Skip to content
CAI
Software that uses CAICheck a score

Joker666/hono-starter

47.2

Weak · 21 September 2026

564

lines of production code

TypeScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This is a Node.js web application providing user authentication and account management services. It exposes RESTful endpoints for user registration, login, and profile retrieval, secured with JWT tokens. The system manages user data via a MySQL database and processes background tasks, such as sending welcome emails, using a Redis-backed job queue.

Features

Add user serialization and implement authentication controller

The src/web/controller/serializer/user.ts file was added to handle user data serialization, mapping the internal User model to a simplified UserResponse type containing id, name, email, and createdAt fields. The src/web/controller/auth.ts file was created to implement the AuthController class, which handles login, registration, and user profile retrieval (me) endpoints. The controller integrates with the UserService to fetch user data, uses the new serializer to format responses, and returns JWT tokens alongside serialized user data for login and registration flows. Error handling for database issues and user not found cases is also included.

src/web/controller · high confidence

Added async welcome email task

A new asynchronous function, sendWelcomeEmailAsync, has been added to the task client. This function schedules a SendWelcomeEmail job on the default queue for a given user ID, logging the job addition. This introduces a new capability for users to receive welcome emails via a background task.

src/task/client · high confidence

Added user repository with database operations

A new UserRepository class has been introduced in src/repository/user.ts, providing methods to create, find by ID, and find by email for user entities using Drizzle ORM.

src/repository · high confidence

Added user service for account management

A new UserService class has been introduced in src/service/user.ts to handle user-related operations. This service provides methods to create new users (including password encryption), find users by email, and find users by ID, acting as a layer between the application logic and the user repository.

src/service · high confidence

Initial database schema and connection setup

The application now includes the initial database schema and connection logic. This introduces a 'user' table containing fields for id, name, email, password, reset\_token, and timestamps, along with the corresponding Drizzle ORM schema definition and MySQL connection configuration.

src/db · high confidence

Introduces a centralized error and response handling module

Adds new modules for standardized HTTP error and data responses. The error module provides helper functions to return consistent JSON error responses for various HTTP status codes (e.g., 404, 400, 422, 401, 500) and defines specific error messages for user-related errors. The response module provides utilities to serve data and generic status responses. This change standardizes how the web controller layer formats and sends HTTP responses.

src/web/controller/resp · high confidence

Introduces core infrastructure for environment configuration, encryption, and background jobs

The application now enforces required environment variables via a new \src/lib/env.ts\ module that validates configuration (e.g., \SECRET\_KEY\, database credentials) using Zod. A new \src/lib/encryption.ts\ module provides AES-256-CBC encryption and decryption utilities. JWT token generation and verification are centralized in \src/lib/jwt.ts\. Additionally, a Redis-backed background job queue is established in \src/lib/queue.ts\ using BullMQ, and the logger is updated to respect the \LOG\_LEVEL\ environment variable.

src/lib · high confidence

Introduces structured user authentication and validation in the web layer

The web layer now features a dedicated server entry point (src/web/server.ts) that configures Hono routes for user login, registration, and profile retrieval, protected by JWT middleware. Input validation for login and registration endpoints is handled via new Zod schemas (src/web/validator/user.ts), which enforce email format, password length, and name constraints. A shared validation utility (src/web/validator/validator.ts) processes these schemas, returning 422 errors for invalid payloads. The previous generic routes file (src/web/routes.ts) has been removed.

src/web · medium confidence

New background task infrastructure for sending welcome emails

A new Tasker class has been introduced to manage background jobs via BullMQ, specifically processing a 'send\_code\_completion' task that triggers the sendWelcomeEmail function. This adds a dedicated worker setup with completion and failure logging, alongside the new sendWelcomeEmail module that handles the actual email dispatch logic.

src/task · high confidence

Project initialization and infrastructure setup

The repository has been initialized with a complete project structure, including a Node.js 22 Dockerfile, a docker-compose configuration for MySQL and Redis, and environment templates. The build system is configured with PNPM, Biome for formatting/linting, and TypeScript is set to use 'nodenext' module resolution. Additionally, a .gitignore file has been updated to exclude build artifacts and environment files, and the root script now runs the build step before starting the development server.

(repo-wide) · high confidence

Behavioural changes

Refactor server startup and add request tracing

The application's entry point has been restructured to use a dedicated Server class and explicit environment variable validation, replacing the previous inline setup. A new tracing middleware is now applied to every request, generating a unique 10-character identifier for each request. Additionally, the server now gracefully handles the SIGTERM signal to close the HTTP server, database connection, and worker processes.

src · high confidence

Dependencies

Updated dependencies and tooling in package.json and lockfile

The project's dependencies were updated, including Hono (4.3.2 → 4.6.18), pino (9.0.0 → 9.6.0), and @hono/node-server (1.11.1 → 1.13.7). New packages added include @hono/swagger-ui, @hono/zod-validator, bullmq, drizzle-orm, ioredis, mysql2, and zod. Dev dependencies were also updated, with @types/node upgraded from 20.11.17 to 22.10.10, tsx from 4.7.1 to 4.19.2, and typescript 5.7.3 added. Additionally, @biomejs/biome, drizzle-kit, and prettier were added as dev dependencies, and the Node.js engine requirement was set to \>=20.0.0 \<23.0.0.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 47 → 47 (-0.1)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 95 → 96 (+0.6)
  • Architecture 69 → 69 (+0.0)
  • Maturity 77 → 82 (+5.5)
  • Readiness 12 → 13 (+0.9)
  • Security 91 → 91 (-0.7)

Resolved (12)

  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Further orphaned files (smaller)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Medium CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Medium IaC: CKV_DOCKER_2 (Dockerfile)
  • Medium vulnerability: [GHSA redacted] (pnpm-lock.yaml)
  • Medium vulnerability: [GHSA redacted] (pnpm-lock.yaml)
  • Medium vulnerability: [GHSA redacted] (pnpm-lock.yaml)
  • No exposed public API
  • single-maintainer — knowledge-concentration (bus factor) risk

New (24)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • High IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • High vulnerability: [GHSA redacted] (pnpm-lock.yaml)
  • Medium CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Medium IaC: WD-DOCKER-0003 (Dockerfile)
  • Medium vulnerability: [GHSA redacted] (pnpm-lock.yaml)
  • Medium vulnerability: [GHSA redacted] (pnpm-lock.yaml)
  • Medium vulnerability: [GHSA redacted] (pnpm-lock.yaml)
  • Outdated (npm): @hono/node-server
  • Outdated (npm): @hono/swagger-ui
  • Outdated (npm): @hono/zod-validator
  • Outdated (npm): bullmq
  • Outdated (npm): dotenv
  • Outdated (npm): drizzle-orm
  • Outdated (npm): hono
  • …and 4 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

Joker666/hono-starter was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 87b8d423ef341c3d5d5a05cd5d2fbe32d1169ce4 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.