Skip to content
CAI
Software that uses CAICheck a score

Graphify-Labs/graphify

48.8

Weak · 26 September 2026

136.6k

lines of production code

Python

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a code analysis tool that converts source code and documents into knowledge graphs by extracting structural relationships across a wide variety of programming languages. It processes input files to build network graphs, detects community structures, and exports the resulting data to visual HTML reports or graph databases like Neo4j. The project provides modular extractors, regression tests for multi-language support, and worked examples to demonstrate its graphing and querying capabilities.

Features

Add .dockerignore and .gitattributes to improve repository hygiene

The repository now includes a .dockerignore file to exclude development artifacts, caches, and documentation from Docker build contexts, and a .gitattributes file to prevent generated HTML files from skewing the repository's primary language detection on GitHub.

(repo-wide) · high confidence

Added script to generate animated README demo SVG

A new Python script (scripts/gen\_demo\_path.py) generates an animated SVG (docs/demo-path.svg) for the README, visualizing a 'path lights up' demo where a terminal command triggers a graph traversal animation using the brand palette.

scripts · high confidence

Added skillgen expected output files for graphify agent skills

Added expected markdown files for the graphify skill across multiple agent platforms (agents, antigravity, claude, gemini, kiro, vscode, aider, amp, claw). These files define the instructions and usage patterns for the graphify tool, which converts codebases into knowledge graphs. The files include usage instructions, step-by-step guides for installation, file detection, extraction, and querying, as well as platform-specific configurations and rules for using the graphify tool.

tools · high confidence

New worked examples for document pipeline and httpx-like codebases

Added two new reproducible worked examples in the \worked/\ directory to demonstrate the tool's graphing capabilities. The \worked/example/\ example provides a small, self-contained document ingestion and search pipeline (parser, validator, processor, storage, and API modules) with architecture notes, allowing users to trace call relationships and community structures in a linear, multi-module system. The \worked/httpx/\ example provides a synthetic 6-file Python codebase modeled after the httpx HTTP library, featuring a clean layering of exceptions, models, authentication, transport, and client classes, complete with a generated graph report (\GRAPH\_REPORT.md\) and evaluation review (\review.md\) to showcase node/edge extraction, community detection, and surprising connection identification.

worked · high confidence

Removals

Removal of the graphify Python package

The entire \src/graphify\ module has been removed, deleting all associated source files including the core pipeline components (\analyzer\, \ast\_extractor\, \detector\, \exporter\, \graph\_builder\, \models\, \reporter\, \visualizer\) and the package initialization file. This eliminates the library's capability to extract knowledge graphs from code and documents, detect file types, build network graphs, and generate reports or visualizations.

src/graphify · high confidence

Architecture

Language extractors migrated to a modular package structure

The monolithic \graphify/extract.py\ is being split into a new \graphify/extractors\ package, with individual modules created for each supported language (e.g., \bash.py\, \csharp.py\, \cobol.py\). This change introduces a registry (\LANGUAGE\_EXTRACTORS\) and a shared base module (\base.py\) containing common utilities like \\_make\_id\ and \\_file\_stem\. The migration follows a strict 'verbatim move' policy to ensure behavior preservation, with \extract.py\ acting as a facade that re-exports the moved functions so existing importers remain unchanged. A \MIGRATION.md\ guide is provided for porting remaining languages, noting that config-driven extractors (like Python and JavaScript) must be moved as a batch due to shared core dependencies.

graphify/extractors · high confidence

Fixes

Fix graph.html export for large graphs

Resolves a crash or failure when exporting the visualization for large code graphs, ensuring the graph.html output is generated correctly regardless of graph size.

graphify · high confidence

Refactor exporters into modular package and fix HTML export stability and security

The graphify exporters have been reorganized from a single module into a dedicated package (graphify/exporters) with separate modules for base logic, HTML, and graph database exports. This change includes critical fixes for the HTML export: it now prevents vis-network stack overflow crashes on large graphs by seeding node positions, resolves stored XSS vulnerabilities in tooltips and labels via proper HTML entity encoding, and fixes broken neighbor links and hyperedge perimeter rendering. Additionally, a new exporter has been added to push graph data directly to Neo4j and FalkorDB instances.

graphify/exporters · high confidence

Test coverage

Add regression tests for the no\_cluster path replace fallback; Added test fixtures for cross-crate edge inference validation; Expanded test fixtures for multi-language extraction and structural analysis.

