Skip to content
CAI
Software that uses CAICheck a score

MagicMirrorOrg/MagicMirror

50.2

Adequate · 1 October 2026

13.9k

lines of production code

JavaScript

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a modular smart mirror application that runs on Node.js and Electron, featuring a modernized UI with a flexible region-based layout and extensive theming capabilities. It supports a wide array of default modules for displaying alerts, calendars, clocks, compliments, newsfeeds, and weather data, with robust internationalization and configuration options. The architecture distinguishes between a server-only mode for headless operation and a client-only mode for remote display, ensuring secure communication via strict access controls and context isolation.

How it got here

2014–2017 — UI modernization and test expansion

19 changes.

The project underwent a major UI overhaul, replacing the static DOM with a flexible region-based layout and modernizing styling with CSS variables and updated font libraries. Concurrently, the codebase was hardened with stricter security defaults, upgraded dependencies, and a new server-only runtime, while comprehensive end-to-end and unit tests were added to ensure stability across core modules and configuration scenarios.

2018–2022 — Comprehensive test suite expansion

10 changes.

This period focused on significantly expanding test coverage across the project, adding unit, integration, and end-to-end tests for core utilities, Electron environment, and key modules like Calendar, Weather, and Compliments. The work included migrating tooling to Husky v6 and establishing robust mocking infrastructure to support reliable, isolated testing without external dependencies.

2023–2026 — default module expansion and test coverage

5 changes.

This period focused on integrating new default alert and calendar modules into the core application, complete with comprehensive unit tests for their functionality and configuration. Significant effort was also dedicated to expanding test coverage for existing weather, newsfeed, and update notification modules to ensure robustness and reliability.

Features

Expanded language support with new and updated translation files

The application now supports a wider range of languages through the addition of new translation files (including Afrikaans, Arabic, Azerbaijani, Bulgarian, Catalan, Chuvash, Welsh, Esperanto, Gujarati, Hebrew, Hindi, Indonesian, Icelandic, and others) and updates to existing ones. These files provide localized strings for core UI elements such as date formats, weather conditions, module error messages, and update notifications, ensuring the interface is accessible in more languages.

translations · high confidence

Introduce clientonly script for launching Electron client

A new \clientonly/index.js\ script has been added to allow users to start the Electron application by connecting to a remote server. The script accepts command-line arguments (such as \--address\, \--port\, and \--use-tls\) or environment variables to determine the server connection details. It fetches configuration from the specified server URL, validates the port, and then spawns the Electron process, passing the server configuration via an environment variable. The script supports both HTTP and HTTPS connections and handles display server detection (Wayland vs. X11) to ensure the Electron app launches correctly in the current environment.

clientonly · high confidence

Introduce dedicated server-only runtime and file-watcher for standalone server mode

This change adds a new \serveronly\ directory containing \index.js\ and \watcher.js\, establishing a distinct entry point for running the application in server-only mode (without Electron). The \index.js\ file initializes the app and logs the ready status with the correct protocol (HTTP or HTTPS) and address. The \watcher.js\ module provides a file-watching mechanism that monitors source files for changes, automatically restarting the server process via \node ./serveronly\ when updates are detected, including logic to wait for port availability and notify connected clients to reload.

serveronly · high confidence

New default alert and calendar modules added

The MagicMirror² now includes two new default modules: an alert module for displaying notifications and alerts with configurable effects and positions, and a calendar module for displaying events from public iCal calendars. The alert module supports various notification effects (slide, jelly, flip, etc.) and can display welcome messages. The calendar module fetches and displays events from iCal feeds, with support for multiple calendars, event filtering, and customizable display options.

defaultmodules · high confidence

Behavioural changes

Introduces internal alias resolver and refactors core startup logic

The application now uses a new \js/alias-resolver.js\ module to map internal require aliases (such as \logger\ and \node\_helper\) to absolute paths, ensuring consistent resolution across the codebase. This change is integrated into the core startup sequence in \js/app.js\ and the configuration checker \js/check\_config.js\. Additionally, the Electron entry point \js/electron.js\ has been updated to enforce \contextIsolation: true\ and \nodeIntegration: false\ by default for improved security, and the \js/ip\_access\_control.js\ module now implements stricter same-origin checks alongside IP whitelisting to prevent CSRF attacks.

js · high confidence

Major UI overhaul and modernization of the core application shell

The application's core HTML structure has been completely rewritten to support a modern, region-based layout system, replacing the previous static DOM elements with a flexible grid of containers (e.g., \region top bar\, \region middle center\) that allow modules to be positioned dynamically. The entry point for the JavaScript has switched from standard script tags to an ES module (\`type=

(repo-wide) · high confidence

Migration to Husky v6 with npx-based pre-commit hook

The project has migrated to Husky v6, replacing the previous hook implementation with a new executable \.husky/pre-commit\ script. This script now uses \npx lint-staged\ to execute linting on staged files, ensuring the tooling works correctly regardless of whether \lint-staged\ is installed globally or locally in the project.

