Skip to content
CAI
Software that uses CAICheck a score

lizhipay/acg-faka

33.6

Weak · 19 September 2026

113.8k

lines of production code

JavaScript

with PHP

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is a PHP-based virtual card and digital goods e-commerce platform that manages product inventory, user accounts, and payment processing. It provides a comprehensive admin interface for managing orders, merchants, and security, alongside a user-facing storefront for browsing products and handling transactions. The application supports multi-tenant merchant operations, agent referral programs, and automated digital delivery via QR code decoding.

How it got here

2021 — Initial framework and UI implementation

39 changes.

This period established the core application architecture by implementing the kernel, dependency injection, Eloquent models, and service-layer interfaces. It simultaneously delivered the complete admin and user-facing controller logic, including authentication, commerce, and agent features, alongside a comprehensive Material Design and glassmorphism UI overhaul.

2025–2026 — comprehensive admin and user interface overhaul

15 changes.

This period focused on implementing a complete suite of JavaScript controllers for both the admin panel and user-facing interfaces, covering core e-commerce, financial, and security workflows. The work included establishing a robust backend service layer, introducing Docker-based deployment with automated HTTPS setup, and significantly enhancing the admin dashboard with safer data handling and improved usability features.

Features

Add acg.js utility library and Bootstrap Table assets

The static assets directory now includes a new acg.js utility script that provides cross-browser helper functions for internationalization, caching, script loading with version-based cache busting, and AJAX requests. Additionally, the Bootstrap Table library (v1.19.1) has been added, including its CSS styles, the main JavaScript implementation, and a Chinese language localization file, enabling enhanced data table rendering and interaction capabilities.

assets/static · high confidence

Add default 'Cartoon' theme configuration and settings

Introduces a new default theme named 'Cartoon' (version 1.0.1) for the user-facing interface. The theme configuration defines its metadata, specifies Smarty as the rendering engine, and maps logical pages (such as login, registration, order management, and member centers) to specific HTML template files. Additionally, it provides a settings file allowing administrators to configure basic options like style selection, cache expiration, and an optional ICP filing number for display in the store footer.

app/View/User/Theme/Cartoon · high confidence

Added QR code detection and decoding library

The \khanamiryan/qrcode-detector-decoder\ library has been added to the vendor directory, introducing PHP classes for detecting and decoding QR codes. This includes core components such as \Binarizer\ and \BinaryBitmap\ for image processing, \BitMatrix\ and \BitArray\ for bit-level data handling, and \DefaultGridSampler\ for perspective correction. The update enables the application to parse QR code images and extract the encoded text or data.

(repo-wide) · high confidence

Added default and universal themes for the authorization tree component

The authorization tree module now includes two built-in visual themes: a default theme (auth-skin-default) and a universal theme (auth-skin-universal). These CSS files define the styling for the permission tree interface, including layout, colors, and indentation for nodes and status indicators. A template file is also provided to guide the creation of custom themes, ensuring consistent styling rules for future extensions.

assets/static/layui/css/modules/laydate, assets/static/modules/src · high confidence

Initial configuration and WAF rule sets added

The application now includes its core configuration files, setting the app version to 3.7.7 and defining default MySQL database connection details (host 127.0.0.1, database demo). Additionally, a Web Application Firewall (WAF) is introduced with rule sets for URL, POST, GET, Cookie, and User-Agent inputs, blocking common attack vectors such as SQL injection, XSS, directory traversal, and PHP backdoor usage.

config · high confidence

Initial release of the application's data models

This update introduces the complete set of Eloquent models for the application's core domain, including Bill, Business, Card, Cash, Category, Commodity, Config, Coupon, Manage, Order, Pay, PriceTemplate, Shared, Ticket, User, and their associated entities. These models define the database schema, relationships, and business logic for features such as billing, order management, user groups, and payment processing.

