Skip to content
CAI
Software that uses CAICheck a score

mevdschee/php-crud-api

52.1

Adequate · 19 September 2026

35.6k

lines of production code

PHP

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is a PHP-based CRUD API library that provides a single-file interface for performing Create, Read, Update, and Delete operations on relational databases. It supports multiple database engines, including MySQL, PostgreSQL, SQL Server, and SQLite, and exposes data through a PSR-7 compliant HTTP middleware pipeline. The API handles complex data relationships via joins, manages schema introspection, and supports various authentication methods and output formats like JSON and GeoJSON.

How it got here

2015–2018 — PHP-CRUD-API v2 architecture and multi-database support

27 changes.

The project underwent a major v2 release, refactoring the core engine to a PSR-7 middleware architecture and expanding database support to include PostgreSQL, SQL Server, and SQLite. This period introduced comprehensive features such as JWT and database authentication, schema management, OpenAPI documentation, and caching backends, alongside extensive functional testing and client-side integration examples.

2019–2026 — GeoJSON support and release automation

11 changes.

This period focused on expanding spatial data capabilities by introducing GeoJSON support for queries and adding corresponding Leaflet client examples. It also enhanced the project's infrastructure through comprehensive Docker environment updates for multiple Debian versions and implemented automated release and publishing scripts.

Features

Add Auth0 vanilla JavaScript example

Added a new vanilla HTML/JavaScript example in examples/clients/auth0/vanilla.html that demonstrates how to integrate with Auth0. The example handles the OAuth 2.0 implicit flow by checking for an access token in the URL hash, redirecting to the Auth0 authorize endpoint if missing, and making authenticated API requests using the Bearer token in the X-Authorization header.

examples/clients/auth0 · high confidence

Add Debian 11 and Debian 13 Docker environments

New Dockerfiles and initialization scripts are added for Debian 11 (PHP 7.4) and Debian 13 (PHP 8.4). These environments automatically provision and start MariaDB, PostgreSQL (with PostGIS), and SQLite. The Debian 13 variant additionally includes SQL Server 2025 support, while the Debian 11 variant skips SQL Server. Both configurations clone the PHP-CRUD-API repository and execute its test suite upon startup.

docker/debian11 · high confidence

Add Debian 12 Docker environment for PHP-CRUD-API testing

A new Docker build context for Debian 12 has been introduced, providing a containerized environment to run the PHP-CRUD-API test suite. The setup installs PHP 8.2 along with clients and extensions for MariaDB, PostgreSQL (including PostGIS), and SQLite, then automatically initializes these database services and creates the necessary test databases and users before executing the application's test script.

docker/debian12 · high confidence

Add PHP entry point for API initialization

A new entry point file (src/index.php) has been added to initialize the API. It sets up the configuration with database credentials (username, password, database) and handles incoming requests using the Api class, RequestFactory, and ResponseUtils.

src · high confidence

Add examples index page listing client integrations

A new index page at examples/index.html has been added to serve as a navigation hub for the project's example clients. It provides direct links to various frontend integration examples, including VanillaJS, Angular, React, Vue, and others, as well as specific authentication examples for Auth.php and Auth0.

examples · high confidence

Added Firebase authentication example

Added two HTML files in the examples/clients/firebase directory that demonstrate integrating Firebase Authentication with a vanilla JavaScript client. The example includes a login page using FirebaseUI (v4.0.0) to support Google, Facebook, Twitter, GitHub, Email, Phone, and Anonymous providers, and a success page that retrieves a JWT access token to call a backend API endpoint.

examples/clients/firebase · high confidence

Added PHP CRUD API core script

A new \extras/core.php\ file has been added, providing a basic PHP script that handles HTTP requests (GET, POST, PUT, DELETE) to perform CRUD operations on a MySQL database. The script connects to a local MySQL instance, parses the request method and path to determine the table and key, escapes input values to prevent SQL injection, and executes the corresponding SQL query, returning results in JSON format or affected row counts.

extras · high confidence

Added release automation scripts for versioning and Docker publishing

New scripts have been added to automate the project's release workflow. The \release.sh\ script handles version bumping (major, minor, or build increments), updates dependencies, compiles the single-file distribution, and creates a GitHub release with the compiled assets attached. The \publish-docker.sh\ script builds and pushes the latest release as a Docker image to Docker Hub. These scripts require the GitHub CLI and Docker to be installed and authenticated.

scripts · high confidence

Added vanilla HTML authentication example

A new vanilla HTML client example (vanilla.html) has been added to the examples/clients/auth.php directory. This standalone page demonstrates the OAuth 2.0 implicit flow by extracting an access token from the URL hash, storing it in the X-Authorization header, and fetching a specific API record (post ID 1 with joined categories, tags, and comments) from api.php.

