Skip to content
CAI
Software that uses CAICheck a score

gotthardp/lorawan-server

38.7

Weak · 23 September 2026

8.7k

lines of production code

Erlang

with JavaScript

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is an open-source LoRaWAN server that integrates network and application server functions for private IoT networks. It provides a comprehensive administration interface and RESTful API for managing gateways, devices, and network configurations. The platform also includes operational tooling for deployment, database management, and automated testing.

Features

Add Buildroot package for LoRaWAN Server

A new Buildroot package for the open-source LoRaWAN Server is introduced, allowing users to build and install the network and application server components. The package is configured via a new Config.in entry that selects Erlang as a dependency, and the corresponding lorawan-server.mk file defines the build and installation steps for version v0.7.0.

scripts/buildroot · high confidence

Add scripts for database backup/restore and service management

New shell and batch scripts are provided to simplify running the LoRaWAN server as a background service on Linux (via systemd) and Windows (via erlsrv). The scripts include a startup wrapper (lorawan-server) that resolves the installation directory and configures logging, a control utility (lorawanctl) for managing the running node, and a service unit file for the packet forwarder. Additionally, new dbexport and dbimport scripts (for both Unix and Windows) allow users to back up and restore the server's database via the HTTP API.

scripts · high confidence

Improved Debian packaging and the systemd service

The project now includes a complete set of scripts for building .deb packages, including build-deb, control.template, conffiles.template, postinst, and postrm. This enables users to install the server via standard Debian package management, with automatic creation of the 'lorawan' user and log directory during installation, and proper cleanup (including user removal) during package removal.

scripts/dpkg-deb · medium confidence

Initial admin panel scaffolding with user management

The admin area now includes a complete React-based admin interface built on react-admin. This adds a dashboard, a custom sidebar menu with collapsible sections, and full CRUD views (list, show, create, edit) for managing Users and Scopes. The app connects to a JSON Server API endpoint and includes standard Create React App configuration files.

admin · high confidence

Initial release of the LoRaWAN server

The LoRaWAN server is now available as an open-source solution for private LoRaWAN networks, integrating network and application server functions. This initial release includes the core server implementation, a Dockerfile for containerized deployment, and configuration files for Erlang/OTP 21+. It supports gateways via the Packet Forwarder and Basic Station protocols, handles Class A and C devices, and provides a web-based administration interface. The server is distributed under the MIT license.

(repo-wide) · high confidence

New admin API endpoints for managing and viewing LoRaWAN entities

The update introduces a comprehensive set of new Erlang modules (e.g., \lorawan\_admin\, \lorawan\_admin\_db\_record\, \lorawan\_admin\_feed\) that implement RESTful and WebSocket-based API endpoints for the web administration interface. These changes enable users to perform CRUD operations on database records (nodes, gateways, events) with granular field-level authorization and pagination, as well as subscribe to real-time event feeds via WebSockets. The new endpoints support filtering, sorting, and exporting data, providing a more robust and secure administrative interface for managing the LoRaWAN network.

src · high confidence

New web-based administration interface for server management

The private/admin area now provides a comprehensive web-based administration interface built on ng-admin and AngularJS. This new interface allows users to manage servers, applications, users, areas, gateways, multicast channels, networks, groups, profiles, devices, nodes, queued frames, rxframes, connectors, handlers, connections, and events. It includes features such as filtering, sorting, and editing of these entities, as well as support for multiple regions, ADR configuration, and various other administrative tasks.

priv/admin · high confidence

Behavioural changes

New internal data structures for devices, gateways, and connectors

Added new Erlang record definitions in the \include/lorawan.hrl\ and \include/lorawan\_db.hrl\ header files. These changes introduce structured data types for managing network entities, including \\#area\, \\#gateway\, \\#network\, \\#group\, \\#profile\, \\#device\, \\#node\, \\#connector\, and \\#handler\. These records define the schema for storing and processing LoRaWAN data, such as RSSI/SNR metrics, GPS coordinates, and MQTT connector configurations.