app/Model · high confidence

Introduce service-layer interfaces and revocable admin session management

This change adds a comprehensive set of service interfaces in app/Service to define the application's core capabilities, including application store operations, currency and exchange rate management, payment and order processing, plugin administration, messaging, and ticketing. It also introduces ManageSessionManager, which implements a revocable session system for administrators using JWTs and database-backed session records, allowing sessions to be individually or globally revoked.

app/Service · high confidence

Introduces new service implementations for core platform features

The app/Service/Bind directory now contains the concrete implementations for the platform's core services, replacing previous or missing logic. This includes AppService for application store interactions, CashService for user settlement, CurrencyService for currency configuration and conversion, DictService for secure remote table lookups, EmailService for SMTP-based messaging, ImageService for thumbnail generation, ManageSSOService for admin login with 2FA support, McpService for developer plugin management, MessageService for system notifications, and OrderService for order processing. These changes provide the functional backbone for the application's service layer.

app/Service/Bind · high confidence

New 'Cartoon' user theme adds comprehensive dashboard, agent, and business management views

The application introduces a new 'Cartoon' user interface theme, providing a complete set of new view templates for the user area. This includes a Dashboard with asset and business statistics, an Agent section for referral links and commission tracking, and extensive Business management tools for shop setup, product/category/coupon management, and card key handling. It also adds dedicated views for user security (password, email, personal info), financial operations (coin cash-out and records), and general user activity (orders, bills, messages).

app/View/User/Theme/Cartoon/User · high confidence

New 'Cartoon' user theme layout components

The 'Cartoon' user theme now includes its own layout structure, introducing new common view files for the page header, footer, main navigation, and security settings navigation. These components define the visual shell and menu hierarchy for the user dashboard, including support for light/dark mode toggling, responsive navigation, and specific sub-menus for shop management, finance, and promotion features.

app/View/User/Theme/Cartoon/Common · high confidence

New 'Cartoon' user theme with immersive visuals and modular layout

The 'Cartoon' user theme has been introduced, featuring a modular view structure (Header, Footer, Index, Item, Query, Closed) that replaces previous styling. The theme includes a full-canvas starfield animation for the site-closed state, a responsive navigation bar with language switching and user account management, and dedicated pages for browsing categories, purchasing items with SKU selection, and querying orders. It integrates standard UI libraries (Bootstrap, FontAwesome) and custom JavaScript controllers to handle dynamic interactions like category switching and order lookups.

app/View/User/Theme/Cartoon/Index · high confidence

New CSP reporting and installation wizard controllers

Added app/Controller/Csp.php to handle Content Security Policy violation reports with rate limiting and silent dropping to prevent dashboard poisoning and whitelist manipulation. Added app/Controller/Install.php to provide a multi-step installation wizard that checks environment prerequisites (PHP 8.0+, required extensions, writable directories), tests database connectivity with specific error classification, and supports pre-filled configuration for Docker environments.

app/Controller · high confidence

New Cartoon theme authentication pages

The Cartoon user theme now includes a complete set of authentication views (Login, Register, Email Forget, Phone Forget) along with shared Header and Footer templates. These pages provide a consistent, branded interface for user account management, supporting configurable login credentials, registration via email or phone with optional verification codes, and password recovery flows.

app/View/User/Theme/Cartoon/Authentication · high confidence

New Docker deployment support with integrated HTTPS and database management

This change introduces a complete Docker deployment solution for acg-faka, allowing users to run the application in a single container with built-in MariaDB and Redis, or via Docker Compose with external services. Key features include an automated installation wizard that pre-fills database credentials, secure random password generation for the database stored in a volume, and a suite of shell scripts (acg-ssl.sh, acg-ssl-import.sh, acg-ssl-renew.sh) to easily configure HTTPS using Let's Encrypt or custom certificates. The entrypoint script handles data volume seeding, session backend configuration (Redis or file-based), and thread manager integration, while nginx and php-fpm configurations ensure security by restricting access to sensitive files and enforcing a single entry point.

