Skip to content
CAI
Software that uses CAICheck a score

koajs/koa

58.0

Adequate · 25 September 2026

1.8k

lines of production code

JavaScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the Koa v3 web framework, a modernized Node.js application layer that replaces legacy generator-based middleware with native ES6 classes and async/await patterns. It provides core HTTP request and response handling, including context management, header manipulation, and stream support, while enforcing strict compatibility with both CommonJS and ES modules. The codebase focuses on a clean, extensible API surface for building web servers, supported by comprehensive test suites and modern dependency management.

How it got here

2013 — Koa v3 core rewrite and modernization

6 changes.

This period focused on rewriting the Koa core library to use modern ES6 classes and native Node.js APIs, replacing the legacy generator-based architecture. The update involved removing outdated examples, benchmarks, and test suites while modernizing dependencies and establishing a new project structure with updated documentation and tooling.

2021–2024 — Comprehensive test coverage expansion

6 changes.

This period focused on significantly expanding the test suite for the Koa framework, adding comprehensive coverage for core components including the application, context, request, and response objects. New test helpers were introduced to support custom stream testing and mock context creation, while existing tests were augmented to verify ESM/CJS interoperability and async local storage features.

Features

Initial project scaffolding and documentation

This change establishes the foundational structure of the project by adding essential configuration and documentation files. It includes a Codecov configuration for partial coverage, an EditorConfig for consistent coding styles, a .mailmap for author normalization, and a comprehensive AUTHORS file listing all contributors. Additionally, it introduces a CODE\_OF\_CONDUCT.md to define community standards, a detailed History.md documenting version changes from 3.0.0-alpha.3 back to early releases, and a rewritten Readme.md that updates the project description, installation instructions, and code examples to reflect modern Node.js and Koa v3 practices.

(repo-wide) · high confidence

Removals

Removal of legacy Koa example files

The repository has removed several example files from the \examples\ directory, including \compose.js\, \negotiation.js\, \route.js\, \simple.js\, and \streams.js\. These files, which demonstrated older Koa patterns such as generator-based middleware and manual routing, are no longer present in the codebase.

examples · high confidence

Removal of legacy benchmark suite

The legacy benchmarking infrastructure has been removed, including the Makefile, the middleware benchmark script, and the shell-based runner. This eliminates the ability to run performance tests using the old generator-based middleware pattern and the 'wrk' tool with the 'harmony-generators' flag.

benchmarks · high confidence

Behavioural changes

Koa v3 core library rewritten with modern JavaScript and native APIs

The \lib\ directory has been completely rewritten for Koa v3, replacing the legacy prototype-based structure with modern ES6 classes and native Node.js APIs. The \Application\ class now extends \EventEmitter\ and accepts a configuration object in its constructor, while \Context\ is simplified to a prototype object with delegation. Request and response handling now uses native \URLSearchParams\ for query strings, \http-errors\ for error handling, and \mime-types\ for content types. New utility modules like \is-stream.js\ and \only.js\ have been added, while legacy files like \lib/status.js\ have been removed. This change introduces breaking changes in the API surface, including the removal of \app.use()\ chaining, the shift to constructor options, and the deprecation of legacy error handling patterns.

lib · high confidence

Test coverage

Add test helpers for custom streams and context creation; Added application-level test suite; Added comprehensive test coverage for response object methods; Added test coverage for Koa context methods; Added tests for search-params and ESM/CJS interoperability; Added unit tests for request context properties and methods; Removal of legacy test suites for application and context.

Dependencies

Introduce package-lock.json and modernize Koa 3.2.1 dependencies

This release adds a package-lock.json file to ensure deterministic dependency resolution and updates the project to version 3.2.1. The dependency tree has been significantly modernized: legacy packages like \co\, \debug\, \mime\, \qs\, \negotiator\, and \bytes\ have been removed in favor of specific, maintained utilities such as \accepts\, \content-disposition\, \content-type\, \cookies\, \destroy\, \encodeurl\, \escape-html\, \http-assert\, \http-errors\, \koa-compose\, \mime-types\, \on-finished\, \parseurl\, \statuses\, \type-is\, and \vary\. Dev dependencies have also been updated, replacing older testing and linting tools with \c8\, \gen-esm-wrapper\, \standard\, and \supertest\. Additionally, the minimum supported Node.js version is now 18, and the package exports are configured to support both CommonJS and ES modules.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 39 → 58 (+18.5)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 44 → 48 (+3.7)
  • Architecture 100 (new)
  • Maturity 57 → 60 (+3.3)
  • Readiness 28 → 65 (+36.7)
  • Security 61 → 77 (+16.2)

Resolved (24)

  • Dimension evaluation failed
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Hotspot: lib/response.js (lib/response.js)
  • LLM evaluation failed
  • Low CVE: [GHSA redacted] (package-lock.json)
  • Medium CVE: [GHSA redacted] (package-lock.json)
  • Medium CVE: [GHSA redacted] (package-lock.json)
  • Medium CVE: [GHSA redacted] (package-lock.json)
  • No automated tests
  • No exposed public API
  • No tests found
  • Test reliability not included
  • …and 4 more

New (25)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no installation or build instructions (docs/api/index.md)
  • Documentation: no usage examples (README.md)
  • Documentation: no usage examples (docs/api/index.md)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: [GHSA redacted] (package-lock.json)
  • No assertions (empty test): should not crash when stream errors and no error listener exists (tests/application/respond.test.js)
  • No assertions: should not throw (tests/response/status.test.js)
  • No assertions: should not throw (tests/response/status.test.js)
  • No assertions: should not throw unhandled errors when replacing failing stream (tests/response/body.test.js)
  • No assertions: should not throw when header.host is invalid (tests/request/whatwg-url.test.js)
  • No assertions: should not throw when host is void (tests/request/whatwg-url.test.js)
  • Outdated (npm): content-disposition
  • Outdated (npm): content-type
  • Outdated (npm): cookies
  • Outdated (npm): type-is
  • …and 5 more

Changes since last survey

  • 6 commits — 4 feature/other, 2 fixes

By area

  • (root) — 1 commit
  • tests/context — 1 commit
  • tests/request — 1 commit
  • tests/response — 1 commit
  • docs/api — 1 commit
  • lib/application.js — 1 commit

Notable commits

  • fix: fix(response): keep the Blob content type instead of forcing octet-stream (#1987)
  • fix: fix: parse absolute-form request targets in request.URL (#1999)
  • change: ci: bump node versions to 22-26 (#1972)
  • change: docs: point request.hostname URL link at current Node.js docs (#1994)
  • change: feat: re-export http-errors utilities (#1991)
  • change: patch: make ctx.assert errors instanceof HttpError (#1998)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

koajs/koa was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 824c1cf8de9a91a2941973b25dc8a3d3029b9e4f — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-dd72cc24c749.