yaml, rector.php) by copying stubs and injecting project-specific paths and namespaces, while offering to overwrite existing files. The CheckCommand allows users to run the deptrac static analysis tool, and the RectorCommand applies PHP rector rules for code refactoring. Additionally, a family of Make\* commands (MakeController, MakeEntity, MakeRepository, MakeService, MakeUseCase) has been added to generate new class files from templates, automatically placing them in the correct directories and namespaces defined in the configuration.

src/Commands · high confidence

New PHPCleanArchitectureRectorableTrait for automatic interface implementation

A new PHP trait, PHPCleanArchitectureRectorableTrait, has been added to the src/Concerns directory. This trait provides reusable logic for Rector-based code refactoring, specifically enabling the automatic addition of interface implementations to classes within configured target namespaces. It includes methods to check if a class already implements a specific interface and to verify if a class belongs to a designated namespace, streamlining the enforcement of clean architecture patterns during static analysis and code transformation.

src/Concerns · high confidence

New Rector rules to enforce clean architecture interfaces

This release introduces a set of new Rector rules that automatically add specific clean architecture interfaces to classes based on their role. The \LevelsEnum\ defines the architectural layers (entities, repositories, use cases, controllers, services), and corresponding Rector rules (\AddPHPCleanArchitectureInterfaceEntityToClassesRector\, \AddPHPCleanArchitectureInterfaceRepositoryToClassesRector\, \AddPHPCleanArchitectureInterfaceUseCaseToClassesRector\, \AddPHPCleanArchitectureInterfaceControllerToClassesRector\, \AddPHPCleanArchitectureInterfaceServiceToClassesRector\) ensure that classes in these layers implement the appropriate interface (\EntityInterface\, \RepositoryInterface\, \UseCaseInterface\, \ControllerInterface\, \ServiceInterface\). This helps maintain a consistent and strict clean architecture structure across the codebase.

src/Enums, src/Rector · high confidence

Behavioural changes

Use case execution now uses a singleton pattern and dispatches lifecycle events

The \BaseUseCase\ class has been refactored to enforce a singleton instantiation model, replacing the previous per-invocation object creation with a static \getInstance\ method and a private constructor. This change alters how use cases are initialized and shared during execution. Additionally, the execution flow now integrates with the \Dispatcher\ to emit \UseCaseStartedEvent\ and \UseCaseCompletedEvent\ events around the use case's \handle\ method, enabling external listeners to react to the start and completion of use cases. The previous callback-based hooks (\beforeExecute\, \afterExecute\, \rollback\) have been removed in favor of this event-driven approach.

src · high confidence

Test coverage

Added strict types declarations to test files

Added \declare(strict\_types=1);\ to the test bootstrap and configuration files (\tests/Pest.php\, \tests/TestCase.php\, and \tests/Feature/ExampleTest.php\) to enforce strict type checking within the test suite.

tests · high confidence

Dependencies

Update PHP version requirement and stabilize dependency versions

The project now requires PHP 8.2 or higher and has shifted its minimum stability from 'dev' to 'stable' to ensure more reliable dependency resolution. Several development tools have been updated to newer major versions, including PHPStan (2.1), PHP CS Fixer (3.0), and Composer (2.9). Additionally, the 'deptrac/deptrac' dependency was moved from 'require-dev' to 'require' with a version constraint of ^4.6, and new dependencies for Symfony YAML and Event Dispatcher were added.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 57 → 71 (+13.7)
  • Rubric changed (rubric-2026.08.17 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 99 (+0.5)
  • Architecture 69 → 69 (+0.0)
  • Maturity 76 → 79 (+3.1)
  • Readiness 81 → 80 (-0.7)
  • Security 37 → 65 (+28.0)

Resolved (19)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — no supported dependency manifest was read
  • Duplicated block (24 lines × 5) (src/Commands/Makes/MakeControllerCommand.php)
  • Duplicated block (47 lines × 2) (src/Application.php)
  • Duplicated block (5 lines × 2) (src/Commands/InstallCommand.php)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No exposed public API
  • Off-boarding risk: anonymized user #1
  • Test reliability not included

New (21)

  • Dependency hygiene PARTLY measured — Composer dependencies read, no committed lock to grade for currency
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (13 lines × 2) (src/Application.php)
  • Duplicated block (29 lines × 5) (src/Commands/Makes/MakeControllerCommand.php)
  • Duplicated block (5 lines × 2) (src/Commands/InstallCommand.php)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Members sharing a duplicated core (5 members, 50+ identical tokens) (src/Commands/Makes/MakeControllerCommand.php)
  • …and 1 more

Changes since last survey

  • 3 commits — 2 feature/other, 1 fixes

By area

  • (root) — 2 commits
  • (repo) — 1 commit

Notable commits

  • fix: fix: Reviewed the dependabot deptrac bump and fixed two issues: removed committed merge-conflict markers from the auto-merge workflow, and loosened deptrac's exact pin to ^4.6 in composer.json
  • change: Merge pull request #16 from giacomomasseron/dependabot/composer/deptrac/deptrac-4.7.1
  • change: build(deps): update deptrac/deptrac requirement from 4.6.2 to 4.7.1

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

giacomomasseron/php-clean-architecture was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit e8b5389eef9463851660aea25ba280e741bf6213 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.