Skip to content
CAI
Software that uses CAICheck a score

makenowjust-labs/recheck

58.9

Adequate · 20 September 2026

11k

lines of production code

Scala

with TypeScript

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

Recheck is a security tool designed to detect Regular Expression Denial of Service (ReDoS) vulnerabilities by analyzing regex patterns for exponential or polynomial time complexity. It provides a multi-platform analysis engine that combines automata-based detection with fuzzing, accessible via a command-line interface, a JavaScript library, and an ESLint plugin for static code analysis. The system supports various execution backends, including native Node.js workers and Java processes, to ensure accurate and performant validation of regex safety.

How it got here

2020–2021 — ReDoS checker monorepo launch

8 changes.

The project was rebranded to 'recheck' and restructured into a monorepo to deliver a new Regular Expression Denial of Service (ReDoS) detection tool. This period involved building the core JavaScript analysis engine and an accompanying ESLint plugin, while upgrading the underlying Scala infrastructure and removing legacy template utilities.

2022–2023 — Scala 3 migration and documentation launch

21 changes.

The project migrated its core Scala modules and CLI to Scala 3, introducing a new automata-based ReDoS detection engine and JSON-RPC communication layer. Concurrently, the JavaScript ecosystem was modernized with esbuild tooling, Node 20 support, and a new native worker-pool backend for synchronous checks. This period also saw the initial release of the official documentation website featuring an interactive playground.

Features

Add Node.js code execution support for recall validation

The recheck-exec module now includes a NodeExecutor that allows executing JavaScript code via the \node\ command. On the JVM, this executor runs the provided code in a separate process, capturing the exit code, standard output, and standard error, with optional timeout handling. A corresponding stub for the JavaScript platform is also added, which currently throws an exception indicating that recall validation is not supported in that environment. Tests verify the executor's ability to run simple scripts, handle non-zero exit codes, and respect timeout constraints.

modules/recheck-exec · high confidence

Add \`no-vulnerable\` rule for detecting ReDoS in RegExp patterns

The \eslint-plugin-redos\ now includes a new \no-vulnerable\ rule that analyzes regular expressions to detect Regular Expression Denial of Service (ReDoS) vulnerabilities. The rule reports errors for patterns with exponential or polynomial complexity, configurable via the \permittableComplexities\ option to allow specific complexity levels. It supports various configuration parameters for the underlying \recheck\ analysis engine, including timeouts, attack limits, and checker modes (\auto\, \automaton\, \fuzz\). A new \cache\ option is also available to optimize performance by caching check results. The rule handles both literal regex patterns and \RegExp\ constructor calls, and can be configured to ignore errors for unsupported features or parsing failures via the \ignoreErrors\ option.

packages/eslint-plugin-redos/src/rules · high confidence

Add interactive playground and documentation website components

This change introduces the core UI components for a new documentation website and an interactive playground. It adds a \Demo\ component that allows users to configure and run regular expression checks with various parameters (such as timeout, attack limits, and mutation size) via a form built with \react-hook-form\. Supporting form elements (\NumberInput\, \Select\, \TextArea\) and their styles are included to handle these inputs. Additionally, a \HomepageFeatures\ component is added to display key product capabilities like practical regex support and ReDoS detection on the site's landing page.

website/src/components · high confidence

Add static assets for the documentation website

The website static directory now includes configuration and image assets required for the documentation site. A \.nojekyll\ file has been added to ensure static site generators like GitHub Pages serve the content without processing. Additionally, new SVG images have been introduced: a primary logo (\logo.svg\) in red, theme-specific variants for dark (\logo-dark.svg\) and light (\logo-light.svg\) modes, and utility icons including a book, gears, and a magic wand, which support the visual identity and navigation of the documentation.

website/static · high confidence

Add website home page and interactive playground

The website now includes a new home page (index) featuring a themed logo, site title, tagline, and navigation buttons for 'Get Started' and 'Playground', alongside a dedicated playground page that embeds an interactive demo component for users to try the tool in their browser.

website/src/pages · high confidence

Added caching for ReDoS checks with configurable strategies

The eslint-plugin-redos now supports caching the results of ReDoS checks to improve performance. A new \cache\ option allows users to specify a cache file location and a strategy (\aggressive\ or \conservative\, with \conservative\ as the default). In conservative mode, only results from the deterministic automaton checker are cached, while aggressive mode caches all results. The cache is automatically invalidated if the underlying \recheck\ version or other settings change.