docker · high confidence

New Material Design admin interface and user-facing helpers

The admin panel now uses a new Material Design layout, introducing dedicated view components for the header (with theme/layout detection and full navigation menu), footer (with consolidated asset loading), toolbar (with page-title tabs), and stat cards. A new PHP helper provides admin-specific variables and hook integrations. Additionally, new helpers and templates for the user-facing side include a widget renderer for dynamic form inputs, a header navigation builder, and a submit page for automatic order requests.

app/View/Admin · high confidence

New admin configuration controllers for login, security, and settings

The admin panel now includes dedicated JavaScript controllers for managing core configuration areas. The login controller adds a 3D card effect, Caps Lock detection, theme switching, and support for TOTP-based two-factor authentication during login. The security controller introduces a confirmation dialog when clearing the admin entrance path and handles Content Security Policy (CSP) clearing. The configuration index controller enables Markdown-based notice editing, logo/background uploads, and dynamic theme setting modals. The Google 2FA controller provides a dedicated interface for binding and unbinding TOTP secrets via QR codes. The language controller adds a registry-based system for managing translation statuses (pending, machine-translated, human-confirmed) and allows enabling/disabling languages. The mail controller adds a test email sending feature with proper form state management. The other controller introduces currency presets (CNY, USD, EUR, etc.) and a substation display list for managing merchant visibility on the main site. The plugin controller adds a plugin update system with version tracking and a robust HTML sanitizer for plugin display content to prevent XSS.

assets/admin/controller/config · high confidence

New admin configuration pages for email, security, and site settings

The admin panel now includes dedicated configuration views for Email (SMTP server, encryption, and test sending), Security (request logging, admin entrance protection, IP detection, and link filtering), and Site Settings (branding, theme selection for PC/mobile, and background images). Additional management interfaces have been added for Plugins (start/stop/restart/update), Payment methods, Payment plugins, and Site Languages (add/rebuild/retranslate/scan/clean). These pages provide the UI for managing core system behaviors and integrations.

app/View/Admin/Config · high confidence

New admin controllers for user financial and membership management

Added new JavaScript controllers for the admin panel to manage user bills, business levels, cash withdrawals, user groups, and recharge orders. These controllers provide UI logic for listing, filtering, and performing actions on these resources, including handling modal dialogs, table rendering, and API interactions for tasks like marking withdrawals as paid, adjusting user balances, and exporting recharge data.

assets/admin/controller/user · high confidence

New admin dashboard components for version management and user profile

The admin interface now includes dedicated JavaScript modules to enhance the dashboard experience. A new global controller (\assets/admin/controller/global.js\) introduces a version management system that checks for updates, displays a changelog popup with beta/stable indicators, and allows users to update the application directly from the UI. It also adds a user profile section in the header that displays account level (Professional/Enterprise), developer status, and balance, along with a secure password change modal that includes a warning about account lockout after failed attempts and an option to force logout on other devices. Additionally, a new dictionary utility (\assets/admin/js/\_admin.js\) provides standardized, localized status badges for common administrative entities such as orders, tickets, payments, and user statuses, ensuring consistent visual representation across the admin panel.

assets/admin/js · high confidence

New admin dashboard controller with robust data formatting and retry logic

Added a new JavaScript controller for the admin dashboard that handles rendering of earnings, trends, and todo items. The implementation introduces safer number formatting by converting monetary values to cents for integer arithmetic to avoid floating-point errors, and includes a retry mechanism for failed network requests with user-visible feedback. It also features locale-aware date and number formatting, and restricts URL generation to safe HTTP/HTTPS schemes.

assets/admin/controller/dashboard · high confidence

The admin dashboard now features a redesigned layout with distinct sections for announcements, user account info, earnings (today, yesterday, month), pending tasks, and interactive trend charts. Users can view profit, turnover, order, and recharge metrics via segmented time ranges (7/30 days) and detailed business data panels showing KPIs like average order value and profit composition.

