Skip to content
CAI
Software that uses CAICheck a score

m-noer/flutter_starter_project

61.8

Adequate · 21 September 2026

1.9k

lines of production code

Dart

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a mobile application, likely built with Flutter, that manages user authentication and presents a dashboard interface. The codebase has been refactored to remove the initial onboarding flow, routing users directly to login or the main dashboard based on their state. The project also includes integration and unit tests for the login functionality, alongside standard dependency and configuration updates.

Behavioural changes

Removes onboarding flow and updates app theme and navigation

The onboarding page and associated route have been removed, with the app now routing directly to the login or dashboard based on the user's login state. The global theme has been updated with a new purple-to-blue color palette and increased border radius on buttons and input fields. Additionally, the dashboard header now displays 'Nerolab' instead of 'VarX' and includes a logout button that clears local storage and returns the user to the login screen.

lib/core · high confidence

iOS project file formatting fix

The iOS project file (project.pbxproj) was updated to remove a trailing newline at the end of the file, ensuring consistent file formatting.

ios · medium confidence

Test coverage

Updated integration test for login page; Updated test mocks and removed obsolete onboarding tests.

Dependencies

Updated Dart SDK constraint and dependency versions

The project's Dart SDK constraint has been raised from '\>=2.14.0' to '\>=2.15.1'. Several dependencies have been updated to newer versions: 'connectivity\_plus' to 2.2.0, 'device\_info\_plus' to 3.2.1, 'flutter\_native\_splash' to 1.3.3, and 'image' to 3.1.0. Additionally, the 'dots\_indicator' and 'introduction\_screen' packages have been removed from the project.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 58 → 62 (+3.8)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (+0.0)
  • Architecture 100 → 91 (-9.2)
  • Maturity 88 → 90 (+1.8)
  • Readiness 35 → 33 (-1.9)
  • Security 61 → 81 (+20.1)
  • Domain Modelling 100 → 100 (+0.0)

Resolved (18)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (pubspec.lock)
  • High CVE: [GHSA redacted] (pubspec.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No exposed public API
  • Rotate the exposed credentials — git history can't be un-committed
  • Secret: generic-api-key (android/app/src/development/google-services.json)
  • Secret: generic-api-key (android/app/src/production/google-services.json)
  • Secret: generic-api-key (android/app/src/staging/google-services.json)
  • Test reliability not included
  • The Working with Translations section is excellent but only covers usage; the Create Google Sheet and Declare delegate steps are present in the outline, so a dedicated 'Adding Localization' or 'Localizing Your App' doc would clarify how to get started. (README.md)
  • complexity unreadable for .dart, .kt, .swift — churn × complexity hotspots could not be measured
  • early-stage repository — too little history to judge knowledge freshness
  • git history depth insufficient
  • single-maintainer — knowledge-concentration (bus factor) risk

New (13)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • High CVE: [GHSA redacted] (pubspec.lock)
  • High CVE: [GHSA redacted] (pubspec.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Leaked secret: gcp-api-key (web/firebase-messaging-sw.js)
  • Leaked secret: high-entropy-secret (web/firebase-messaging-sw.js)
  • Low cohesion: PageUtil (LCOM4 4) (lib/core/utils/services/page_util.dart)
  • Medium: security finding (details withheld)
  • No Gemfile.lock committed by an application
  • No dependency advisory monitoring

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

m-noer/flutter_starter_project was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 26cbbd9219cfdaf50049c91263bf28ff64463c74 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.