Skip to content
CAI
Software that uses CAICheck a score

k1tbyte/Wand-Enhancer

47.5

Weak · 23 September 2026

6k

lines of production code

C#

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

WandEnhancer is a .NET-based desktop application designed to patch and modify Electron-based software, specifically targeting Adobe products for activation and update control. It utilizes a custom library, AsarSharp, to securely read, write, and verify ASAR archives while applying structural JavaScript patches via a WPF interface. The system also features a hardened remote web panel with a WebSocket bridge, enabling remote trainer control, game status synchronization, and multi-language support.

How it got here

2024–2025 — Project initialization and core library development

7 changes.

The project was rebranded as WandEnhancer and initialized with a .NET-based patcher and a Vite-based web panel, replacing legacy Node.js scripts. Significant effort focused on developing the AsarSharp library, introducing secure ASAR extraction and creation, integrity verification, and Chromium-style Pickle serialization tools.

2026 — WandEnhancer 2.0 structural overhaul

7 changes.

The project underwent a major rebranding and architectural shift to WandEnhancer, targeting .NET Framework 4.8 with a new WPF interface and a structurally robust JavaScript patching engine. This period focused on hardening the web-panel bridge with strict security controls, implementing multi-language support, and establishing automated release validation and testing pipelines.

Features

AsarSharp introduces secure extraction and new packaging capabilities

The AsarSharp library now includes a new AsarCreator class for building .asar archives from directories, supporting options to unpack specific paths via regex. The AsarExtractor has been rewritten to improve performance by using a single file handle for all reads and, critically, to prevent path traversal (zip-slip) attacks during extraction by validating that all file and link targets remain within the destination directory. Extraction also now correctly handles symlinks on non-Windows platforms and preserves executable permissions.

AsarSharp · high confidence

Integrity verification for ASAR archives

AsarSharp now includes an integrity helper that computes and validates SHA-256 hashes for ASAR files. The new IntegrityHelper class supports both standard file verification and streaming hashing, allowing users to verify archive integrity by checking file and block-level hashes against expected values.

AsarSharp/Integrity · high confidence

Introduce PickleTools for Chromium-style Pickle serialization

Added the PickleTools library, including the Pickle and PickleIterator classes, to support reading and writing Chromium-style Pickle data structures. The implementation handles payload buffer allocation with a 4096-byte initial unit, manages header and payload sizing, and provides methods for writing and reading integers, unsigned 32-bit values, and UTF-8 strings with proper alignment.

AsarSharp/PickleTools · high confidence

Introduce multi-language support and accent color customization in the web panel

The web panel now supports six languages (English, Russian, German, French, Spanish, and Chinese) with automatic browser locale detection and a manual selector in the Settings drawer. Users can also customize the interface accent color via a picker in Settings, with the choice persisted locally. These features are implemented using Lingui for internationalization and a dedicated appearance storage module, integrated into the main app entry point and the Settings UI.

web-panel/src · high confidence

Introduce new AsarFileSystem implementation for reading and writing ASAR archives

The AsarSharp library now includes a new AsarFileSystem namespace containing the core logic for handling ASAR archives. This adds a new Disk class for low-level I/O operations (reading headers, copying files, and atomic writes), a Filesystem class for managing the archive's internal tree structure and node lookups, a FileSystemCrawler for scanning directories and handling symlinks, and a FilesystemEntry model representing archive metadata. This new implementation provides the underlying mechanics for the library's archive manipulation capabilities.

AsarSharp/AsarFileSystem · high confidence

New custom renderer script support and IPC debugging tool

Users can now place custom JavaScript files in the \web-panel/scripts/custom\ directory to inject logic into the Wand renderer, with a provided example demonstrating safe, repeatable script loading via the \WandEnhancer\ global API. Additionally, a new default \ipc-logger.js\ script has been added to intercept and log Electron IPC \invoke\ and \send\ calls in the browser console, aiding in debugging remote panel communication. A \verify-dist.mjs\ script has also been introduced to enforce build invariants, ensuring production bundles parse correctly and do not contain development-only artifacts.