examples/clients/auth.php · high confidence

Added vanilla JavaScript upload example

A new standalone HTML example has been added to the upload client examples that demonstrates file uploading using vanilla JavaScript and the HTML5 File API. The example allows users to select a PNG image, preview it in the browser, and upload it to the server via a POST request to the records API, while also listing existing categories on page load.

examples/clients/upload · high confidence

Custom controllers and OpenAPI builders can now receive their own configuration settings

Custom controllers and custom OpenAPI builders can now be configured with specific settings via the config system. The Config class now supports keys prefixed with the short name of a custom class (e.g., \MyController.someKey\), allowing these components to access their own configuration parameters through a new \CustomSettings\ helper class. This isolates custom component settings from the main API configuration and prevents conflicts when multiple custom classes share the same short name.

src/Tqdev/PhpCrudApi/Config · high confidence

Initial GeoJSON support for spatial data queries

Added a new GeoJSON module that allows users to query database tables containing geometry columns and receive results in standard GeoJSON format. The implementation includes classes for representing GeoJSON Features, FeatureCollections, and Geometry objects (parsing WKT to GeoJSON coordinates), along with a service that handles listing and reading records. This service supports filtering by bounding box and vector tiles, enabling integration with mapping clients that expect GeoJSON input.

src/Tqdev/PhpCrudApi/GeoJson · high confidence

Introduce structured database reflection model for tables and columns

The API now uses a new set of reflection classes (ReflectedColumn, ReflectedTable, ReflectedDatabase) to model database schema metadata. This change enables the system to distinguish between table aliases and real database names, correctly parse column types including length, precision, and scale, and identify primary and foreign keys. Notably, it adds support for views by inferring primary keys and foreign keys based on naming conventions (e.g., columns ending in '\_id'), allowing views to be treated as queryable resources with proper relationship metadata.

src/Tqdev/PhpCrudApi/Column/Reflection · high confidence

Introduces abstract base middleware class for PSR-15 compliance

A new abstract Middleware class has been added to the Base middleware package, implementing the PSR-15 MiddlewareInterface. This class provides a standardized foundation for middleware components by handling dependency injection for the router, responder, and configuration interface, and offering protected helper methods (getArrayProperty, getMapProperty, getProperty) to simplify accessing configuration values specific to each middleware instance.

src/Tqdev/PhpCrudApi/Middleware/Base · high confidence

New API endpoints for cache management, schema introspection, GeoJSON, and OpenAPI

This change introduces several new controller endpoints in the API. Users can now clear the cache via a new /cache/clear endpoint, manage database schema (tables and columns) through /columns endpoints, and retrieve OpenAPI specifications via /openapi. Additionally, GeoJSON data can be fetched using /geojson endpoints, and the /status/ping endpoint now reports both database and cache connectivity status.

src/Tqdev/PhpCrudApi/Controller · high confidence

New Docker build and run automation scripts

Added shell scripts to streamline Docker operations for the php-crud-api project. build\_all.sh automates building images for all subdirectories using buildx, while run.sh and run\_all.sh provide interactive and batch modes to run containers with the local source directory mounted. A new clean\_all.sh script allows users to remove all existing containers and images in one step.

docker · high confidence

New Leaflet examples for GeoJSON and GeoJSON tile layers

Added example files in the Leaflet client directory that demonstrate how to use custom GeoJSON and GeoJSON tile layers. The new \geojson-layer.js\ and \geojson-tile-layer.js\ scripts provide \L.GeoJSONLayer\ and \L.GeoJSONTileLayer\ classes, which fetch GeoJSON data from a URL and render it on a Leaflet map. The \vanilla.html\ example shows how to integrate these layers with a standard Leaflet map instance, including configuration for zoom levels and URL templates for bounding box and tile coordinates.

examples/clients/leaflet · high confidence

New OpenAPI 3.0 specification generation for all API endpoints

The API now automatically generates a comprehensive OpenAPI 3.0 document that describes all enabled controllers (records, columns, geojson, cache, status, and dbAuth) and their operations. This document includes detailed schemas for request and response bodies, component parameters (such as filters, pagination, and format options), security schemes derived from active middlewares (basic, JWT, API key, dbAuth), and standardized error responses. The generated specification is served via the /openapi endpoint and supports XML content negotiation when the format parameter is enabled.

