Skip to content
CAI
Software that uses CAICheck a score

mataroablog/mataroa

59.5

Adequate · 13 August 2026

8.9k

lines of production code

Python

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This is a Django-based blogging platform that enables users to create, manage, and export their blogs in multiple formats, including EPUB, Hugo, and Zola. The system provides comprehensive user authentication, subscription management via Stripe, and content moderation tools. It also supports rich media uploads, analytics tracking, and automated email notifications for subscriptions and moderation summaries.

How it got here

2020 — Modernization and feature expansion

11 changes.

The project underwent a comprehensive modernization, upgrading to Django 6 and replacing legacy tooling with modern Python standards like pyproject.toml and Ruff. Concurrently, the codebase was reorganized into structured modules, and the application expanded with new features for analytics, billing, and content export.

2021–2025 — Infrastructure and feature expansion

8 changes.

This period focused on expanding application features, including EPUB export, image upload capabilities, and a restructured views module. It also involved significant infrastructure changes, replacing Ansible with Bash scripts and systemd units for deployment and background task management.

Features

Add Hugo export templates and styling

The Hugo export now includes a complete set of base templates (baseof, index, list, single, and 404 pages) along with a style.css and theme.toml to support the 'mataroa' theme. This enables users to export their blog content in a structured, styled format compatible with Hugo, including proper RSS feed links and a custom 404 page.

_export\_base\hugo · high confidence

Add Zola export base templates and configuration

Added the foundational template files and configuration for the Zola static site generator export. This includes a new 404 error page, an index template that lists blog posts with titles and dates, a post detail template for individual articles, and a base CSS stylesheet. The configuration file sets up RSS feed generation, enables code syntax highlighting, and configures internal link checking to emit warnings rather than errors.

_export\_base\zola · high confidence

Added base template files for EPUB export

The export\_base\_epub directory now includes the foundational structure for generating EPUB files. New files such as container.xml, content.opf, mimetype, toc.ncx, and toc.xhtml have been added to define the EPUB package, metadata, and table of contents. This establishes the base template used during the EPUB export process.

_export\_base\epub · high confidence

Added user authentication and password management templates

The application now includes a complete set of templates for user registration and authentication, including login, logout, password reset, and password change flows. Users can now log in with a username and password, request a password reset via email, and securely change their password. The login form includes helpful text for the username field and displays form errors appropriately.

main/templates/registration · high confidence

Adds drag-and-drop and paste-to-upload for images, plus auto-save and draft management scripts

The templates/assets directory now includes new JavaScript modules: \drag-and-drop-upload.js\ enables users to upload images via drag-and-drop or by pasting images into the body textarea, automatically inserting Markdown image syntax. \save-snapshot.js\ implements an auto-save feature that periodically posts the post title and body to \/post-backups/create/\. \make-draft-button.js\ adds UI controls to set the publication date to today or clear it for drafts. These scripts are accompanied by new CSS files (\style-moderation.css\ and \style.css\) that style the moderation dashboard, update dark mode colors, and apply base styles like font sizes and link colors.

main/templates/assets · medium confidence

Custom error pages for 400, 403, 404, and 500 status codes

The application now provides dedicated, user-friendly error pages for common HTTP status codes. Users encountering a bad request (400), permission denied (403), a missing page (404), or an internal server error (500) will see a consistent layout with a clear title, a brief explanation, and navigation links to go back or return to the homepage. This replaces any previous default or missing error templates, ensuring a better experience when errors occur.

main/templates · high confidence

New analytics, billing, and API documentation templates

Added templates for the new analytics dashboard (analytic\_detail, analytic\_list), billing management (billing\_card, billing\_overview, billing\_subscribe, billing\_resubscribe, billing\_subscription\_cancel, billing\_subscription\_resume, billing\_card\_confirm\_delete), and API documentation (api\_docs, api\_key\_reset). Also added templates for blog import (blog\_import), blog index (blog\_index), comment moderation (comment\_approve, comment\_confirm\_delete, comment\_form, comment\_list), comparisons page (comparisons), user dashboard (dashboard), export functionality (export\_index, export\_print, export\_unsubscribe\_success), and various guides (guides\_comments, guides\_customdomain, guides\_images, guides\_markdown). These changes introduce new user-facing pages for managing subscriptions, viewing site statistics, managing API keys, and accessing documentation.

main/templates/main · high confidence

New management commands for moderation summaries, renewal reminders, and post notifications