Dependencies

Migrate to pyproject.toml and update dependency constraints

The project has migrated its build configuration from requirements.txt to pyproject.toml, establishing a modern dependency structure with a version floor of 0.9.68. This change introduces a comprehensive suite of tree-sitter language extractors (including Python, JavaScript, TypeScript, Go, Rust, Java, C/C++, Ruby, C\#, Kotlin, Scala, PHP, Swift, Lua, Zig, PowerShell, Elixir, ObjC, Julia, Verilog, Fortran, Bash, and JSON) as core dependencies, alongside networkx, numpy, and rapidfuzz. It also defines optional extras for various backends (MCP, Neo4j, FalkorDB, PDF, video, LLM providers) and graph algorithms. The migration includes tightening version constraints for key libraries, such as capping starlette below version 2 to maintain dual-compatibility with the MCP SDK, and raising the floor for pillow to 12.3.0 to address [CVE redacted]. The legacy requirements.txt file has been removed.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 41 → 49 (+7.7)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 96 → 73 (-22.2)
  • Architecture 38 (new)
  • Maturity 70 → 59 (-10.7)
  • Readiness 15 → 58 (+43.0)
  • Security 56 → 80 (+24.4)
  • Accessibility 52 (new)

Resolved (34)

  • Analyzed solution does not cover the bulk of the repository
  • Coverage not measured — test suite did not build
  • Disclosure policy has no reporting contact
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • LLM evaluation failed
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • …and 14 more

New (798)

  • Coverage not measured — no coverage collector is wired up
  • Critical CVE: [GHSA redacted] (uv.lock)
  • CsharpNameResolver.init (cognitive 29) (graphify/extractors/csharp.py)
  • CsharpNameResolver.init (cyclomatic 19) (graphify/extractors/csharp.py)
  • Dependency advisory scan runs only on code events
  • Dependency hygiene PARTLY measured — Python dependencies read, no exact pin to grade for currency
  • Documentation: no architecture or design documentation (docs/translations/README.zh-CN.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (10 lines × 2) (graphify/analyze.py)
  • Duplicated block (10 lines × 2) (graphify/cache.py)
  • Duplicated block (10 lines × 2) (graphify/cluster.py)
  • Duplicated block (10 lines × 2) (graphify/exporters/graphdb.py)
  • Duplicated block (10 lines × 2) (graphify/extract.py)
  • Duplicated block (10 lines × 2) (graphify/extract.py)
  • Duplicated block (10 lines × 2) (graphify/extractors/apex.py)
  • Duplicated block (10 lines × 2) (graphify/extractors/dm.py)
  • Duplicated block (10 lines × 2) (graphify/extractors/erlang.py)
  • Duplicated block (10 lines × 2) (graphify/install.py)
  • Duplicated block (10 lines × 2) (graphify/symbol_resolution.py)
  • Duplicated block (10 lines × 3) (graphify/cli.py)
  • …and 778 more

Changes since last survey

  • 300 commits — 135 feature/other, 165 fixes

By area

  • graphify/extractors — 63 commits
  • (root) — 42 commits
  • graphify/extract.py — 31 commits
  • graphify/build.py — 11 commits
  • graphify/watch.py — 11 commits
  • graphify/cli.py — 10 commits
  • graphify/dedup.py — 8 commits
  • graphify/cache.py — 7 commits
  • graphify/hooks.py — 7 commits
  • graphify/install.py — 5 commits
  • graphify/paths.py — 5 commits
  • graphify/serve.py — 5 commits
  • tests/test_js_destructured_export.py — 5 commits
  • tests/test_watch.py — 5 commits
  • tests/test_dedup.py — 4 commits
  • tests/test_elixir_import_resolution.py — 4 commits
  • tools/skillgen — 4 commits
  • graphify/main.py — 3 commits
  • graphify/detect.py — 3 commits
  • graphify/export.py — 3 commits

Notable commits

  • fix: Add a regression test for a genuinely external module reference
  • fix: Add a regression test for the PHP JS id collision edge drop
  • fix: Add a regression test for the god node guard on a duplicate name
  • fix: Add a regression test for the god node guard on the fallback
  • fix: Add a regression test for the issue's own repro
  • fix: Add a regression test for the qualified only fallback
  • fix: Add a regression test for the stray source_location gate
  • fix: Add a regression test for unexported require destructures
  • fix: Add an end to end regression test for the reporter's exact repro
  • fix: Add end to end regression test for the issue own repro shape
  • fix: Add regression test for an ambiguous basename staying skipped
  • fix: Add regression test for dangling edge pruning consistency
  • fix: Add regression test for defines_id on a non Latin path
  • fix: Add regression test for non Latin segments in id prefixes
  • fix: Add regression test for stale sidecar cohesion recomputation
  • fix: Add regression test for the clustered path replace fallback
  • fix: Add regression test for the no_cluster path replace fallback
  • fix: Add regression test for the stale sidecar html export path
  • fix: Add regression test for unscoped callers with no allowlist
  • fix: Add regression tests executing Step 1 with a hostile substituted path
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

Graphify-Labs/graphify was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 4000de15466588ec3ee32f9e10a587ca97d3b8a5 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-a15879f6f801.