include · high confidence

Test coverage

Added load and functional tests for the LoRaWAN server

Added new test modules to the test suite: \load\_tests.erl\ for simulating multiple gateways and nodes to verify system behavior under load, \loramote\_tests.erl\ for validating message handling and sequence logic, and supporting helper modules \test\_admin.erl\ and \test\_forwarder.erl\ to manage test fixtures and simulate device communication.

test · high confidence

Dependencies

Added new admin frontend dependencies

The project now includes two new package.json files that define the dependencies for the admin interface. The root package.json adds libraries for mapping (leaflet, ui-leaflet), data visualization (vis, angular-visjs), and UI components (angular-bootstrap-colorpicker). The admin/package.json introduces a React-based admin interface using react-admin, FontAwesome icons, and React 16.8.6.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 35 → 39 (+3.4)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 42 → 51 (+8.7)
  • Architecture 99 → 99 (+0.2)
  • Maturity 48 → 62 (+14.8)
  • Readiness 19 → 19 (-0.2)
  • Security 68 → 74 (+5.8)
  • Accessibility 49 → 49 (+0.0)

Resolved (17)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High IaC: DS-0029 (scripts/docker/raspbian.arm7/Dockerfile)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium IaC: CKV_DOCKER_3 (Dockerfile)
  • Medium IaC: CKV_DOCKER_3 (scripts/docker/raspbian.arm7/Dockerfile)
  • Medium IaC: CKV_DOCKER_6 (Dockerfile)
  • Medium IaC: CKV_DOCKER_7 (scripts/docker/raspbian.arm7/Dockerfile)
  • Medium IaC: DS-0013 (scripts/docker/raspbian.arm7/Dockerfile)
  • No exposed public API
  • Scanner failed to run — not a clean result
  • Test reliability not included
  • The warning states the server is a development version 0.7.x and recommends using stable 0.6.x, but no migration guide or upgrade path for developers who must switch to 0.7.x is present. (README.md)
  • TooManyMethods: lorawan_admin (src/lorawan_admin.erl)
  • complexity unreadable for .erl, .hrl — churn × complexity hotspots could not be measured
  • dormant codebase — no living knowledge left to concentrate

New (52)

  • (anonymous) (cognitive 22) (priv/admin/admin.js)
  • Coverage not measured — no coverage collector is wired up
  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no committed lockfile, so no resolved version to grade)
  • Duplicated block (5 lines × 2) (src/lorawan_admin_choices.erl)
  • Duplicated block (5 lines × 2) (src/lorawan_connector_amqp.erl)
  • Duplicated block (5 lines × 3) (src/lorawan_admin_connections.erl)
  • Duplicated block (5–6 lines × 2) (src/lorawan_mac_region.erl)
  • Duplicated block (6 lines × 2) (src/lorawan_admin_graph_node.erl)
  • Duplicated block (6 lines × 2) (src/lorawan_connector_amqp.erl)
  • Duplicated block (7 lines × 13) (src/lorawan_admin_applications.erl)
  • Duplicated block (7 lines × 2) (src/lorawan_application_backend.erl)
  • Duplicated block (7 lines × 2) (src/lorawan_connector_amqp.erl)
  • Duplicated block (8 lines × 2) (src/lorawan_connector_mqtt.erl)
  • Duplicated block (9–10 lines × 2) (src/lorawan_handler.erl)
  • FixmeComment (src/lorawan_gw_router.erl)
  • FixmeComment (src/lorawan_mac.erl)
  • Floating npm dependency: angular-simple-logger
  • Floating npm dependency: jquery
  • Floating npm dependency: ng-admin
  • High IaC: DS-0029 (scripts/docker/raspbian.arm7/Dockerfile)
  • …and 32 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

gotthardp/lorawan-server was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit ae8c1eb123acd53539e7b26f353fe54454444ace — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.