MiniProfiler/rack-mini-profiler
55.6
Adequate · 28 September 2026
3.9k
lines of production code
Ruby
with JavaScript
2
measurements over time
What this system is
This system is a Ruby-based performance profiling library that instruments web requests to capture detailed timing metrics for controllers, views, and database queries. It provides a modular architecture with support for multiple storage backends, including file-based persistence, and offers a browser-side UI for visualizing flamegraphs and SQL execution details. The tool is designed to integrate with Rails and various database adapters, allowing developers to diagnose bottlenecks through comprehensive request tracing and memory profiling.
How it got here
2012 — Version 5.0.0 major refactor
13 changes.
This period centered on the release of version 5.0.0, which involved a major architectural refactor to drop legacy code, raise the minimum Ruby version to 3.2, and remove jQuery dependencies. The work introduced opt-in patching, a new file-based storage backend, and enhanced SQL profiling with bind parameter recording, alongside comprehensive updates to the test suite and UI assets.
2014–2016 — Timer struct refactoring and instrumentation expansion
6 changes.
The codebase underwent a significant refactoring of internal timing structures into a modular class hierarchy to improve maintainability and separation of concerns. This period also saw the expansion of profiling capabilities through new instrumentation patches for various database and search engine drivers, alongside the introduction of a dedicated Page timer struct for SQL metrics. Comprehensive test coverage was added for the core library components, storage backends, and the new timer structures to ensure reliability.
2017–2023 — profiler instrumentation and compatibility fixes
5 changes.
This period focused on enhancing SQL profiling capabilities by updating PostgreSQL patches to record bound parameters and fixing MySQL2 instrumentation for Rails 5+ compatibility. The work also included upgrading the embedded speedscope library for better flamegraph visualization and deprecating the old rack\_profiler generator in favor of rack\_mini\_profiler.
Features
Add sample application entry point and performance snapshot data
The website now includes a basic Rack configuration file (config.ru) to run the sample application, alongside a data.json file containing a detailed performance snapshot of a request to the Discourse welcome topic. This snapshot includes timing breakdowns for network, rendering, and database queries, providing a baseline for performance analysis and debugging within the sample environment.
website · high confidence
Added Rack application configuration for testing
A new \config.ru\ file has been added to the \test\_old\ directory to serve as the entry point for running the Rack::MiniProfiler test application. This configuration sets up a basic Rack app that connects to a local MySQL database, performs simulated sleep operations and database queries, and runs the MiniProfiler middleware to demonstrate its functionality on localhost:8080.
_test\old · high confidence
Introduces Page timer struct with SQL metrics and serialization support
The \lib/mini\_profiler/timer\_struct/page.rb\ file is added, defining a new \Page\ timer struct that initializes with both wall-clock and monotonic timestamps. This struct introduces specific tracking for SQL performance, including \sql\_count\, \cached\_sql\_count\, and \duration\_milliseconds\_in\_sql\, and provides \as\_json\ methods to ensure compatibility with the Oj serialization library.
rack-mini-profiler · high confidence
New database and search engine instrumentation patches
Added new profiling patches for a wide range of data stores and search engines, including ActiveRecord, MySQL2, PostgreSQL, Oracle Enhanced, MongoDB (Mongoid 3 and 5), MongoMapper (Plucky), Neo4j, NoBrainer (RethinkDB), Riak, RSolr, and Sequel. These patches instrument the respective libraries to capture SQL and query execution times, allowing users to see performance metrics for these specific database drivers in the Mini Profiler results.
lib/patches/db · high confidence
New file-based storage backend for Mini Profiler
A new FileStore implementation is introduced, allowing profiling results to be persisted to the local filesystem instead of relying solely on in-memory storage. This addresses the inconsistency of the previous MemoryStore and provides a durable, disk-backed option for storing profiler data, including snapshots and view tracking, with configurable expiration and automatic cleanup.
