Skip to content
CAI
Software that uses CAICheck a score

ludofleury/blackflag

63.8

Adequate · 21 September 2026

2k

lines of production code

PHP

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Add Black Flag character creation with primary attributes and skills

Introduced the core domain model for creating and managing playable characters in the Black Flag RPG. This includes primary attributes (Adaptability, Charisma, Constitution, Dexterity, Expression, Knowledge, Perception, Power, Strength) with validation logic ensuring a minimum total of 46 points. The change also adds a skills system, allowing characters to learn specific skills with levels, specializations, and professional status. An event-sourcing implementation is provided via \EventStore\ and \EventBus\ classes, backed by a Doctrine \Message\ entity for persistence. Configuration files for Doctrine, Messenger, and routing are added to support this new infrastructure.

php · high confidence

Add Nginx configuration for PHP-FPM and Symfony front controller

A new Nginx Dockerfile and configuration file (php-symfony.conf) have been added to the project. The configuration sets up Nginx to serve static files from the /var/app/public directory and routes all requests through the index.php front controller via PHP-FPM on port 9000. It also includes security measures to prevent direct access to other PHP files and logs to /var/log/nginx/.

nginx · medium confidence

Dependencies

Add PHP 8 and Symfony 5.2 dependencies

The project now requires PHP 8 and upgrades to Symfony 5.2, including related packages such as symfony/framework-bundle, symfony/messenger, and doctrine/orm. Development dependencies for testing and static analysis (e.g., phpunit, phpstan, vimeo/psalm) are also added.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 62 → 64 (+1.6)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (-0.3)
  • Architecture 100 → 97 (-3.1)
  • Maturity 54 → 48 (-5.5)
  • Readiness 64 → 68 (+3.7)
  • Security 55 → 73 (+17.6)
  • Event Sourcing 100 → 100 (+0.0)

Resolved (27)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (php/composer.lock)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (php/composer.lock)
  • High CVE: [GHSA redacted] (php/composer.lock)
  • High CVE: [GHSA redacted] (php/composer.lock)
  • High CVE: [GHSA redacted] (php/composer.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low CVE: [GHSA redacted] (php/composer.lock)
  • Medium CVE: [GHSA redacted] (php/composer.lock)
  • Medium CVE: [GHSA redacted] (php/composer.lock)
  • Medium CVE: [GHSA redacted] (php/composer.lock)
  • Medium CVE: [GHSA redacted] (php/composer.lock)
  • No exposed public API
  • …and 7 more

New (30)

  • Critical CVE: [GHSA redacted] (php/composer.lock)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • High CVE: [GHSA redacted] (php/composer.lock)
  • High CVE: [GHSA redacted] (php/composer.lock)
  • High CVE: [GHSA redacted] (php/composer.lock)
  • High CVE: [GHSA redacted] (php/composer.lock)
  • High IaC: WD-DOCKER-0001 (php/Dockerfile)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low CVE: [GHSA redacted] (php/composer.lock)
  • Low IaC: WD-COMPOSE-0002 (docker-compose.dev.yml)
  • Medium CVE: [GHSA redacted] (php/composer.lock)
  • …and 10 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

ludofleury/blackflag was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit d56eaddf4d8b846d0c4face7ad87329519b34d62 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.