web-panel/scripts · high confidence

New installed-apps-sync bridge and remote trainer control scripts

The bridge now includes a new renderer-side script module that synchronizes installed game data, catalog information, and game/trainer status to the main process via IPC. This module also introduces remote command handling, allowing the bridge to trigger trainer launches and stops remotely. Additionally, a new script manages the remote pairing UI by injecting styles and rendering QR codes for the connection flow.

web-panel/bridge/scripts · high confidence

New release automation and validation scripts

Added PowerShell scripts to support the 2.0.0.0 release process: \validate-release-metadata.ps1\ ensures the assembly version in AssemblyInfo.cs matches the latest CHANGELOG.md entry and optional release tag; \get-changelog-section.ps1\ extracts changelog content for a specific version (handling pre-release tags); and \test-desktop.ps1\ / \test-patch-locators.ps1\ provide regression tests for desktop patching, update notification logic, and JavaScript patch locators.

scripts · high confidence

Repository initialization with rebranded project structure and build tooling

The repository is initialized with the project rebranded to WandEnhancer, including updated solution files, build scripts (build.cmd/ps1/sh), and documentation (README, CONTRIBUTING, AGENTS). The legacy Node.js unlocker scripts (memoryScanner.js, unlocker.js) are removed, and the project now relies on a .NET-based patcher with a bundled Remote Web Panel. Configuration files (.gitattributes, .gitignore) are added to manage line endings and exclude build artifacts, logs, and local settings.

(repo-wide) · high confidence

Behavioural changes

Automated release metadata validation on commit

A new pre-commit hook has been added to automatically validate release metadata before changes are committed. This hook executes a PowerShell script located in the repository's scripts directory, ensuring that release-related metadata is consistent and correct prior to saving code changes.

.githooks · high confidence

Bridge runtime and protocol hardened with strict validation and security controls

The web-panel/bridge module has been rewritten to enforce strict protocol compliance and security boundaries. The new bridge-state and protocol-router components validate all incoming WebSocket messages, requiring a compatible handshake before processing commands and rejecting requests from mismatched trainers or unknown cheat targets. Security is strengthened by rejecting cross-origin WebSocket connections, limiting WebSocket frame sizes to 1MB, and ignoring untrusted HTTP Host headers. Additionally, the bridge now normalizes trainer values (converting numeric toggles to booleans), tracks game status and installed apps with signature-based deduplication, and exposes a robust health endpoint for monitoring.

web-panel/bridge · high confidence

Improved path handling, extraction security, and file copy diagnostics

The library now uses a faster, literal-prefix algorithm for computing relative paths, falling back to full normalization only when necessary for security checks or complex path structures. Extraction safety is strengthened by validating that file candidates remain inside the root directory after full path normalization, preventing zip-slip attacks. Additionally, file copy operations now clear read-only attributes to avoid permission errors and provide detailed diagnostic messages when access is denied, helping users identify causes like antivirus interference or pending file deletions.

AsarSharp/Utils · high confidence

WandEnhancer rebrands and introduces structural JavaScript patching with a new .NET 4.8 WPF UI

The application has been rebranded to WandEnhancer and now targets .NET Framework 4.8, featuring a WPF interface with localized resources and custom visibility converters. The core patching engine has been overhauled to locate JavaScript edits structurally by anchoring on stable API names and IPC identifiers rather than fragile signatures, ensuring patches remain valid across builds. This new engine supports multiple patch types, including Pro activation, update disabling, and a remote web panel preview, while also introducing a static on-disk patch strategy that manages Electron ASAR integrity fuses and handles backup/rollback logic.