packages/eslint-plugin-redos/src/utils · high confidence

Initial release of eslint-plugin-redos for ReDoS detection

The \eslint-plugin-redos\ package is introduced to help users detect Regular Expression Denial of Service (ReDoS) vulnerabilities in their codebases. The plugin exposes a \no-vulnerable\ rule and provides both standard and flat configuration presets (\recommended\ and \flat\). It includes TypeScript definitions for type safety and is built using esbuild, with support for Node.js v20 (dropping v14).

packages/eslint-plugin-redos · high confidence

Initial release of the Recheck documentation website

The Recheck documentation website is now available, providing users with comprehensive guides on usage (as JavaScript, Scala, and ESLint plugins), internals, and a live Playground for testing. The site features a responsive design with automatic dark mode support, Algolia-powered search, and Google Analytics integration.

website · high confidence

Introduces a native Node.js worker-pool backend for synchronous checks

The \packages/recheck/src/lib\ module now includes a new \WorkerPool\ implementation that executes regular-expression checks in a pool of Node.js worker threads, providing a high-performance alternative to the existing Java and pure-JavaScript backends. This change adds the necessary infrastructure to support the \RECHECK\_BACKEND=worker\ and \RECHECK\_SYNC\_BACKEND=synckit\ environment variables, allowing users to opt into this faster, native execution path for synchronous validation without relying on external processes or the slower pure-JS interpreter.

packages/recheck/src/lib · high confidence

Introduction of the \`recheck\` JavaScript package for ReDoS detection

The \recheck\ package is introduced as a new JavaScript library for detecting Regular Expression Denial of Service (ReDoS) vulnerabilities. It exposes \check\ (asynchronous) and \checkSync\ (synchronous) functions that analyze a regular expression pattern and return diagnostics, including potential hotspots. The API supports a comprehensive set of configuration parameters to tune the analysis, such as \accelerationMode\ (with values \auto\, \on\, \off\), \checker\ type selection (\auto\, \fuzz\, \automaton\), and various limits for fuzzing iterations, string sizes, and timeouts. The package is implemented in TypeScript, targets ES2020, and includes Jest-based test infrastructure.

packages/recheck · high confidence

New ECMA-262 regular expression parser implementation

The \recheck-parse\ module now includes a new parser for ECMA-262 regular expressions, implemented in Scala 3 using the fastparse library. This change introduces a new \Parser\ object that converts regex strings into an Abstract Syntax Tree (AST), handling features such as named captures, back-references, and Unicode properties. The implementation includes specific validation for flag sets, capture index assignment, and back-reference resolution, along with corresponding test suites to verify parsing correctness and error handling.

modules/recheck-parse · high confidence

New JSON serialization and deserialization for recheck diagnostics and parameters

This change introduces a new \codec\ package that provides Circe-based JSON encoders and decoders for recheck core types. Users can now serialize \Diagnostics\ (including safe, vulnerable, and unknown states), \Checker\ modes, \AttackComplexity\, \AttackPattern\, \Hotspot\, and \ErrorKind\ into structured JSON. Additionally, a decoder for \Parameters\ is added, allowing configuration objects to be loaded from JSON with support for default fallbacks on missing fields, including specific handling for \Duration\ types (mapping null to infinity).

modules/recheck-codec/shared/src/main · high confidence

New JavaScript API for ReDoS pattern checking

A new JavaScript entry point (ReDoSJS) is now available in the recheck-js module, exposing a \check\ function that allows JavaScript applications to analyze regular expressions for ReDoS vulnerabilities. This API accepts a pattern, flags, and optional parameters (such as a custom checker or a logger callback), and returns the analysis result as a JavaScript object.

modules/recheck-js · high confidence

New automata-based ReDoS detection engine

The recheck-core module now includes a new ReDoS checker based on automata theory, implemented in the \automaton\ package. This engine compiles regular expressions into an ε-NFA and analyzes the resulting state machine to detect exponential and polynomial time complexity vulnerabilities. It is integrated into the \ReDoS\ frontend as a selectable strategy (alongside the existing fuzzing approach) and includes a recall validation step to verify findings against a JavaScript runtime.

modules/recheck-core · high confidence

Removals

Removal of Hello World template utility

The Hello.scala file, which previously provided a simple utility to return the string "Hello World", has been removed from the codebase. This eliminates the associated template functionality for users who may have relied on this specific output.