src/Tqdev/PhpCrudApi/OpenApi · high confidence

New cache backend implementations and factory

The cache subsystem now includes concrete implementations for Redis, Memcache, Memcached, and temporary file storage, accessible via a new CacheFactory. This allows users to configure the API to use external caching services or local file-based caching instead of the previous default behavior, with specific configuration options for connection addresses and ports for each backend type.

src/Tqdev/PhpCrudApi/Cache · high confidence

New client-side example applications for various JavaScript frameworks

Added a collection of standalone HTML examples in the examples/clients directory demonstrating how to interact with the API using popular JavaScript libraries and frameworks, including Angular (1.x and 2), Vue.js, React, Knockout, Handlebars, Mustache, Zepto, and vanilla JavaScript. These examples provide ready-to-use templates for common CRUD operations and data binding patterns.

examples/clients · high confidence

New middleware components for authentication, authorization, and request handling

This update introduces a comprehensive suite of new middleware classes to the PhpCrudApi request pipeline. Authentication is expanded with DbAuthMiddleware (handling login, registration, and password changes against a database table), ApiKeyAuthMiddleware (validating API keys from headers), and JwtAuthMiddleware (verifying JWT tokens with configurable algorithms and claims). Authorization is now handled by AuthorizationMiddleware, which allows custom handlers to restrict table access, column visibility, and record filters. Additional request-handling middleware includes CorsMiddleware (improved CORS support with exception handling), FirewallMiddleware (IP allowlisting with CIDR support), IpAddressMiddleware (automatically populating IP address fields on create), JoinLimitsMiddleware (limiting join depth and table count), PageLimitsMiddleware (enforcing pagination caps), JsonMiddleware (converting JSON fields in requests/responses), CustomizationMiddleware (pre/post request hooks), and AjaxOnlyMiddleware (restricting access to AJAX requests). A new VariableStore class facilitates data sharing between middleware components.

src/Tqdev/PhpCrudApi/Middleware · high confidence

New schema management services for table and column definitions

The API now includes DefinitionService and ReflectionService classes in the Column namespace to handle database schema operations. DefinitionService allows users to programmatically add, remove, and update tables and columns, including managing primary keys, foreign keys, and column types (name, length, precision, scale, nullable). ReflectionService provides a cached reflection of the database structure, enabling efficient retrieval of table metadata and supporting cache refresh mechanisms for schema changes.

src/Tqdev/PhpCrudApi/Column · high confidence

PHP-CRUD-API v2 release with multi-database support and PSR-7 architecture

The project has been rebranded from 'mysql-read-api' to 'PHP-CRUD-API' and upgraded to version 2, introducing support for PostgreSQL, SQL Server, and SQLite alongside MySQL. The internal architecture has been refactored to use PSR-7 interfaces and a middleware pipeline, replacing the previous monolithic structure. This release includes a new single-file distribution (\api.php\) generated by a build script, Docker support for local development, and a comprehensive test suite. The API now serves as the reference implementation for TreeQL in PHP.

(repo-wide) · high confidence

Behavioural changes

Database layer refactored for multi-driver support and improved data handling

The database abstraction in src/Tqdev/PhpCrudApi/Database has been rewritten to support MySQL, PostgreSQL, SQL Server, and SQLite with driver-specific SQL generation. This introduces a new ColumnConverter for handling boolean, binary, and geometry types across drivers, a ColumnsBuilder for generating LIMIT/OFFSET, ORDER BY, and INSERT/UPDATE statements, and a ConditionsBuilder that fixes LIKE filter escaping for SQLite and SQL Server. A new LazyPdo class implements lazy connection initialization, while GenericDB now uses persistent connections for MySQL and PostgreSQL and adds TrustServerCertificate=true for SQL Server. Data conversion is now handled by DataConverter for proper type casting and base64 encoding, and GenericReflection provides unified schema introspection across all supported databases.

src/Tqdev/PhpCrudApi/Database · high confidence

Introduce structured document classes for API responses and errors

The API now uses dedicated \ErrorDocument\ and \ListDocument\ classes to format its JSON output. \ErrorDocument\ standardizes error responses by mapping specific PDO exceptions (such as duplicate keys or data integrity violations) to appropriate error codes and messages, while \ListDocument\ structures list results into a consistent 'records' and 'results' format. This change ensures that API consumers receive predictable, structured data for both successful list queries and error conditions.

src/Tqdev/PhpCrudApi/Record/Document · high confidence

PhpCrudApi v2 core API engine and PSR-7 integration

The library introduces a new v2 API engine (src/Tqdev/PhpCrudApi/Api.php) that replaces the previous implementation with a PSR-7 compliant architecture. This change brings a comprehensive middleware pipeline supporting authentication (JWT, Basic, API Key, DB, WP), security (CORS, SSL Redirect, Firewall, XSRF, IP Address), and data handling (JSON, XML, CSV, GeoJSON, Validation, Sanitation). The core now utilizes a configurable router and responder system, allowing for custom controllers and OpenAPI documentation generation, while utility classes (RequestFactory, ResponseFactory) handle PSR-7 request/response creation and output.

