Skip to content
CAI
Software that uses CAICheck a score

jsonrainbow/json-schema

66.1

Adequate · 19 September 2026

9.6k

lines of production code

PHP

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is a PHP library for validating JSON documents against JSON Schema specifications, supporting multiple drafts from 03 through 2020-12. It provides a structured validation engine that resolves schema URIs, enforces strict type checking, and collects detailed constraint errors. The library also includes utilities for deep data comparison and URI handling to ensure accurate validation across various schema dialects.

How it got here

2008–2012 — Architecture modernization and standardization

8 changes.

The project underwent a comprehensive refactoring to support multiple JSON Schema drafts through a new draft-aware validation engine and URI resolution system. This period also involved modernizing the codebase by adopting PSR standards, introducing strict typing, and replacing legacy test suites and validation methods with a cleaner, more robust API.

2013–2016 — Structural refactoring and test expansion

10 changes.

This period focused on restructuring the library's core validation logic by introducing dedicated entity classes for JSON pointers and error handling, alongside pluggable type-checking strategies. Significant effort was dedicated to expanding test coverage across validation constraints, URI resolution, and specific JSON Schema drafts, while also automating release workflows and providing a user demo.

2025 — Draft-07 support and validation fixes

5 changes.

The project introduced full validation support for JSON Schema Draft-07, adding constraints for keywords like if/then/else and contains. Concurrently, it enhanced core utility functions with deep comparison and copy capabilities, and replaced PHP's native URI validation with RFC 3986-compliant validators to ensure stricter standard adherence.

Features

Add JSON Schema Draft-07 validation support

This location introduces the complete set of constraint classes required to validate JSON documents against the JSON Schema Draft-07 specification. The \Draft07Constraint\ class orchestrates the validation by checking all Draft-07 keywords, while the \Factory\ class maps these keywords to their specific implementations. New capabilities include support for \const\, \contains\, \propertyNames\, \if/then/else\, \content\ (encoding and media type), and \dependencies\ (including schema-based dependencies), alongside updated logic for \additionalItems\, \additionalProperties\, and \patternProperties\ to align with the Draft-07 standard.

src/JsonSchema/Constraints/Drafts/Draft06, src/JsonSchema/Constraints/Drafts/Draft07, src/JsonSchema/Constraints/Drafts/Draft2019 · high confidence

Add JSON Schema Validator demo script

A new demo has been added to the \demo/\ directory to help users quickly test the \JsonSchema\\Validator\. This includes a PHP script (\demo.php\) that validates a sample JSON file (\data.json\) against a basic schema (\schema.json\), along with a \README.md\ explaining how to run and customize the example.

demo · high confidence

Introduce pluggable type-checking strategies for objects and arrays

The library now supports different strategies for determining whether a value is an object or an array via the new \TypeCheckInterface\ and its implementations (\LooseTypeCheck\ and \StrictTypeCheck\). \LooseTypeCheck\ treats associative arrays as objects, while \StrictTypeCheck\ only considers actual PHP objects as such. This allows users to control how mixed data structures are validated against JSON Schema definitions.

src/JsonSchema/Constraints/TypeCheck · high confidence

New URI resolution and retrieval components

Introduces the UriResolver and UriRetriever classes in the src/JsonSchema/Uri namespace to handle JSON Schema URI resolution and content retrieval. The UriResolver parses and combines URIs, supporting relative paths, fragments, and local file paths (file://). The UriRetriever manages fetching schema content, including translating json-schema.org URLs to local package resources, validating media types (with exclusions for json-schema.org), caching fetched schemas, and resolving JSON pointers within fragments.

src/JsonSchema/Uri · high confidence

New entity classes for JSON pointer handling and error collection

This change introduces three new classes in the src/JsonSchema/Entity directory: JsonPointer, ErrorBag, and ErrorBagProxy. JsonPointer provides a dedicated object for managing JSON Pointer paths (RFC 6901), including encoding/decoding of special characters and tracking whether values originate from schema defaults. ErrorBag serves as the central repository for validation errors, storing structured error details (property path, message, constraint info) and managing error masks, while ErrorBagProxy is a trait that allows other components to easily integrate with this error collection mechanism. These entities replace or supplement previous inline error handling and path string manipulation, providing a more structured and type-safe approach to validation error reporting and JSON reference resolution.