_lib/mini\profiler/storage · high confidence
Removals
Removal of legacy Rack MiniProfiler middleware
The legacy \Rack::MiniProfiler\ middleware implementation in \lib/profiler/profiler.rb\ has been removed. This file contained a basic, largely unimplemented profiler that only measured total request time via \Benchmark.measure\ without actually appending results to the response body or supporting sub-profiles. Its removal indicates that the profiler functionality has been refactored or replaced by a more complete implementation elsewhere in the codebase.
lib/profiler · high confidence
Behavioural changes
Deprecate rack\_profiler generator in favor of rack\_mini\_profiler
The \rack\_profiler:install\ generator is now deprecated and issues a warning directing users to use \rack\_mini\_profiler:install\ instead. A new \rack\_mini\_profiler:install\ generator has been added to generate an initializer that requires and initializes rack-mini-profiler in development mode, while the old generator now delegates to the new one to maintain backward compatibility.
lib/generators · high confidence
Optional Net::HTTP and SQL patching with configurable backends
The library now supports optional patching of Net::HTTP requests, controlled by the RACK\_MINI\_PROFILER\_PATCH\_NET\_HTTP environment variable (defaulting to enabled), and allows users to selectively enable or disable specific database patches via the RACK\_MINI\_PROFILER\_PATCH environment variable. The SQL patching logic has been refactored to support a wider range of database adapters, including Oracle Enhanced, Sequel, and various MongoDB drivers, while ensuring that patches are only applied when the corresponding libraries are present and Rails patching is enabled.
lib/patches · high confidence
PostgreSQL patch now supports parameter binding recording
The PostgreSQL instrumentation patch has been updated to record bind parameters alongside SQL statements. The new \prepend.rb\ implementation (and the legacy \alias\_method.rb\) now passes bound arguments to \Rack::MiniProfiler.binds\_to\_params\ when recording SQL via \exec\, \exec\_params\, \exec\_prepared\, \send\_query\_prepared\, and \async\_exec\. This ensures that profiling data for prepared statements and parameterized queries includes the actual parameter values, improving visibility into query execution details.
lib/patches/db/pg · high confidence
Precompiled JavaScript templates and updated UI assets
The profiler UI now uses precompiled JavaScript templates (via doT) instead of loading and compiling them at runtime, which improves performance and ensures compatibility with strict Content Security Policies. The UI assets have been updated to include the \dot.1.1.2.min.js\ library, and the CSS has been migrated from Less to Sass (with \includes.scss\ as the source and \includes.css\ as the compiled output). The JavaScript logic (\includes.js\) has been refactored to remove jQuery dependencies, using native Fetch API and modern JavaScript features, while adding support for Hotwire Turbo Drive and improved localStorage handling for Safari.
lib/html · high confidence
Rack::MiniProfiler upgraded to version 5.0.0 with significant architectural and feature changes
The library has been refactored into a modular structure with dedicated files for actions, client settings, configuration, and storage, moving from a monolithic implementation. Key user-facing changes include the introduction of a Snapshots feature with an asynchronous transporter that supports gzip compression and exponential backoff for reliability, and enhanced memory profiling capabilities via a new GCProfiler class that provides detailed ObjectSpace analysis. The UI now supports Hotwire Turbo Drive, allows configuring the HTML container for injection, and offers better Content Security Policy (CSP) nonce support for scripts and styles. Additionally, the authorization mode \:whitelist\ is deprecated in favor of \:allow\_authorized\, and the gem now ensures compatibility with Rack 2.x and 3.x while removing the jQuery dependency.
_lib/mini\profiler · high confidence
Rails integration now uses ActiveSupport notifications and file storage by default
The Rails railtie has been refactored to use ActiveSupport notifications for profiling instead of patching Rails methods, providing more accurate timing for controllers, views, and Active Record queries (including instantiation counts). It also switches the default storage backend from memory to a file store to improve consistency, configures automatic skipping of asset paths, and disables compression for profiled requests to ensure accurate data capture.
_lib/mini\_profiler\rails · high confidence
Rails patches are now opt-in and disabled by default
The library now requires explicit configuration to enable Rails-specific patches, which are turned off by default to prevent conflicts with other gems. Users must now create a \lib/enable\_rails\_patches.rb\ file containing \module Rack; MINI\_PROFILER\_ENABLE\_RAILS\_PATCHES = true; end\ to activate these patches. Additionally, separate opt-in files (\lib/prepend\_mysql2\_patch.rb\, \lib/prepend\_pg\_patch.rb\, \lib/prepend\_net\_http\_patch.rb\) are provided to enable specific database and network profiling patches, giving users finer control over which internal patches are applied.
lib · high confidence
Refactored timing structures into a modular class hierarchy
The internal timing data structures have been reorganized from a single monolithic file into distinct classes (\Base\, \Client\, \Custom\, \Request\, \Sql\) within the \lib/mini\_profiler/timer\_struct\ directory. This refactoring introduces a \Base\ class to handle common attribute storage and JSON serialization, while specific timer types now encapsulate their own logic: \Request\ manages the hierarchical tree of child timings and SQL tracking, \Sql\ handles query details and stack traces, \Custom\ supports external API/cache timing, and \Client\ processes browser-side performance data. This change improves code maintainability and separation of concerns without altering the external profiling API.
