Skip to content
CAI
Software that uses CAICheck a score

mermaid-js/mermaid

52.2

Adequate · 29 July 2026

87.3k

lines of production code

TypeScript

with JavaScript

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

How this codebase got here

Score

  • CAI 50 → 52 (+1.9)
  • Rubric changed (rubric-2026.08.17 → rubric-2026.08.18) — scores are not directly comparable.

Lenses

  • Code Health 76 → 76 (+0.3)
  • Architecture 87 → 89 (+2.7)
  • Maturity 71 → 75 (+3.6)
  • Readiness 41 → 41 (+0.1)
  • Security 49 → 57 (+8.0)
  • Domain Modelling 100 → 100 (+0.0)
  • Accessibility 53 → 53 (+0.0)

Resolved (59)

  • Change coupling: iconRounded.ts ↔ iconSquare.ts (packages/mermaid/src/rendering-util/rendering-elements/shapes/iconRounded.ts)
  • Change coupling: theme-base.js ↔ theme-neutral.js (packages/mermaid/src/themes/theme-base.js)
  • Change coupling: theme-dark.js ↔ theme-forest.js (packages/mermaid/src/themes/theme-dark.js)
  • Change coupling: theme-dark.js ↔ theme-neutral.js (packages/mermaid/src/themes/theme-dark.js)
  • Change coupling: theme-default.js ↔ theme-forest.js (packages/mermaid/src/themes/theme-default.js)
  • Change coupling: theme-default.js ↔ theme-neutral.js (packages/mermaid/src/themes/theme-default.js)
  • Change coupling: theme-forest.js ↔ theme-neutral.js (packages/mermaid/src/themes/theme-forest.js)
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Dependency hygiene not measured — no supported dependency manifest was read
  • FileTooLong: dagre/mermaid-graphlib.js (packages/mermaid/src/rendering-util/layout-algorithms/dagre/mermaid-graphlib.js)
  • FileTooLong: er/erRenderer.js (packages/mermaid/src/diagrams/er/erRenderer.js)
  • FileTooLong: rendering-elements/clusters.js (packages/mermaid/src/rendering-util/rendering-elements/clusters.js)
  • FileTooLong: state/shapes.js (packages/mermaid/src/diagrams/state/shapes.js)
  • FileTooLong: timeline/svgDraw.js (packages/mermaid/src/diagrams/timeline/svgDraw.js)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • …and 39 more

New (49)

  • Change coupling clique: theme-base.js, theme-dark.js, theme-default.js, theme-forest.js, theme-neutral.js (packages/mermaid/src/themes/theme-base.js)
  • Change coupling: bandAxis.ts ↔ linearAxis.ts (packages/mermaid/src/diagrams/xychart/chartBuilder/components/axis/bandAxis.ts)
  • Change coupling: bandAxis.ts ↔ orchestrator.ts (packages/mermaid/src/diagrams/xychart/chartBuilder/components/axis/bandAxis.ts)
  • Change coupling: chartTitle.ts ↔ index.ts (packages/mermaid/src/diagrams/xychart/chartBuilder/components/chartTitle.ts)
  • Change coupling: linearAxis.ts ↔ orchestrator.ts (packages/mermaid/src/diagrams/xychart/chartBuilder/components/axis/linearAxis.ts)
  • Change coupling: orchestrator.ts ↔ textDimensionCalculator.ts (packages/mermaid/src/diagrams/xychart/chartBuilder/orchestrator.ts)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • FileTooLong: c4/c4Db.ts (packages/mermaid/src/diagrams/c4/c4Db.ts)
  • FileTooLong: c4/c4Renderer.ts (packages/mermaid/src/diagrams/c4/c4Renderer.ts)
  • FileTooLong: class/classDb.ts (packages/mermaid/src/diagrams/class/classDb.ts)
  • FileTooLong: direction/materializedGeometry.ts (packages/mermaid/src/rendering-util/layout-algorithms/swimlanes/direction/materializedGeometry.ts)
  • FileTooLong: flowchart/flowDb.ts (packages/mermaid/src/diagrams/flowchart/flowDb.ts)
  • FileTooLong: git/gitGraphRenderer.ts (packages/mermaid/src/diagrams/git/gitGraphRenderer.ts)
  • FileTooLong: layout-utils/validateLayout.ts (packages/mermaid/src/rendering-util/layout-algorithms/layout-utils/validateLayout.ts)
  • FileTooLong: orthogonalRouter/router.ts (packages/mermaid/src/rendering-util/layout-algorithms/swimlanes/orthogonalRouter/router.ts)
  • FileTooLong: sequence/sequenceDb.ts (packages/mermaid/src/diagrams/sequence/sequenceDb.ts)
  • FileTooLong: sequence/sequenceRenderer.ts (packages/mermaid/src/diagrams/sequence/sequenceRenderer.ts)
  • FileTooLong: src/render.ts (packages/mermaid-layout-elk/src/render.ts)
  • FileTooLong: wardley/wardleyRenderer.ts (packages/mermaid/src/diagrams/wardley/wardleyRenderer.ts)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • …and 29 more

Changes since last survey

  • 31 commits — 21 feature/other, 10 fixes

By area

  • (repo) — 14 commits
  • .github/workflows — 7 commits
  • (root) — 4 commits
  • packages/mermaid — 2 commits
  • .changeset/revert-pr-7672.md — 1 commit
  • demos/railroad.html — 1 commit
  • docs/syntax — 1 commit
  • packages/parser — 1 commit

Notable commits

  • fix: Merge branch 'develop' into revert-pr-7672
  • fix: Merge branch 'develop' into revert-pr-7672
  • fix: Merge pull request #7948 from aloisklink/ci/revert-CI-scoping
  • fix: Merge pull request #7984 from aloktomarr/fix/architecture-unicode-titles-7961
  • fix: Merge pull request #7985 from Ehtasham-Yasin/bug/7979_railroad-demo-diagram-name
  • fix: Merge pull request #8005 from pbrolin47/revert-pr-7672
  • fix: Revert "Merge pull request #7672 from sjackson0109/fix/4648-directions"
  • fix: [autofix.ci] apply automated fixes
  • fix: fix(architecture): allow non-ASCII characters and punctuation in unquoted titles
  • fix: fix(railroad): correct EBNF demo keywords
  • change: Added changeset
  • change: Merge branch 'develop' into ci/add-ci-argos-full-label
  • change: Merge pull request #7975 from mermaid-js/renovate/npm-dompurify-vulnerability
  • change: Merge pull request #7976 from mermaid-js/renovate/npm-vitest-vulnerability
  • change: Merge pull request #7978 from mermaid-js/renovate/npm-js-yaml-vulnerability
  • change: Merge pull request #7980 from aloisklink/ci/add-ci-argos-full-label
  • change: Merge pull request #7989 from Hashim1999164/docs/replace-directives-with-frontmatter-4756
  • change: Merge pull request #7999 from mermaid-js/renovate/npm-sharp-vulnerability
  • change: Merge pull request #8003 from aloisklink/ci/remove-use-of-pull_request_target-in-validate-lockfile
  • change: chore(deps): update dependency dompurify to v3.4.12 [security]
  • …and 11 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

mermaid-js/mermaid was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 29 July 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 4bc79dd223bd47d445949819951cf46fdaae33ca — the exact code this score is about.
  • Scored under rubric-2026.08.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer latest.