Skip to content
CAI
Software that uses CAICheck a score

maillab/cloud-mail

36.1

Weak · 1 October 2026

23.6k

lines of production code

JavaScript

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a cloud-based email management platform comprising a Vue.js frontend and a backend worker service. It enables users to compose and manage emails with rich text editing, while supporting OAuth authentication, AI-powered verification, and automated email processing. The backend provides administrative controls for user management, analytics, and secure storage, with notifications delivered via Telegram and webhooks.

Features

Added English language support for the mail worker interface

The mail worker now supports English in addition to Chinese. This change introduces new i18n resource files (\en.js\ and \zh.js\) and an initialization module (\i18n.js\) that detects the user's preferred language via the \Accept-Language\ header and falls back to Chinese. All user-facing error messages, permission labels, and system status texts are now available in English, allowing non-Chinese speakers to interact with features like email sending limits, domain permissions, and role management.

mail-worker/src/i18n · high confidence

Added TinyMCE editor plugins for enhanced content editing

The application now includes several new TinyMCE plugins to enrich the email composition experience. Users can insert and toggle collapsible accordion sections, manage custom anchors, and utilize advanced list styles for ordered and unordered lists. The editor also supports automatic link detection, automatic content resizing, and draft saving to prevent data loss. Additionally, users can insert special characters, view and edit raw source code, and apply syntax highlighting to code samples.

(repo-wide) · high confidence

Added email analysis data access and optimized email list retrieval

Introduced a new analysis DAO layer to support data visualization features, providing database queries for total email/user/account counts and daily activity trends over the last 15 days with timezone adjustments. Additionally, added a library for email list column definitions that optimizes list performance by fetching a brief summary (excluding full content unless necessary) and stripping whitespace from content fields to reduce payload size.

mail-worker/src/dao · high confidence

Expanded API surface for user management, account configuration, and email operations

The mail-worker API has been significantly expanded to support new administrative and user-facing capabilities. Administrators can now manage user accounts directly via new endpoints for listing, adding, modifying status/type, resetting send counts, and restoring or permanently deleting users and their associated accounts. User account management has also improved with endpoints to rename accounts, configure bulk receive settings, and pin accounts to the top of the list. Email operations now include marking messages as read and sending new emails, while new API routes enable viewing all emails (including batch deletion), accessing analytics data, and managing registration keys. Additionally, OAuth integration has been broadened to support LinuxDo, GitHub, and Google logins, and a new endpoint allows fetching email content via Telegram.

mail-worker/src/api · high confidence

Introduces new UI components and localization infrastructure

The application now includes a suite of new frontend components to enhance the user interface and functionality. This adds a skeleton loader for the email list to improve perceived performance during loading, a shadow DOM-based HTML renderer for email content to ensure style isolation, and a TinyMCE-based rich text editor for composing messages. Additionally, a new write-email layout is introduced to handle sending, replying, and forwarding, featuring a recent contacts selector and attachment management. The update also establishes the foundation for internationalization by adding English and Chinese translation files and a language initialization module, alongside static asset caching headers and a new icon set.

mail-vue/src · high confidence

Major backend service overhaul with AI, OAuth, and storage integrations

The mail-worker service has been significantly expanded with new capabilities for AI-powered verification code extraction, multi-platform OAuth2 login (LinuxDo, GitHub, Google), and flexible object storage (S3 and KV). The system now supports detailed role-based access control with domain and email restrictions, automated email forwarding to Telegram and webhooks, and analytics data caching. Additionally, attachment handling has been improved to support inline images and S3 storage, while user management features include batch operations and registration key validation.

mail-worker/src/service · high confidence

New email rendering templates for HTML, text, and Telegram notifications

Added three new template files in the mail-worker module to handle email content rendering: \email-html.js\ generates a self-contained HTML document with shadow DOM isolation and auto-scaling for email bodies; \email-msg.js\ formats email metadata (subject, sender, recipient) and body text for Telegram notifications, including HTML escaping and message length truncation to respect Telegram's 3500-character limit; \email-text.js\ provides a simple HTML wrapper for plain-text email content. These templates replace or supplement previous inline logic, ensuring consistent formatting and safety (e.g., script removal, HTML escaping) across email and Telegram output channels.

mail-worker/src/template · high confidence

Behavioural changes

Background maintenance and static asset serving via KV

The mail worker now serves static files and attachments directly from KV storage instead of relying solely on the assets binding, and introduces a scheduled task that runs every 30 minutes to clear verification records, reset daily send counts, complete pending email receives, auto-clean emails, refresh analytics caches, and remove unbound OAuth users.

mail-worker/src · high confidence

Consolidated database initialization and migration logic in mail-worker

The mail-worker's database setup has been refactored to replace the previous separate initialization scripts (init-db.js, init-cache.js) with a single, versioned migration entry point (init.js). This new module handles the initial schema creation and applies incremental schema updates for versions v1.1 through v3.3, introducing new capabilities such as automatic email cleaning (v3.3), webhook configuration (v3.3), OAuth2 support for LinuxDo, GitHub, and Google (v3.2), AI-powered verification code handling (v3.1), and email blacklisting (v3.1). It also includes performance optimizations via new database indexes (v3.2) and UI-related schema changes like unread status tracking (v2.5) and account sorting (v2.8).

mail-worker/src/init · high confidence

Customized TinyMCE editor styling and icon set

The email composition experience now uses a custom-styled TinyMCE editor. A new CSS file (\index.css\) overrides default editor styles to enforce specific margins, font sizes, link colors, and scrollbar appearances, while also ensuring images scale responsively and tables without explicit borders render cleanly. Additionally, a new default icon set (\icons.min.js\) has been introduced, providing a comprehensive suite of SVG icons for the editor toolbar.