app/View/Admin/Dashboard · high confidence

New admin login page with theme toggle and 2FA support

The admin authentication area now includes a dedicated login view (Login.html) that provides a modern interface for administrator access. Users can toggle between light and dark themes using the header button, which respects system preferences by default. The form collects username and password, and conditionally displays a CAPTCHA field when enabled in configuration. It also supports Google Authenticator (2FA) via a dedicated input field and includes a 'remember me' option for persistent sessions.

app/View/Admin/Authentication · high confidence

New admin pages for user management, billing, and support

Added new view templates for the admin panel to manage users, bills, business levels, cash settlements, user groups, messages, orders, and support tickets. These pages provide tables and action buttons for listing and managing these resources, including mobile-responsive styles and integration with specific JavaScript controllers.

app/View/Admin/User · high confidence

New admin panel controllers for authentication, dashboard, and core management features

This change introduces a comprehensive set of new controllers in the admin area, establishing the backend management interface. Key additions include Authentication (login/logout), Dashboard, and Manage (user settings, admin management, and automated security cleanup for detected malware/XSS). It also adds controllers for core business operations: Commodity (product management with stats), Order, Recharge, Card, Coupon, Pay (payment settings/plugins), and Category. Configuration is handled by Config (site, SMS, email, security, and IP modes), while Plugin manages the app store, developer center, and plugin documentation. Additional controllers cover User management (members, groups, bills), Ticket support, Message management, Log viewing, File management, Language translation, and a new Mcp controller exposing a JSON-RPC API for developer tools.

app/Controller/Admin · high confidence

New admin payment controller with safe deletion and multi-merchant profiles

Added new admin controllers for payment management (api.js and plugin.js) that introduce a safe deletion workflow—previewing impact on orders and recharge before allowing permanent deletion or archival—and support for multiple merchant configuration profiles per plugin, allowing admins to switch, rename, or delete non-default profiles while viewing which payment interfaces use each profile. The controllers also include plugin update management and strict URL sanitization to prevent unsafe protocol injection.

assets/admin/controller/pay · high confidence

New admin store views for developer MCP integration and store authentication UI

Added two new admin store view templates: Developer.html introduces a card-based interface for managing MCP (Model Context Protocol) AI access, allowing developers to generate and manage access keys for AI tools like Claude and Cursor, with features for toggling the service, viewing connection details, and handling security warnings for HTTP connections. Store.html adds a new authentication panel UI for the admin store, featuring a modernized login/register form with floating labels, theme-aware styling, and a popup layout optimized for desktop views.

app/View/Admin/Store · high confidence

New admin trade management views for cards, categories, commodities, coupons, and orders

Added new admin interface pages for managing trade-related entities. The Card view allows uploading, locking, unlocking, selling, and exporting card secrets. The Category view supports creating, enabling, disabling, and removing product categories. The Commodity view provides an overview dashboard and a list for adding, listing, delisting, and removing products. The Coupon view enables generating, locking, unlocking, and exporting coupons. The Order view displays order statistics and a list with options to clean up useless orders and export filtered data, including mobile-specific styling for order details.

app/View/Admin/Trade · high confidence

New admin views for price templates and store management

Added new UI pages for managing price templates and stores in the admin panel. The Price Template page allows users to define pricing rules (based on cost or current price, with member-level adjustments) and apply them in bulk to products. The Store page provides a table interface for managing stores, including a button to view inbound task counts and support for mobile-responsive layouts for sync and import logs.

app/View/Admin/Shared · high confidence

New base controller hierarchy for API and View rendering

The application introduces a new set of abstract base controllers in app/Controller/Base to standardize how API responses and views are rendered. For API endpoints, Manage, Shared, and User controllers now provide a consistent json() helper for structured responses, with the User API controller adding business-level validation. For web views, the Manage and User base controllers now handle rendering logic, including injecting application configuration, session data, and theme settings into templates. The User view controller specifically supports dynamic theming (mobile vs desktop) and allows plugins to override template paths, while Manage view controllers handle admin-specific rendering. This refactoring centralizes common rendering concerns and provides a cleaner inheritance model for new controllers.