src/main · high confidence

Behavioural changes

Adopts esbuild for bundling with explicit Node 20 target

The build process for the ESLint plugin now uses esbuild to bundle the source code into a CommonJS module, replacing previous bundling methods. This change explicitly sets the compilation target to es2020 and configures the build to run on the Node platform, ensuring compatibility with Node.js 20 while dropping support for Node.js 14. Additionally, a custom esbuild plugin is included to mark all non-relative imports as external, preventing unnecessary dependencies from being bundled into the final output.

packages/eslint-plugin-redos/scripts · high confidence

Build system migrated to esbuild with explicit Node.js 20 support

The build process for the recheck scripts has been rewritten to use esbuild, replacing the previous tooling. This change introduces explicit support for Node.js 20 (dropping Node 14) and sets the compilation target to ES2020. The new build script produces three outputs: a main library, a browser-specific bundle, and a separate worker bundle. It also implements a plugin to inline Web Workers as JavaScript strings and conditionally disables source maps in production builds to reduce output size.

packages/recheck/scripts · high confidence

CLI argument parsing and RPC handling rewritten for Scala 3

The recheck CLI's command-line argument parsing has been rewritten using Scala 3 syntax and the \decline\ library, introducing new \Argument\ instances for duration, checker mode, acceleration mode, and seeder type that validate inputs and provide clear error messages. Additionally, the JSON-RPC communication layer has been updated to support Scala 3, with new tests verifying request/response encoding, ID handling, and error reporting for both request and notification handlers.

modules/recheck-cli/src · high confidence

A new custom CSS file has been added to the website to apply specific visual tweaks. Code line highlighting now uses a subtle background tint that adapts to dark mode, and the header GitHub link displays a custom SVG icon with hover opacity effects. Additionally, the 'See all results' footer link within the search widget is hidden to address a known Docusaurus issue.

website/src/css · high confidence

The eslint-plugin-redos package has been updated to support ESLint's flat configuration format. A new recommended configuration is now available, which enables the 'redos/no-vulnerable' rule by default. The plugin's main entry point has been restructured to expose both the legacy and flat config versions, ensuring compatibility with modern ESLint setups while maintaining the core vulnerability detection capability.

packages/eslint-plugin-redos/src · high confidence

New backend selection and synchronous execution options for the recheck package

The \recheck\ package now supports selecting the analysis backend via the \RECHECK\_BACKEND\ environment variable, allowing users to choose between \auto\ (tries native then Java), \java\, \native\, \worker\, or \pure\. Additionally, the synchronous \checkSync\ function now supports a \RECHECK\_SYNC\_BACKEND\ variable, enabling users to run checks synchronously using either the \synckit\ worker backend or the \pure\ JavaScript implementation, with input validation ensuring both \source\ and \flags\ are strings.

packages/recheck/src · high confidence

Project rebrand to recheck and build infrastructure updates

The project has been renamed from 'template-scala' (or 'redos') to 'recheck', described as a 'trustworthy ReDoS checker', with the README and license year updated to 2025. Build and development tooling have been significantly reconfigured: the Scala formatter (scalafmt) is upgraded to version 3.11.5 with Scala 3 dialect support, the Scala fixer (scalafix) is configured for Scala 3 import organization, and the JavaScript package manager has switched to pnpm with a new workspace configuration. Additionally, new configuration files have been added to manage CI git blame history, set JVM heap size limits for SBT, and configure Yarn to ignore platform checks.

(repo-wide) · high confidence

ReDoS checker rewritten in Scala 3 with new CLI and RPC subsystems

The recheck tool has been migrated to Scala 3, introducing a new command-line interface and a JSON-RPC agent mode for remote checking. The CLI now exposes granular configuration options for fuzzing parameters (such as attack limits, timeouts, and mutation sizes) via the \recheck check\ command, while the new \recheck agent\ command enables asynchronous, cancellable checks over a stdio-based JSON-RPC protocol. Under the hood, the automata-based detection engine has been refactored to use Scala 3 syntax and features, including updated epsilon-NFA construction, deterministic finite automaton conversion, and look-ahead NFA handling to identify polynomial and exponential complexity vulnerabilities.

repository · high confidence

Recheck-common module rewritten in Scala 3

The recheck-common library has been migrated to Scala 3, introducing new core abstractions for fuzzing execution: AccelerationMode (auto/on/off), Checker (automaton/fuzz/auto), and Seeder (static/dynamic). It also adds a Context class for managing execution deadlines and cancellation tokens, along with a set of specific exceptions (TimeoutException, CancelException, etc.) to handle runtime errors. Comprehensive test coverage has been added for all new enums, the cancellation mechanism, and context behavior.

modules/recheck-common, modules/recheck-unicode · high confidence

Test coverage

Added comprehensive test suite for the recheck codec; Added test worker infrastructure for the recheck library; Removal of HelloSuite test file.