src/JsonSchema/Entity · high confidence

New release automation and test runner CLI tools

The bin directory now includes several new scripts to support development workflows: \bin/run-test-case\ allows developers to execute individual JSON Schema test suite cases by description; \bin/extract-release-notes.sh\ and \bin/prepare-release.sh\ automate the extraction and formatting of release notes from CHANGELOG.md; and \bin/update-changelog.sh\ enables programmatic insertion of changelog entries under specific categories. These tools streamline the release process and local testing without altering the core validation logic.

bin · high confidence

Removals

Removal of legacy Selenium test suite

The entire Selenium-based test suite for the JSON validator has been removed. This includes the main test suite definition file (SUITEPhpJsJsonSchemaValidator) and all individual test case files covering features such as basic types, arrays, patterns, enums, and validation constraints. These tests previously automated validation of both the JavaScript and PHP implementations of the validator.

seleniumTests · high confidence

Behavioural changes

New exception hierarchy with common interface for easier error handling

The library now provides a unified exception hierarchy under the JsonSchema\\Exception namespace. All custom exceptions (such as ValidationException, JsonDecodingException, and InvalidSchemaException) implement the new ExceptionInterface, allowing consumers to catch all library-specific errors with a single catch block. Additionally, JsonDecodingException now provides descriptive error messages for specific JSON decode failures (e.g., syntax errors, UTF-8 issues) instead of generic codes.

src/JsonSchema/Exception · high confidence

Refactored URI retrieval with new AbstractRetriever and dedicated implementations

The URI retrieval mechanism has been restructured to use an AbstractRetriever base class, with specific implementations for cURL, file\_get\_contents, and predefined arrays. This change introduces a PredefinedArray retriever for loading schemas from a local array, improves HTTP header parsing in the file\_get\_contents retriever to handle redirects correctly, and adds support for file:// URIs. Users relying on custom retrievers should ensure they extend the new AbstractRetriever class.

src/JsonSchema/Uri/Retrievers · high confidence

Refactored validation architecture with draft-aware constraint resolution

The validation engine has been restructured to support multiple JSON Schema drafts (03, 04, 06, 07, 2019-09, and 2020-12) through a new \DraftIdentifiers\ system and a \SchemaStorage\ component that handles URI resolution and reference expansion. The public API now uses \Validator::validate()\ instead of the deprecated \check()\ and \coerce()\ methods, and validation errors are centralized in a new \ConstraintError\ class. This change enables strict dialect-specific validation and improves how relative URIs and internal schema references are resolved.

src/JsonSchema · high confidence

Refactored validation architecture with new constraint classes and strict typing

The validation logic in src/JsonSchema/Constraints has been restructured to use a new base class (BaseConstraint) and a suite of dedicated constraint classes (Collection, Const, Enum, Format, Number, Object, Schema, String, Type) with strict types enabled. This change introduces a new Factory class to manage constraint instantiation and configuration, including a new CHECK\_MODE\_STRICT flag and support for draft-06, draft-07, and draft-2019-09 schemas. Users will see more precise error reporting, better handling of type coercion, and improved performance due to the removal of legacy optimization paths and the use of a deep comparer for equality checks.

src/JsonSchema/Constraints · high confidence

Repository cleanup and modernization for release 6.12.0

This release cleans up the repository structure by removing legacy JavaScript validation files (JsSchema.php, functions.js, interface.js, jquery.js) and their associated CSS, which are no longer part of the PHP library. It introduces a .gitattributes file to exclude development artifacts (tests, docs, CI configs) from the packaged distribution, and adds a .php-cs-fixer.dist.php configuration to enforce PSR-2/Symfony coding standards. The project also adopts the MIT license, updates the README with usage examples for type coercion and default values, and adds a SECURITY.md policy for vulnerability reporting.