app/Controller/Base · high confidence

New business management interface for merchants

This update introduces a new set of JavaScript controllers for the merchant-facing business management area, enabling store owners to manage their shop operations. The new code adds functionality for handling business subscriptions and configuration, managing product categories and commodities (including pricing, delivery settings, and descriptions), uploading and managing card keys for digital goods, creating and distributing coupons, and viewing order details with manual delivery capabilities.

assets/user/controller/business · high confidence

New developer store and installation progress UI controllers

Added new JavaScript controllers for the admin store interface: \developer.js\ introduces a developer plugin management view with Markdown-rendered audit rejection reasons and strict HTML sanitization, while \home.js\ implements a new installation/update progress overlay featuring a glassmorphism design, real-time elapsed timers, and theme-aware styling to replace the previous fake percentage progress bars.

assets/admin/controller/store · high confidence

New domain entities for payments, queries, and risk control

Added new entity classes to the application domain: PayEntity for payment details, a suite of Query entities (Get, Save, Delete) for structured data retrieval and manipulation, and RiskContext for managing security decisions. The Query entities introduce specific behaviors such as pagination limits, column filtering, and conflict detection in query parameters, while RiskContext provides a mechanism for escalating security actions like pass, limit, review, or deny based on voting from multiple subscribers.

app/Entity · high confidence

The application now includes dedicated view templates for several key user-facing flows. A new 404 error page (app/View/404.html) provides a polished, theme-aware experience with animated progress indicators and fallback actions. An installation wizard (app/View/Install.html) has been added to guide users through the setup process, featuring a step-by-step interface, theme switching, and language selection. Additionally, new views for legal terms (app/View/LegalTerms.html) and a static rewrite detection page (app/View/Rewrite.html) have been introduced to handle compliance and initial environment checks.

app/View · high confidence

New kernel framework with dependency injection, request handling, and database integration

The kernel now includes a foundational framework featuring a custom dependency injection container (Kernel\\Container\\Di) that supports property injection via the \#\[Inject\] attribute and interface binding via \#\[Bind\]. It introduces a new request handling layer (Kernel\\Context\\Request) that parses HTTP inputs, applies XSS filtering, and exposes methods for GET, POST, JSON, and header data. The kernel also integrates with Laravel's Eloquent ORM via a Capsule Manager for database access, includes a file-based cache system (Kernel\\Cache\\Cache), and provides a CLI tool (Kernel\\Console\\RequestLogDecrypt) for decrypting AES-256-GCM encrypted request logs. Additionally, it defines several new exception classes and utility traits like Singleton and Make.

kernel · high confidence

New security and utility classes added to app/Util

A suite of new utility classes has been introduced to the application core. AdminEntrance provides a configurable, secret-path gatekeeper for the admin panel, returning 404 to unauthenticated visitors. CallbackIpWhitelist enforces IP allowlists on webhook callbacks. Csp implements Content Security Policy enforcement with nonce injection and a safe allowlist mechanism. Client handles robust client IP resolution from proxy headers, migrating trusted proxy configuration from a volatile file to the persistent config table. Currency centralizes site-wide currency display and payment gateway conversion. Captcha generates high-quality, anti-automation verification codes. CommodityPurge safely cascades the deletion of products and their associated orders and tickets. Other additions include Aes for encryption, Context for request-scoped state, File and FileCache for storage operations, Helper for theme and plugin detection, and Http for external requests.

app/Util · high confidence

New shared API controllers for authentication, commodity, and plugin endpoints

Added new controller classes in app/Controller/Shared to expose shared API functionality. Authentication.php provides a connect endpoint returning shop name and user balance. Commodity.php implements items and item endpoints with strict access controls: it enforces the api\_status flag on all code-based lookups to prevent unauthorized access to non-opened products, sanitizes output via SharedPayload to exclude internal fields (like factory\_price and shared\_id) from downstream responses, and implements a sharedStockSnapshot method that takes the maximum of cached and database stock values to avoid false out-of-stock reports. Plugin.php adds a face endpoint that returns an AES-encrypted context lock token. All controllers use Waf and SharedValidation interceptors for security.