Dependencies

Initial release of the recheck monorepo and ESLint plugin

This change introduces the initial project structure for recheck, a ReDoS (Regular Expression Denial of Service) checker. It establishes a monorepo managed by Lerna 10.0.1 and pnpm, containing the core \recheck\ package, the \eslint-plugin-redos\ for static analysis, and platform-specific binary packages (Linux, macOS, Windows). The core package relies on \synckit\ for synchronous execution and targets Node.js 20+, while the Scala backend has been upgraded to Scala 3.7.4 and uses ICU4j 78.3 for Unicode data processing.

(dependencies) · high confidence

Upgrade build tooling and add Unicode data generation scripts

The project's build infrastructure has been significantly updated: sbt is upgraded from version 1.4.0 to 1.12.15, and several plugins have been added or updated, including sbt-scalafix (0.9.21 to 0.14.9), sbt-assembly (new), sbt-ci-release (new), sbt-scalajs-crossproject (new), sbt-scalajs (new), sbt-native-image (new), sbt-scalafmt (2.4.2 to 2.6.2), and sbt-scoverage (new). Additionally, new Scala source files (CaseMapDataGen.scala, PropertyDataGen.scala, UnicodeDataGen.scala) have been added to the project directory to generate Unicode case mapping and property data, replacing the previous reliance on external libraries like icu4j for this specific data generation step.

project · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 59.

Lenses

  • Code Health 88
  • Architecture 78
  • Maturity 51
  • Readiness 76
  • Security 52

Changes since last survey

  • 300 commits — 288 feature/other, 12 fixes

By area

  • (root) — 196 commits
  • .github/workflows — 25 commits
  • (repo) — 21 commits
  • project/plugin.sbt — 21 commits
  • project/build.properties — 16 commits
  • packages/recheck — 4 commits
  • modules/recheck-cli — 3 commits
  • modules/recheck-core — 3 commits
  • project/build.sbt — 3 commits
  • packages/eslint-plugin-redos — 2 commits
  • modules/recheck-common — 1 commit
  • modules/recheck-exec — 1 commit
  • modules/recheck-parse — 1 commit
  • modules/recheck-unicode — 1 commit
  • packages/recheck-linux-arm64 — 1 commit
  • website/docusaurus.config.js — 1 commit

Notable commits

  • fix: Fix #1616: resolve the windows path issue
  • fix: Fix ReDoS.checkAuto test for preventing flaky test
  • fix: Fix scalafix config correctly for Scala 3
  • fix: Fix scalafmt config for Scala 2.12 files of SBT
  • fix: Merge pull request #1620 from makenowjust-labs/fix/1616-win-path
  • fix: Merge pull request #1629 from makenowjust-labs/fix/path-check-test
  • fix: Merge pull request #1631 from makenowjust-labs/fix/pnpm
  • fix: Merge pull request #1638 from makenowjust-labs/fix/redos-checkAuto-flaky-test
  • fix: Merge pull request #1650 from makenowjust-labs/fix/explicit-dep-type
  • fix: Merge pull request #1651 from makenowjust-labs/fix/to-scala3
  • fix: Merge pull request #1653 from makenowjust-labs/fix/apply-rewrite
  • fix: Merge pull request #1697 from makenowjust-labs/fix/export-type-eslint-plugin
  • change: Add @types/estree for typecheck
  • change: Add d.ts to the ESLint plugin
  • change: Add a Linux ARM64 build
  • change: Add dependencies for types explicitly
  • change: Add the --detectOpenHandles option to run test
  • change: Apply -rewrite -new-syntax and -rewrite -indent
  • change: Disable coverage on ScalaJS tests
  • change: Enable --forceExit option
  • …and 280 more

Architecture

  • 0 containers · 1 bounded contexts · 0 dependency edges (baseline)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

makenowjust-labs/recheck was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit d4dbb9557e55c253fd14f4238e78462489a38824 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.