The application now includes several new management commands in the \main/management/commands\ directory. \mailsummary\ generates and emails a daily moderation summary to administrators. \mailrenewal\ sends email reminders to premium subscribers about upcoming subscription renewals. \processnotifications\ handles sending email notifications to subscribers when new posts are published, including both plain text and HTML versions. \checkstripe\ provides a mechanism to reconcile Stripe subscription data with the local database, allowing administrators to downgrade premium status for users who have lost their Stripe subscriptions. Additionally, \mailexports\ handles monthly markdown exports of user blogs, \testnotification\ allows sending test emails for debugging, and \devdata\ generates sample data for local development.

main/management · high confidence

Restructure and expand the views module with new API, billing, and export endpoints

The \main/views\ package has been reorganized into distinct modules (\api.py\, \billing.py\, \export.py\, \general.py\, \moderation.py\) to improve code organization. This change introduces new API endpoints for managing comments and posts, a rewritten billing overview and subscription management interface, and enhanced export functionality for Hugo and Zola static site generators. Additionally, the moderation dashboard has been rebuilt to include user management and image usage leaderboards.

main/views · high confidence

Architecture

Introduce structured modules for routing, content processing, and security

The application's codebase has been reorganized into distinct modules to improve maintainability and separation of concerns. A new \denylist.py\ module centralizes security and validation logic, including disallowed usernames, page slugs, and HTML element allowlists. Content processing is handled by \text\_processing.py\, which manages markdown-to-HTML conversion, syntax highlighting, and text sanitization. Routing is now managed through \urls.py\ with views split into \general\, \moderation\, \api\, and \billing\ submodules. Additionally, \feeds.py\ implements the RSS feed logic, \sitemaps.py\ handles sitemap generation, and \middleware.py\ manages host-based routing and subdomain resolution.

main · high confidence

Behavioural changes

Added placeholder for static directory

A .gitkeep file was added to the static directory to ensure the directory is tracked by version control, preventing it from being ignored or deleted.

static · low confidence

Database schema updates for new and modified models

The database schema has been updated to support new features and refine existing ones. Key changes include the addition of models for images, pages, comments, analytics, and email notifications, alongside numerous field additions and modifications to the User and Post models. Specific updates include enabling blog comments, supporting custom domains and redirects, adding newsletter subscription capabilities, and migrating primary keys to BigAutoField for better scalability.

main/migrations · high confidence

The site's footer and webring components have been extracted into separate, reusable template partials. A new 'delisted' partial was added to display a warning when a blog is removed from search engines. The footer is now split into a generic version for the main site and a blog-specific version that displays a custom note. Additionally, the wering navigation has been isolated into its own partial, allowing for consistent rendering of previous/next links and the webring name across blog pages.

main/templates/partials · medium confidence

Major configuration overhaul and Django 6 beta upgrade in mataroa

The mataroa application has been upgraded to Django v6 beta 1, introducing significant changes to how the application is configured and secured. The settings file has been rewritten to use pathlib for path management and explicit environment variable parsing, replacing the previous dj-database-url dependency. New environment variables control local development mode, signup availability, and canonical host settings. Security middleware is now conditionally applied based on debug and localdev states, and the admin URL path has been changed from 'admin/' to 'dja/'. Email configuration has been updated to use Postmark with TLS, and static file storage has been switched to use ManifestStaticFilesStorage for cache-busting.

mataroa · high confidence

Modernizes development environment with uv and ruff

The project replaces the legacy Python tooling stack with modern alternatives: the \uv\ package manager and lockfile (\uv.lock\) replace \pip\ and \requirements.in\, and \ruff\ replaces \black\, \isort\, and \flake8\ for formatting and linting. The \uwsgi\ web server is removed in favor of \gunicorn\, and the \DOKKU\_SCALE\ and \Procfile\ for Dokku deployment are deleted. Additionally, the \.env.example\ file is replaced by \.envrc.example\ to support \envrc\-based environment variable management, and the \.editorconfig\ is removed.