app/Controller/Shared · high confidence

New shared admin controllers for price templates and store management

Added new shared JavaScript controllers for the admin interface: \priceTemplate.js\ introduces a UI for configuring pricing rules (base price, markup types, rounding, and member-level adjustments), and \store.js\ provides core logic for store management including import task handling and popup height fitting. These files establish the client-side logic for these specific administrative features.

assets/admin/controller/shared · high confidence

New user-facing API controllers for agent, authentication, billing, and commerce

This change introduces a suite of new API controllers in the user-facing layer (app/Controller/User/Api) that power core platform capabilities. AgentMember enables agent-level member listing and balance transfers with strict column filtering to prevent side-channel data leakage. Authentication adds a configurable registration flow supporting email or phone verification, risk-based manual review holds, and SSO session issuance. Bill, Cash, and CommodityOrder provide financial tracking, withdrawal submission with serializable transaction isolation and rate limiting, and order listing with merchant-permission scoping to hide sensitive fields from sub-stations. Card, Category, Commodity, and Coupon allow merchants to manage inventory, organize products, import card secrets, and generate discount vouchers with input sanitization and validation. Business handles merchant level purchases and shop configuration (subdomains/top domains). Dict supplies safe category/commodity lists for UI components. Index serves public-facing category and commodity data. All controllers enforce WAF and session/business interceptors and use the shared Query service for data access.

app/Controller/User/Api · high confidence

New user-facing JavaScript controllers for authentication, billing, cashing, and support

This change introduces a suite of new client-side controllers in the user area, providing the interactive logic for previously missing or static pages. Users can now perform full authentication flows (login, registration, password reset via email/phone with captcha), manage their financial accounts (viewing bills, processing cash withdrawals with fee calculations, and topping up with dynamic payment methods), and access support features (creating and viewing support tickets with proof uploads, and browsing purchase records with card key retrieval). The update also includes controllers for user promotion tracking, child account management, and a global navigation system with mobile drawer and PJAX support.

assets/user/controller/user · high confidence

New user-facing controller pages for authentication, dashboard, and commerce

This change introduces a comprehensive set of new controller classes in the user area, providing the backend logic for several user-facing pages. Users can now access a new Promote Center (Agent) to view referral stats and earnings, a detailed Dashboard with personal asset and merchant income summaries, and a Recharge Center with configurable top-up presets and progress tracking. Additionally, new controllers handle Authentication (login, register, password recovery), Business management (store settings, subdomains), and standard commerce features like Order history, Bill viewing, Cash-out records, and Commodity/Coupon management. Security and account settings are also covered with new controllers for Personal info, Email/Phone/Password changes, and Ticket support.

app/Controller/User · high confidence

New user-facing controllers for dashboard purchase records and security account management

This change introduces new client-side controller scripts for the user area. The dashboard controller adds a 'Recent Purchases' table that displays the last five orders with details like trade number, commodity, SKU, amount, payment status, and delivery status, including a modal to view, copy, or download card secrets. The security controllers implement the frontend logic for updating personal information (including avatar and WeChat QR code uploads, and merchant key reset), changing passwords, and binding or changing email and phone numbers. The email and phone binding flows now require a secondary login password verification and a CAPTCHA challenge to enhance account security during contact information changes.

assets/user/controller/dashboard, assets/user/controller/security · high confidence

New user-facing controllers for product browsing, item details, and order queries

Added three new JavaScript controllers to the user interface: index.js handles the main product listing page with category switching and search; item.js manages individual product pages including SKU selection, pricing calculations, stock checks, and flash-sale timers; query.js implements the order search functionality allowing users to look up orders by keywords and view order details including payment status and card secrets. These files provide the client-side logic for core e-commerce interactions.

assets/user/controller/index · high confidence

Official Docker deployment support

Users can now deploy the application using a single Docker Compose command, which provisions a complete environment including Nginx, PHP-FPM, MySQL, and Redis. The setup includes built-in SSL management, automatic database credential handling via secrets, and a pre-configured .htaccess for Apache environments, significantly simplifying the installation process compared to manual server configuration.