.husky · high confidence

Redesigns UI with CSS variables and replaces font/icon libraries

The visual presentation is overhauled to use CSS custom properties for colors, font sizes, and spacing, allowing for more consistent theming and easier adjustments. The default font family changes from Helvetica Neue to Roboto and Roboto Condensed, with font files now sourced from the @fontsource/roboto npm package. Additionally, the legacy weather-icons library is removed and replaced by Font Awesome (via @fortawesome/fontawesome-free), updating the icon set used throughout the interface.

css · high confidence

Updated configuration and styling samples for MagicMirror²

The \config/config.js.sample\ has been refreshed to reflect the current default setup, including a default port of 8080, a new \basePath\ configuration for reverse proxy support, and an expanded \ipWhitelist\ that now includes IPv6 loopback addresses. The sample modules have been updated to use the \openmeteo\ weather provider instead of the deprecated OpenWeatherMap, and the calendar module now includes a specific \fetchInterval\ configuration. Additionally, a new \config/custom.css.sample\ file has been added, providing CSS variables for customizing text colors, fonts, and spacing.

config · high confidence

Test coverage

Added E2E test helpers for app lifecycle, basic auth, and weather mocking; Added Electron module tests for Calendar, Compliments, and Weather; Added end-to-end tests for core modules; Added mock data for calendar and newsfeed tests; Added snapshot tests for updatenotification module; Added test configuration files for module testing; Added test configuration files for the newsfeed module; Added test configurations for Spanish clock module variants; Added test configurations for alert module welcome message behavior; Added test configurations for clock module options; Added test configurations for module display and positioning; Added test configurations for the Compliments module; Added test configurations for weather module variants; Added test helpers for Electron app lifecycle and mock weather data injection; Added tests for Electron app environment and development console; Added unit tests for Calendar, Newsfeed, and UpdateNotification modules; Added unit tests for Compliments module and time formatting utility; Added unit tests for core classes and utilities; Added unit tests for core utility functions and modules; Added unit tests for default modules and root path configuration; Added unit tests for the weather module; Expanded end-to-end test coverage for core application features; Expanded test coverage for the Calendar module.

Dependencies

Upgrade to Node 22+ and modernize core dependencies

The platform now requires Node.js 22.22.2 or 24+ and upgrades key runtime libraries, including Express to v5, Helmet to v8, and node-ical to v0.27.2. Development tooling has also been updated to use Vitest for testing and ESLint v10 for linting.

(dependencies) · high confidence

Housekeeping

Added empty modules directory placeholder

An empty .gitkeep file was added to the modules directory to ensure the directory is tracked by version control.

modules · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 49 → 50 (+1.1)
  • Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 48 → 50 (+1.7)
  • Architecture 99 → 97 (-2.3)
  • Maturity 53 → 48 (-5.4)
  • Readiness 79 → 65 (-14.2)
  • Security 69 → 86 (+16.7)
  • Accessibility 40 → 46 (+5.9)
  • Performance 60 (new)

Resolved (36)

  • App::loadModule (cognitive 19) (js/app.js)
  • App::start (cognitive 25) (js/app.js)
  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
  • FunctionTooLong: app.App (js/app.js)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • Hotspot: defaultmodules/compliments/compliments.js (defaultmodules/compliments/compliments.js)
  • Hotspot: defaultmodules/newsfeed/newsfeed.js (defaultmodules/newsfeed/newsfeed.js)
  • Hotspot: defaultmodules/newsfeed/newsfeedfetcher.js (defaultmodules/newsfeed/newsfeedfetcher.js)
  • Hotspot: defaultmodules/updatenotification/git_helper.js (defaultmodules/updatenotification/git_helper.js)
  • Hotspot: defaultmodules/weather/providers/openmeteo.js (defaultmodules/weather/providers/openmeteo.js)
  • Hotspot: defaultmodules/weather/providers/openweathermap.js (defaultmodules/weather/providers/openweathermap.js)
  • Hotspot: defaultmodules/weather/providers/smhi.js (defaultmodules/weather/providers/smhi.js)
  • Hotspot: js/app.js (js/app.js)
  • …and 16 more

New (20)

  • #getDelayForResponse (cognitive 19) (js/http_fetcher.js)
  • App.#loadModule (cognitive 19) (js/app.js)
  • App.start (cognitive 27) (js/app.js)
  • Concentrated knowledge decay
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low cohesion: WeatherObject (LCOM4 4) (defaultmodules/weather/weatherobject.js)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Outdated (npm): globals
  • Outdated (npm): suncalc
  • Outdated (npm): systeminformation

Changes since last survey

  • 1 commits — 1 feature/other, 0 fixes

By area

  • tests/configs — 1 commit

Notable commits

  • change: Release 2.38.0 (#4286)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

MagicMirrorOrg/MagicMirror was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit f138f5b690ceab6450f55c852ac81d268363f563 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.