(repo-wide) · high confidence

Fixes

Introduce custom deep comparison and deep copy utilities

Added two new utility classes, DeepComparer and DeepCopy, to the JsonSchema\\Tool namespace. DeepComparer provides a static isEqual method that treats mathematically equal numbers (e.g., 1 and 1.0) as identical during validation, addressing issues where integer and float representations of the same value were previously considered distinct. DeepCopy offers a static copyOf method that creates deep copies of input data structures by serializing and deserializing them via JSON, ensuring that sub-schema checks in oneOf validations operate on independent copies rather than shared references.

src/JsonSchema/Tool · high confidence

RFC 3986-compliant URI validation via new validator classes

URI and relative reference validation now uses dedicated \UriValidator\ and \RelativeReferenceValidator\ classes instead of PHP's \filter\_var\, ensuring strict compliance with RFC 3986. This change allows underscores and tildes in hostnames, correctly treats \\#\, \?\, and \?\#\ as valid URI references, and enforces stricter rules for schemes, paths, and special characters like backslashes and spaces.

src/JsonSchema/Tool/Validator · high confidence

Test coverage

Added draft-specific test suites for JSON Schema validation; Added tests for DeepComparer and DeepCopy utilities; Added tests for the exception hierarchy; Added unit tests for URI and relative reference validators; Added unit tests for URI resolution and retrieval; Added unit tests for URI retrievers; Added unit tests for core validation components and RFC 3339 parsing; Expanded test coverage for JSON Schema validation constraints.

Dependencies

Initial composer.json for json-schema library

The project now includes a composer.json manifest defining the library as 'justinrainbow/json-schema'. It requires PHP 7.2 or 8.0 along with the ext-filter and ext-json extensions, and depends on marc-mabe/php-enum version 4.4. Development dependencies include phpunit 8.5, php-cs-fixer 3.3.0, and phpstan 1.12. The package uses PSR-4 autoloading for the JsonSchema namespace, exposes a validate-json binary, and registers a custom repository for the json-schema/json-schema-test-suite.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 66.

Lenses

  • Code Health 85
  • Architecture 100
  • Maturity 58
  • Readiness 75
  • Security 65

Changes since last survey

  • 300 commits — 206 feature/other, 94 fixes

By area

  • (root) — 149 commits
  • src/JsonSchema — 62 commits
  • (repo) — 38 commits
  • tests/Constraints — 22 commits
  • .github/workflows — 15 commits
  • tests/Uri — 6 commits
  • bin/validate-json — 3 commits
  • bin/run-test-case — 1 commit
  • tests/Drafts — 1 commit
  • tests/SchemaStorageTest.php — 1 commit
  • tests/Tool — 1 commit
  • tests/fixtures — 1 commit

Notable commits

  • fix: .gitattributes: Fix .php-cs-fixer.dist.php export-ignore (#861)
  • fix: Fix #827 (#828)
  • fix: Fix CI (php-cs-fixer, HHVM) (#662)
  • fix: Fix PHP 8 deprecated warnings (#619)
  • fix: Fix PHP 8.5 $http_response_header deprecation (#841)
  • fix: Fix README build status badge
  • fix: Fix RFC 3339 date-time validation with high-precision fractional seconds (#940)
  • fix: Fix TypeError in pattern property validation with integer keys (#880)
  • fix: Fix coding style
  • fix: Fix counting
  • fix: Fix idn_to_ascii deprecation warning by using INTL_IDNA_VARIANT_UTS46 (#887)
  • fix: Fix issue when http headers are already present (#843)
  • fix: Fix min/maxProperties check for invalid array input
  • fix: Fix null comparison (#807)
  • fix: Fix objects are non unique despite key order (#819)
  • fix: Fix php cs fixer deprecation warnings
  • fix: Fix pugx badges in README (#742)
  • fix: Fix shell injection in update-changelog workflow for PR titles with backticks (#897)
  • fix: Fix style error
  • fix: Fix support for 32bits PHP (#817)
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

jsonrainbow/json-schema was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 487d2816e962be521cbc805d1110e312634caaef — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.