Skip to content
CAI
Software that uses CAICheck a score

gosuperscript/laravel-eventstore

60.3

Adequate · 21 September 2026

996

lines of production code

PHP

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This is a Laravel package that integrates Greg Young's EventStore with the framework's event system, enabling automatic persistence of domain events to an event store. It provides configuration, logging, and worker processes to handle event streams in parallel, while offering testing utilities to verify event state. The system supports multiple Laravel versions and modern PHP dependencies.

Features

Add event store assertion helpers for testing

Added new test utilities in src/TestUtils to verify event store state. The InteractsWithEventStore trait provides methods to assert that specific events were raised, were not raised, or occurred in a specific order. These assertions are backed by new constraint classes (EventOnEventStoreConstraint, EventNotOnEventStoreConstraint, EventsOnEventStoreConstraint) that query the event store client to check for event presence and order. Additionally, a MakesEventRecords trait was added to simplify the creation of mock event records for tests.

src/TestUtils · high confidence

Initial release of the Laravel EventStore package

The package is introduced, providing a way to integrate Greg Young's eventstore with Laravel's event system. Users can mark events with the \ShouldBeStored\ interface to automatically persist them to an event store, and configure a service provider to handle event-to-class mapping and logging. The release includes configuration for TCP and HTTP URLs, stream definitions, and subscription settings, along with standard project scaffolding like \.editorconfig\, \phpunit.xml.dist\, and documentation files.

(repo-wide) · high confidence

Introduce event store contracts and listener for event persistence

Added two new interfaces, CouldBeReceived and ShouldBeStored, to define the contract for event objects that can be persisted to the event store. A new listener, SendToEventStoreListener, was introduced to handle the persistence of events by posting them to the event store's API, ensuring that events are not duplicated if they have already been received.

src/Contracts, src/Listeners · high confidence

Introduce eventstore configuration file with environment variable support

A new configuration file for the Eventstore connection has been added, defining endpoints for TCP and HTTP URLs, subscription and volatile stream lists, the subscription group, and a connection identifier. All values default to environment variables (e.g., EVENTSTORE\_TCP\_URL, EVENTSTORE\_HTTP\_URL, EVENTSTORE\_SUBSCRIPTION\_STREAMS, EVENTSTORE\_VOLATILE\_STREAMS, EVENTSTORE\_SUBSCRIPTION\_GROUP, and EVENTSTORE\_CONNECTION), allowing users to configure the Eventstore connection via environment variables rather than hardcoded values.

config · high confidence

New traits for event store integration and metadata collection

Added five new PHP traits in the \src/Traits\ directory to support event sourcing. \SendsToEventStore\ provides methods to serialize public properties and extract metadata for events. \ReceivedFromEventStore\ handles deserializing events from the store. Three new metadata traits (\AddsHerokuMetadata\, \AddsLaravelMetadata\, \AddsUserMetaData\) allow automatic inclusion of environment-specific, framework-specific, and current user data in event metadata.

src/Traits · high confidence

Removals

Removal of legacy EventStore classes

The EventStore module has removed several core classes: the abstract SendEvent and ReceiveEvent base classes, their corresponding listener classes (SendEventListener, ReceiveEventListener), the ShouldBeSent and ShouldBeReceived interfaces, and the Stream base class along with its specific implementations (AccountsStream, BusinessExceptionsStream, QuotesStream). This eliminates the previous mechanism for sending and receiving events through HTTP requests and stream-based storage.

src/EventStore · high confidence

Behavioural changes

Refactored EventStore configuration and logging defaults

The package now provides default implementations for event-to-class mapping and logging, removing the need for manual configuration in most cases. The \EventStore\ class now includes static methods (\eventToClass\, \workerLogger\, \workerErrorLogger\, \threadLogger\) that set up sensible defaults (e.g., mapping events to \App\\Events\\\*\ classes, using Laravel's Log facade). The \ServiceProvider\ automatically registers these defaults if not already set. Additionally, the \Client\ class was moved from \src/EventStore/Client.php\ to \src/Client.php\ and updated to read the EventStore URL from \config('eventstore.http\_url')\ instead of \config('services.eventstore.web\_url')\. This simplifies setup by requiring fewer configuration steps for common use cases.

src · high confidence

Refactored EventStore worker to use separate threads for each stream

The EventStore worker has been refactored to spawn a separate process for each subscription stream, allowing volatile and persistent streams to be handled in parallel. The main worker now manages these child processes, restarting them if they stop, and logs their output and errors. A new \EventStoreWorkerThread\ command handles the actual subscription logic for each stream, and a \ConnectionLostException\ was added to track connection issues.

src/Console · high confidence

Test coverage

Added TestEvent fixture for event handling tests; Added test coverage for event store components.

Dependencies

Update Laravel and dependency support

The package now supports Laravel 5.7 through 8.x, allowing users to integrate the event store with a wider range of Laravel versions. Additionally, the library has been updated to support both Ramsey UUID versions 3.8 and 4.0, and Guzzle HTTP client versions 6.3 through 7.x.

(dependencies) · medium confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 56 → 60 (+4.5)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 95 → 98 (+2.5)
  • Architecture 69 → 69 (+0.0)
  • Maturity 50 → 50 (+0.0)
  • Readiness 50 → 63 (+13.7)
  • Security 68 → 76 (+8.3)

Resolved (10)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (7 lines × 2) (src/TestUtils/Constraint/EventNotOnEventStoreConstraint.php)
  • EventsOnEventStoreConstraint.evaluate (cognitive 28) (src/TestUtils/Constraint/EventsOnEventStoreConstraint.php)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No exposed public API
  • Scanner failed to run — not a clean result
  • Test reliability not included
  • dormant codebase — no living knowledge left to concentrate

New (15)

  • Dependency hygiene PARTLY measured — Composer dependencies read, no committed lock to grade for currency
  • Documentation: no architecture or design documentation (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicate interface/contract definition. The SendsToEventStore trait defines getters for eventType, eventId, data, and metadata that are identical to those in the ShouldBeStored interface. The trait also lacks getEventStream(), but the overlap on the other four methods suggests SendsToEventStore is either a partial implementation of ShouldBeStored or a redundant definition.
  • Duplicate interface/contract definition. The methods getEventRecord and setEventRecord are defined identically in both the CouldBeReceived interface and the ReceivedFromEventStore trait. This creates ambiguity for implementers: should they implement the interface, use the trait, or both? If both, they are redundant.
  • Duplicated block (10 lines × 3) (src/TestUtils/Constraint/EventNotOnEventStoreConstraint.php)
  • Duplicated block (12 lines × 2) (src/TestUtils/Constraint/EventNotOnEventStoreConstraint.php)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium: security finding (details withheld)
  • No dependency advisory monitoring
  • Scanner failed to run — not a clean result
  • Scanner failed to run — not a clean result
  • Secret exported as workflow-level env

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

gosuperscript/laravel-eventstore was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 814abc428f1232cc4e1fc8b4f1217e3555762217 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.