mail-vue/public/tinymce · high confidence

Dark mode support and PWA configuration

The application now supports a dark mode, applied via CSS classes and dynamic theme-color meta tags in index.html, and includes a new initial loading screen with a progress animation. Additionally, PWA capabilities are configured through VitePWA in vite.config.js, defining the app manifest name ('Cloud Mail') and icons, while build targets are updated to es2022.

mail-vue · high confidence

Enhanced email processing with AI verification, blacklisting, and role-based domain restrictions

The email worker now supports configurable AI-powered verification code extraction, allowing users to enable or filter codes based on settings. It introduces a blacklisting mechanism that rejects messages matching specific subjects, content, or sender addresses. Additionally, role-based access control is enforced to ensure recipients are authorized to use their assigned domains and are not banned from receiving emails. The processing logic also handles Plus Addressing by resolving base emails, improves attachment handling by using content hashes for storage keys, and supports forwarding via Telegram and webhooks.

mail-worker/src/email · high confidence

Enhanced email validation and utility functions in mail-worker

The mail-worker utility layer now includes stricter email validation that supports plus-addressing (e.g., user+tag@domain) and domain verification, alongside new helpers for extracting email parts, formatting text, and converting HTML to plain text. File handling has been improved with SHA-256 hashing, Base64-to-File conversion, and safer extension extraction, while request utilities now parse user-agent details and domain utilities normalize OSS URLs. These changes support more robust email processing and attachment handling within the worker.

mail-worker/src/utils · high confidence

Expanded API surface and improved error diagnostics

The mail worker's HTTP interface now exposes several new functional endpoints, including APIs for R2 storage, Resend integration, user management, role-based access, email analysis, registration keys, public access, Telegram notifications, and OAuth authentication. Additionally, the application's error handling has been refined to provide specific, user-friendly messages for common configuration issues, such as unbound KV or D1 databases and missing database columns, replacing generic error responses with actionable guidance.

mail-worker/src/hono · high confidence

Expanded data model and configuration schema for advanced email management and integrations

The mail-worker's database schema has been significantly extended to support new administrative, security, and integration features. New entity tables have been added for OAuth providers, user roles, permissions, and registration keys, enabling granular access control and third-party login support. The core email and account entities now track read/unread status, CC/BCC recipients, and sorting preferences, while the settings table has been populated with configuration fields for S3 storage, Telegram bot forwarding, AI verification codes, email blacklisting, auto-cleaning, and webhook notifications. Additionally, the user entity now records device and IP metadata, and the ORM layer exposes a configurable logging environment variable.

mail-worker/src/entity · high confidence

Granular permission checks and centralized authentication context

The security module now enforces fine-grained, path-based permissions for administrative and user-management actions (such as sending emails, managing accounts, roles, and settings) rather than relying on a simple admin-email check. Authentication is centralized in a middleware that validates JWTs and stores the user object in the request context, allowing other components to retrieve user details without re-parsing tokens. Public endpoints are protected by a separate token check, and error messages are now internationalized.

mail-worker/src/security · high confidence

Removal of legacy build artifacts from distribution directory

The \index.html\ entry point and the \vite.svg\ asset have been removed from the \mail-worker/dist\ directory. This indicates that the static build output for this component is no longer managed or served directly from this location, likely as part of a broader restructuring of how the frontend assets are packaged or deployed.

mail-worker/dist · high confidence

Removed static assets from mail-worker distribution

The pre-built static assets for the mail-worker frontend, including the favicon and the main JavaScript bundle, have been removed from the repository. This change reflects a shift to automatic packaging of static resources during deployment, meaning these files are no longer committed directly but are generated as part of the build process.

mail-worker/dist/assets · high confidence

Dependencies

Project migration to pnpm and dependency upgrades

The mail-vue and mail-worker modules have migrated from npm to pnpm, replacing package-lock.json files with pnpm-lock.yaml. This change includes significant dependency updates: mail-vue upgraded Vite to 7.1.5, Element Plus to 2.13.1, and added libraries like vue-i18n, echarts, and dexie, while mail-worker upgraded Wrangler to 4.90.0, Hono to 4.12.16, and added AWS S3 client support and i18next.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 43 → 36 (-7.3)
  • Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 56 → 56 (+0.0)
  • Architecture 47 → 61 (+13.6)
  • Maturity 62 → 62 (+0.3)
  • Readiness 39 → 27 (-12.8)
  • Security 62 → 35 (-27.0)
  • Accessibility 40 → 40 (+0.0)
  • Performance 100 (new)

Resolved (9)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • High CVE: [GHSA redacted] (mail-vue/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (mail-worker/pnpm-lock.yaml)
  • Hotspot: mail-vue/src/views/all-email/index.vue (mail-vue/src/views/all-email/index.vue)
  • Hotspot: mail-vue/src/views/email/index.vue (mail-vue/src/views/email/index.vue)
  • Hotspot: mail-vue/src/views/login/index.vue (mail-vue/src/views/login/index.vue)
  • Hotspot: mail-worker/src/service/account-service.js (mail-worker/src/service/account-service.js)
  • Hotspot: mail-worker/src/service/email-service.js (mail-worker/src/service/email-service.js)

New (2)

  • Banned license: ua-parser-js
  • High vulnerability: [GHSA redacted] (mail-worker/pnpm-lock.yaml)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

maillab/cloud-mail was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit ec7a2bb17c950576c38d7308128cac7696fea169 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.