(repo-wide) · high confidence

Behavioural changes

Admin API controllers rewritten with strict validation and security controls

The admin API controllers in app/Controller/Admin/Api have been completely rewritten to enforce strict input validation, rate limiting, and safer data handling. The Authentication controller now includes IP-based rate limiting for login attempts and mandatory CAPTCHA verification to prevent brute-force attacks. Controllers for App, Bill, BusinessLevel, Card, Cash, Category, Commodity, CommodityGroup, Config, and Coupon now validate all inputs against strict type and format rules, enforce batch operation limits, and use database locking to prevent race conditions during critical operations like cash settlements and commodity deletions. The Card controller specifically addresses the issue where export filenames always showed '2' by properly handling card secret filters in POST-only export queries, ensuring sensitive data never enters URLs.

app/Controller/Admin/Api · high confidence

Admin interface now uses a custom Bootstrap 5-based design system

The admin panel's styling has been replaced with a new CSS foundation based on Bootstrap 5. This change introduces a custom color palette (primary, success, info, warning, danger, etc.), updates the default font to HarmonyOS, and applies Bootstrap's grid, form, and component styles to the admin UI. Users will see a refreshed visual appearance for all admin pages, including updated form controls, buttons, and layout structures.

assets/admin/css · high confidence

Introduction of structured constant interfaces and payment base infrastructure

The application now defines a set of new constant interfaces in app/Consts to centralize configuration for email and SMS captcha templates, admin session management, plugin metadata, payment callback fields, and rendering engine selection. A comprehensive Hook interface is introduced, exposing numerous bitwise constants for admin and user view components, API lifecycle events (such as authentication, order processing, and ticket handling), and risk-control interception points. Additionally, the payment subsystem gains a new abstract Base class in app/Pay that standardizes trade context (amount, trade number, client IP) and HTTP client creation, alongside interfaces for payment types and signature verification.

app/Consts · high confidence

New glassmorphism UI theme with light and dark modes

The user interface has been restyled with a new glassmorphism design language, introducing translucent panels, backdrop blurs, and soft shadows. This update includes a complete theming system that supports both light and dark modes, automatically adjusting colors and contrast for readability. The visual overhaul applies to key interface components, including the authentication wrapper, navigation bar, cards, and form elements, providing a modern and cohesive look across the application.

assets/user/css · high confidence

New interceptor-based access control and security filters

The application now uses a dedicated Interceptor layer to enforce access control and security policies before requests reach controllers. This includes UserSession and ManageSession interceptors for validating user and admin login sessions (including JWT verification and host-referrer checks), role-based interceptors (Business, Store, Owner, Super) to restrict features based on merchant levels and admin types, SharedValidation for API signature verification, UserVisitor for handling promotional tracking and guest sessions, and a Waf interceptor that integrates a firewall to block XSS attacks and unauthorized external links.

app/Interceptor · high confidence

Redesigned admin trade management with safer deletion and drag sorting

The admin trade module (card, category, commodity, coupon, and order controllers) has been rewritten to improve safety and usability. Deletion workflows for categories, commodities, and coupons now require a server-side impact preview before confirming, clearly displaying the scope of cascading deletions (e.g., associated orders, tickets, and cards) and preventing accidental data loss. A new shared drag-sorting component provides native-feeling reordering for both desktop tables and mobile card lists, with support for tree structures and reduced-motion preferences. Additionally, the commodity editor now uses a right-side drawer layout, and coupon generation includes a dedicated result popup with copy and download actions.

assets/admin/controller/trade · high confidence

Redesigned purchase success popup with copy/download actions and usage instructions