_lib/mini\_profiler/timer\struct · high confidence
Upgrade speedscope to version 1.16
The embedded speedscope library has been upgraded to version 1.16. This update includes new assets and JavaScript modules (such as demangle-cpp) to support flamegraph visualization, and ensures the tool works offline by using local font files instead of loading them from Google Fonts.
lib/html/speedscope · high confidence
Version 5.0.0: Ruby 3.2+ requirement and PostgreSQL bind parameter recording
This release raises the minimum supported Ruby version to 3.2.0, dropping support for earlier versions. It introduces the ability to record bind parameters for parameterized and prepared PostgreSQL queries, enhancing SQL visibility in the profiler. Additionally, it includes fixes for CSP nonce support in flamegraph rendering, handling of simple Active Record bind parameters, and prevents asset requests from clearing profiler authorization.
(repo-wide) · high confidence
Fixes
Fixes MySQL2 instrumentation compatibility with Rails 5+
Added Ruby patches for the mysql2 gem to ensure proper SQL profiling instrumentation. The changes introduce two implementation strategies (alias\_method and prepend) for Mysql2::Result and Mysql2::Client classes, allowing the application to correctly measure query execution times and reader durations without double-instrumenting, thereby fixing compatibility issues with Rails 5 and later versions.
lib/patches/db/mysql2 · high confidence
Test coverage
Added integration tests for SQL profiling, middleware behavior, and snapshot storage; Added spec helper with RSpec 3 configuration and time-travel support; Added test coverage for TimerStruct components; Added test coverage for core library components; Added test coverage for storage backends and snapshot logic; Removed legacy Test::Unit test suite.
Dependencies
Update gemspec and add Gemfiles for modern Ruby and Rails support
The gemspec now requires Ruby 3.2.0 or higher and declares runtime dependencies on Rack (\>= 1.2.0) and development dependencies including RSpec (\~\> 3.12.0), Rails (\>= 7.1), and sassc. New Gemfiles have been added for the project root and the website directory to manage these dependencies, with the root Gemfile enforcing the Ruby version constraint and the website Gemfile pinning the local gem path.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 69 → 56 (-13.1)
- Rubric changed (rubric-2026.09.8 → rubric-2026.09.16) — scores are not directly comparable.
Lenses
- Code Health 86 → 86 (+0.0)
- Architecture 100 → 99 (-1.0)
- Maturity 53 → 53 (+0.0)
- Readiness 76 → 59 (-17.7)
- Security 92 → 92 (+0.1)
- Accessibility 46 (new)
Resolved (3)
- Documentation: no installation or build instructions (README.md)
- Hotspot: lib/mini_profiler_rails/railtie.rb (lib/mini_profiler_rails/railtie.rb)
- Off-boarding risk: anonymized user #1
New (8)
- Duplicate Type Definition: Two distinct top-level namespaces (RackMiniProfiler and RackProfiler) define identical InstallGenerator classes with the same method signature. This suggests a naming conflict or legacy aliasing issue where the same functionality is exposed under two different module paths.
- Inconsistent Accessor Pattern: While Ruby typically handles attr_accessor automatically, the explicit listing of both getter and setter as separate methods in the API surface, alongside other properties listed only as Properties (e.g., Config.auto_inject), creates visual inconsistency. However, this is likely an artifact of the API dump format rather than a code inconsistency. A more significant issue is the mix of Property and Method for what are effectively simple getters/setters.
- Inconsistent Configuration Exposure: Configuration options related to snapshots (snapshots_redact_sql_queries, snapshots_transport_destination_url, etc.) are exposed on the main Config object, while other snapshot-related behaviors (like buffering) are exposed on SnapshotsTransporter. This splits the configuration surface for a single feature (Snapshots) across two different types, making it harder for users to find all snapshot-related settings.
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- No ADRs found
- Off-boarding risk: anonymized user #1
- Redundant Operations: transport and ship appear to perform the same core action of sending a snapshot to the destination. ship is likely an internal alias or a specific implementation detail exposed publicly, leading to confusion about which method to use.
Architecture
- Unchanged — 0 containers · 1 contexts · 0 edges
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
MiniProfiler/rack-mini-profiler was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit d95511f0b5fe0ae6d326c6ce7071157d829b9447 — the exact code this score is about.
- Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-2d9048c36d26.