src/Tqdev/PhpCrudApi · high confidence

The record condition logic has been refactored to introduce a dedicated \RelatedCondition\ class, enabling filters on related (joined/child) tables. This change allows the API to render filters as correlated 'EXISTS' sub-queries, ensuring that pagination and record counts remain accurate on the outer table when filtering by related data. The refactoring also includes new classes for logical combinations (\AndCondition\, \OrCondition\, \NotCondition\) and base condition types (\ColumnCondition\, \SpatialCondition\, \NoCondition\), replacing the previous monolithic implementation with a more modular structure.

src/Tqdev/PhpCrudApi/Record/Condition · high confidence

Refactored record handling to support joins, filters, and pagination

The record layer has been restructured into a new service-oriented architecture (RecordService) that replaces the previous implementation. This change introduces dedicated components for managing column inclusion/exclusion (ColumnIncluder), complex filtering with support for related-table conditions (FilterInfo), ordering, and pagination (PaginationInfo). It also adds a new RelationJoiner to handle belongs-to, has-many, and has-and-belongs-to-many relationships, allowing API responses to include nested related data. Additionally, a centralized ErrorCode class standardizes error messages and HTTP status codes across the API.

src/Tqdev/PhpCrudApi/Record · high confidence

Router refactored to use PSR-7 interfaces and improved base path detection

The routing middleware has been rewritten to implement PSR-7 interfaces (ServerRequestInterface, ResponseInterface), replacing the previous request handling mechanism. This change introduces a new Router interface and a SimpleRouter implementation that better supports base path detection by utilizing PATH\_INFO and REQUEST\_URI, ensuring correct route matching when the API is mounted under a sub-path. The router now also caches the route tree for performance and handles exceptions during route execution by returning a standardized error response.

src/Tqdev/PhpCrudApi/Middleware/Router · high confidence

Test coverage

Added PHPStan stubs for WordPress functions; Added SQL test fixtures for MySQL, PostgreSQL, SQLite, and SQL Server; Added functional tests for authentication and cache clearing; Added functional tests for custom controller endpoints; Added functional tests for database column schema operations; Added functional tests for the OpenAPI endpoint; Added functional tests for the records API; Added test configuration files for database drivers and custom components.

Dependencies

Initial Composer dependency configuration for PHP CRUD API

The project now includes a \composer.json\ manifest and a \composer.lock\ file to manage dependencies. This configuration requires PHP 7.2 or higher and introduces PSR-7/PSR-17 HTTP message implementations via the \nyholm/psr7\ and \nyholm/psr7-server\ libraries, alongside standard PSR interfaces. It also adds \phpstan/phpstan\ as a development dependency for static analysis.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 52.

Lenses

  • Code Health 77
  • Architecture 66
  • Maturity 56
  • Readiness 39
  • Security 85

Changes since last survey

  • 300 commits — 250 feature/other, 50 fixes

By area

  • (root) — 195 commits
  • src/Tqdev — 44 commits
  • (repo) — 37 commits
  • tests/fixtures — 5 commits
  • docker/debian12 — 3 commits
  • docker/rockylinux8 — 3 commits
  • docker/ubuntu20 — 3 commits
  • tests/functional — 3 commits
  • docker/centos8 — 2 commits
  • docker/build_all.sh — 1 commit
  • docker/debian11 — 1 commit
  • docker/ubuntu22 — 1 commit
  • docker/ubuntu24 — 1 commit
  • tests/config — 1 commit

Notable commits

  • fix: fix for #842
  • fix: Compatibility fix
  • fix: Fix alias support in test
  • fix: Fix for #806
  • fix: Fix for #822
  • fix: Fix for #850
  • fix: Fix for #881
  • fix: Fix for #922
  • fix: Merge pull request #1077 from PingouinFerreux/fix/star-history-chart
  • fix: fix LIKE filter escaping for sqlite and sql server
  • fix: fix docker warning
  • fix: fix for #1028
  • fix: fix for #1028
  • fix: fix for #789
  • fix: fix for #794
  • fix: fix for #794
  • fix: fix for #794
  • fix: fix for #794
  • fix: fix for #817
  • fix: fix for #837
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

mevdschee/php-crud-api was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 399a398749ab687a68286260023bd73d79da5f26 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.