WandEnhancer · high confidence

Dependencies

Initialize .NET and web-panel dependency manifests

The project now includes explicit dependency definitions for its core components. The .NET side (WandEnhancer and AsarSharp) targets .NET Framework 4.8 and relies on Newtonsoft.Json (13.0.3), ILRepack (2.0.41), and several System.\* packages. The web-panel is set up with pnpm, using Vite (7.3.6), Preact, Tailwind CSS, and Lingui for internationalization, while the legacy root package.json with the 'asar' dependency has been removed.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 51 → 47 (-3.4)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 59 → 48 (-10.4)
  • Architecture 96 → 97 (+0.8)
  • Maturity 54 → 62 (+7.1)
  • Readiness 43 → 35 (-8.1)
  • Security 54 → 70 (+15.7)

Resolved (31)

  • Build did not complete in the analyzer
  • Coverage not included — suite not readable by the collector
  • Duplicated block (10 lines × 2) (AsarSharp/Utils/Extensions.cs)
  • EmptyCatchBlock (WandEnhancer/Utils/Common.cs)
  • EmptyCatchBlock (WandEnhancer/Utils/Extensions.cs)
  • Enhancer.ApplyJsPatch (cognitive 16) (WandEnhancer/Core/Enhancer.cs)
  • Enhancer.PatchAsar (cognitive 18) (WandEnhancer/Core/Enhancer.cs)
  • High CVE: [GHSA redacted] (web-panel/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (web-panel/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (web-panel/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (web-panel/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (web-panel/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (web-panel/pnpm-lock.yaml)
  • High vulnerability: [GHSA redacted] (web-panel/pnpm-lock.yaml)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 11 more

New (35)

  • AsarContentPatcher.Patch (cognitive 17) (WandEnhancer/Core/Patching/Content/AsarContentPatcher.cs)
  • Build failed
  • Coverage not measured — .NET and JavaScript/TypeScript suite
  • Documentation: no contributor guidance (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • DotNetImage.BodyCalls (cognitive 17) (WandEnhancer/Core/Patching/Strategies/Static/DotNetImage.cs)
  • Duplicated block (11 lines × 2) (AsarSharp/Utils/Extensions.cs)
  • Filesystem.SearchNodeFromDirectory (cognitive 28) (AsarSharp/AsarFileSystem/FileSystem.cs)
  • Filesystem.SearchNodeFromDirectory (cyclomatic 17) (AsarSharp/AsarFileSystem/FileSystem.cs)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 15 more

Changes since last survey

  • 23 commits — 17 feature/other, 6 fixes

By area

  • WandEnhancer/Core — 6 commits
  • (root) — 5 commits
  • web-panel/src — 3 commits
  • AsarSharp/AsarFileSystem — 2 commits
  • web-panel/bridge — 2 commits
  • (repo) — 1 commit
  • AsarSharp/Utils — 1 commit
  • WandEnhancer/Locale — 1 commit
  • WandEnhancer/Patches — 1 commit
  • tools/asar-fuses-bypass — 1 commit

Notable commits

  • fix: fix(asar): correct archive tree lookups and fail loudly on unreadable input
  • fix: fix(launcher): clear the fuse in every process Wand spawns
  • fix: fix(launcher): retry the fuse write until the process is ready
  • fix: fix(patch): roll back the installation when patching fails
  • fix: fix(patch): stop the deployed launcher inheriting a read-only flag
  • fix: fix(renderer-scripts): await the bridge bind and retry it on poll
  • change: Merge pull request #279 from k1tbyte/feature/rc_v_2.0.0.0
  • change: chore(build): enforce lint, type-check and dist invariants in build and CI
  • change: chore(release): 2.1.0.0
  • change: chore(release): prepare 2.0.0.0 and support pre-release tags
  • change: docs(changelog): note the failed-patch rollback
  • change: feat(launcher): clear the ASAR fuse from a debugger instead of a proxy DLL
  • change: feat(launcher): log the applied patches and keep the previous log
  • change: feat(launcher): show the window when Wand fails to start
  • change: feat(launcher): write startup diagnostics to launcher.log
  • change: feat(panel): add IconButton primitive and fix input, reconnect and a11y gaps
  • change: feat(patch): report what is blocking a denied copy
  • change: feat(patch-engine): locate patches structurally instead of by signature
  • change: feat(patching): static on-disk patch method with strategy selector
  • change: feat: prepare 2.0.0.0 with opt-in update notifications and pre-release fixes
  • …and 3 more

Architecture

  • Unchanged — 1 containers · 0 contexts · 0 edges

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

k1tbyte/Wand-Enhancer was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit c6ae7a3ad49388ab9ad0ef6e06d235b59cc573cb — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.