The user-facing purchase confirmation dialog has been updated to improve usability. The card secret is now displayed in a monospaced, auto-height code block instead of a fixed-height textarea, eliminating excessive whitespace. New 'Copy' and 'Download' buttons allow users to easily save their card secrets. Additionally, any seller-provided usage instructions (leave messages) are now rendered in a dedicated, styled section within the popup, ensuring buyers can see how to use their purchase immediately upon completion.

assets/user/js · high confidence

Updated Font Awesome icon library to version 6.7.0

The common icon assets have been updated to Font Awesome 6.7.0. This change introduces a new duotone icon style alongside the existing solid, regular, light, and brands styles, and adds a large number of new icons (such as \fa-bagel\, \fa-fondue-pot\, and \fa-transporter-7\) to the available set. Users will see these new icons rendered with the updated font files and CSS classes provided in the \assets/common/css/\_.css\ file.

assets/common/js · high confidence

Dependencies

Initial project dependency configuration

The project now includes a \composer.json\ manifest and a \composer.lock\ file, establishing the initial set of dependencies for the PHP 8.0+ virtual card issuing system. This configuration pins specific versions for core libraries including the Smarty templating engine, Laravel Illuminate components (Database, Pagination, Support), Guzzle HTTP client, PHPMailer, Firebase JWT, and Aliyun SMS SDK, ensuring reproducible builds.

(dependencies) · high confidence

Initial vendor dependency installation

The project's \vendor\ directory has been populated with Composer-managed dependencies, establishing the autoloading infrastructure and executable binaries required for the application. This includes the core Composer autoloader (\autoload.php\), command-line proxies for tools like \carbon\ and \var-dump-server\, and the class mapping files that enable the use of libraries such as Smarty, Guzzle, PHPMailer, and various Symfony components.

vendor · high confidence

Updated Doctrine Inflector library

The Doctrine Inflector vendor package has been updated to version 1.0.2. This upgrade introduces a new caching layer for word inflection to improve performance and adds support for additional languages, including Norwegian Bokmal, Portuguese, Spanish, and Turkish, alongside the existing English and French rulesets.

(repo-wide) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 34.

Lenses

  • Code Health 29
  • Architecture 92
  • Maturity 42
  • Readiness 27
  • Security 73
  • Accessibility 36

Changes since last survey

  • 300 commits — 295 feature/other, 5 fixes

By area

  • app/Controller — 91 commits
  • (root) — 64 commits
  • app/View — 37 commits
  • config/app.php — 27 commits
  • app/Service — 18 commits
  • assets/admin — 11 commits
  • app/Util — 8 commits
  • kernel/Install — 8 commits
  • app/Interceptor — 6 commits
  • app/Pay — 5 commits
  • assets/common — 4 commits
  • (repo) — 3 commits
  • app/Consts — 3 commits
  • assets/static — 3 commits
  • .github/workflows — 1 commit
  • app/Model — 1 commit
  • app/Plugin — 1 commit
  • assets/user — 1 commit
  • config/waf — 1 commit
  • docker/acg-ssl.sh — 1 commit

Notable commits

  • fix: Merge pull request #240 from x1nchen/fix/card-export-filename-count
  • fix: fix(admin): 卡密导出文件名数量恒显示为2
  • fix: fix(docker): install required bcmath extension
  • fix: fix(docker): persist uploaded site logo
  • fix: fix(proxy): honor HTTPS from trusted reverse proxies
  • change: 0.1.4-beta
  • change: 0.1.5-beta
  • change: 0.1.6-beta
  • change: 0.1.7-beta
  • change: 0.1.8-beta
  • change: 0.1.9-beta
  • change: 0.1.9-beta
  • change: 0.2.0-beta
  • change: 0.2.1-beta
  • change: 0.2.2-beta
  • change: 0.2.3-beta
  • change: 0.2.4-beta
  • change: 0.2.5-beta
  • change: 0.2.6-beta
  • change: 0.2.7-beta
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

lizhipay/acg-faka was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 71f860ad7a089836a6a3aaa6357e608217005ee2 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.