(repo-wide) · high confidence

Replace Ansible deployment with Bash scripts

The automated server provisioning and deployment workflow has been rewritten from Ansible to a suite of Bash scripts. This change introduces new scripts for provisioning the server, installing dependencies (including Caddy and rclone), setting up the PostgreSQL database, and managing systemd services. It also adds a new \backup-database.sh\ script for automated database backups and introduces a \.envrc.example\ template for environment configuration.

deploy · high confidence

Replace Ansible deployment with native systemd and Caddy templates

The deployment infrastructure has been migrated from Ansible to native systemd service and timer units, alongside a new Caddy web server configuration. This introduces automated background tasks for processing notifications, sending daily moderation summaries, handling exports, and managing premium renewal reminders, all scheduled via systemd timers. Additionally, the Caddyfile template now configures on-demand TLS and reverse proxying, while environment variables for the application and services are explicitly defined in a new mataroa.env template.

deploy/templates · medium confidence

Test coverage

Expanded test coverage for core features

Added comprehensive test suites for analytics, API endpoints, billing, blog indexing, comments, feeds, image management, management commands, and page creation. These tests verify the correct behavior of post and page analytics tracking, API authentication and post creation, Stripe billing integration, blog index and redirection logic, comment creation and approval, RSS feed formatting, image upload and ownership checks, management commands like processnotifications and mail exports, and page CRUD operations.

main/tests · high confidence

Dependencies

Migrate from requirements.txt to pyproject.toml with modern Python tooling

The project has replaced the legacy requirements.txt file with a modern pyproject.toml configuration, shifting from pip-based dependency management to a PEP 621-compliant standard. This change upgrades the Python version requirement to 3.13 and updates core dependencies, including Django to 6.0, Stripe to 13.0.1, and Gunicorn to 23.0. Additionally, the project now uses Ruff for linting and Black for formatting, while removing older tools like flake8, black, and uwsgi.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 43 → 59 (+16.9)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.08.20) — scores are not directly comparable.

Lenses

  • Code Health 94 → 86 (-8.3)
  • Architecture 96 → 100 (+4.4)
  • Maturity 52 → 59 (+6.3)
  • Readiness 19 → 62 (+43.7)
  • Security 59 → 65 (+6.2)
  • Domain Modelling 100 (new)
  • Accessibility 52 (new)

Resolved (47)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • Duplicated block (10 lines × 2) (main/management/commands/devdata.py)
  • Duplicated block (12 lines × 2) (main/tests/test_billing.py)
  • Duplicated block (12 lines × 2) (main/tests/test_blog.py)
  • Duplicated block (14 lines × 2) (main/tests/test_analytics.py)
  • Duplicated block (14 lines × 2) (main/tests/test_api.py)
  • Duplicated block (5 lines × 2) (main/tests/test_comments.py)
  • Duplicated block (5 lines × 6) (main/tests/test_comments.py)
  • Duplicated block (7 lines × 2) (main/tests/test_posts.py)
  • Duplicated block (7 lines × 2) (main/views/general.py)
  • Duplicated block (8 lines × 3) (main/tests/test_comments.py)
  • Duplicated block (8 lines × 3) (main/tests/test_comments.py)
  • High IaC: DS-0002 (Dockerfile)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 27 more

New (154)

  • Command._generate (cognitive 35) (main/management/commands/devdata.py)
  • Command._generate (cyclomatic 19) (main/management/commands/devdata.py)
  • Command.handle (cognitive 16) (main/management/commands/checkstripe.py)
  • Command.handle (cognitive 23) (main/management/commands/mailrenewal.py)
  • Command.handle (cognitive 31) (main/management/commands/processnotifications.py)
  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (main/views/api.py)
  • Duplicated block (10 lines × 2) (main/views/export.py)
  • Duplicated block (10 lines × 2) (main/views/moderation.py)
  • Duplicated block (12 lines × 2) (main/views/general.py)
  • Duplicated block (14 lines × 2) (main/management/commands/mailsummary.py)
  • Duplicated block (14 lines × 2) (main/views/billing.py)
  • Duplicated block (14 lines × 2) (main/views/moderation.py)
  • Duplicated block (16 lines × 2) (main/views/moderation.py)
  • Duplicated block (23 lines × 2) (main/views/api.py)
  • Duplicated block (27 lines × 2) (main/views/api.py)
  • Duplicated block (39 lines × 2) (main/views/moderation.py)
  • Duplicated block (7 lines × 2) (main/views/api.py)
  • Duplicated block (7 lines × 2) (main/views/api.py)
  • …and 134 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

mataroablog/mataroa was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 13 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 059b546ce997611c74c0a431d67600ffd7cfb54f — the exact code this score is about.
  • Scored under rubric-2026.08.20 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using watchdog-codehealth-analyzer rubric-2026.08.20.