Skip to content
CAI
Software that uses CAICheck a score

mssun/passforios

54.7

Adequate · 1 October 2026

8.7k

lines of production code

Swift

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a secure iOS password management application that stores and manages credentials using Git-backed repositories and PGP encryption. It provides core functionality for viewing, generating, and syncing passwords, while supporting hardware-backed decryption via YubiKey and biometric authentication. The app extends its utility through iOS extensions for system-wide autofill in native apps and web browsers, along with Siri shortcuts for repository synchronization.

How it got here

2017 — Architecture modernization and security hardening

18 changes.

The project underwent a significant architectural overhaul, migrating from CocoaPods to Swift Package Manager and introducing the passKit framework to centralize logic. Security was enhanced through the implementation of a passcode lock, YubiKey NFC support, and Keychain-based credential management, while the UI was modernized to align with iOS 17 standards.

2018–2019 — Autofill, security, and testing expansion

16 changes.

This period focused on integrating iOS system features, specifically implementing a Pass AutoFill extension and Siri shortcuts for repository synchronization. The codebase underwent significant architectural improvements, including a refactor of the OTP parsing infrastructure and a migration to the GopenPGP encryption backend with a fallback mechanism. These functional additions were supported by extensive unit test coverage across the parser, crypto, and keychain components to ensure stability.

2020–2026 — iOS integration and security enhancements

16 changes.

This period focused on deepening iOS integration by adding Siri shortcut support, rewriting the AutoFill extension for credential suggestions, and automating the build of the GopenPGP crypto library. Significant architectural refactoring centralized extension constants and password management services, while introducing YubiKey decryption support and improving QR code scanning reliability. The work was complemented by comprehensive test coverage for persistence and scanning logic, along with the addition of Italian localization.

Features

Add Siri shortcut to sync password repository

Users can now trigger a repository sync via Siri or the Shortcuts app. This new passShortcuts extension registers the SyncRepositoryIntent, which performs a pull followed by a push if there are local commits. The implementation respects device security by restricting the shortcut when the device is locked or protected data is unavailable, and it requires the passphrase to be stored in the keychain to execute successfully.

passShortcuts · high confidence

Add customizable password generator with random and XKCD modes

The passKit/Passwords module now includes a new PasswordGenerator that supports two generation flavors: 'Random' (configurable length, character sets, and group separators) and 'XKCD' (word-based passphrases). Users can customize options such as length, case variation, digit/symbol inclusion, and group count, with enforced length limits specific to each flavor (4–64 for random, 2–5 for XKCD).

passKit/Passwords · high confidence

Added German language support

The app now supports the German language. This change adds the necessary localization files (InfoPlist, Intents, Localizable, Main) to translate UI elements, system permission descriptions, and error messages for German-speaking users.

pass/de.lproj · high confidence

Added Pass AutoFill extension for iOS credential provider

The app now includes a new AutoFill extension that allows users to automatically fill passwords and credentials into other apps. This extension is configured with the necessary entitlements for authentication services and keychain access, supports Face ID for unlocking, and provides a storyboard-based interface for selecting passwords. Separate entitlements are provided for both the main app and a beta distribution channel.

passAutoFillExtension · high confidence

Added Siri shortcut to sync password repository

The app now supports a Siri shortcut that allows users to sync their password repository with the remote server via voice commands or automation tasks. This is implemented through a new Intents definition file that defines the 'Sync Repository' action, including user-facing titles, descriptions, and response messages for success, failure, and various error states (such as missing passphrase or repository). Additionally, usage descriptions for Camera and Face ID permissions have been added to the app's InfoPlist strings.

pass/en.lproj · high confidence

Automated iOS framework build for GopenPGP v2.10.0

A new build script, scripts/gopenpgp\_build.sh, has been added to automate the compilation of the GopenPGP library into an iOS xcframework. This script fetches the specific v2.10.0-passforios branch of the ProtonMail GopenPGP repository, initializes gomobile, and builds the crypto, armor, constants, models, subtle, and helper packages for iOS 13.0+, outputting the resulting Gopenpgp.xcframework to the go/dist directory.

scripts · high confidence

Initial project structure and configuration

This change establishes the foundational configuration for the project, introducing standardized code formatting and linting via \.swiftformat\ and \.swiftlint.yml\ files, setting the Swift version to 5.8 in \.swift-version\, and defining the MIT license in \LICENSE\. It also updates the repository metadata with \.mailmap\ for author normalization, configures the Jekyll site theme in \\_config.yml\, and adjusts \.gitignore\ to exclude build artifacts and dependency folders like \Pods/\ and \go/\.

(repo-wide) · high confidence

Introduce new settings and repository information views

The app now includes dedicated UI screens for managing repository details and advanced configuration. The 'About Repository' view displays key store metrics such as password count, repository size, local commit count, and last sync time, with automatic updates when the store changes. The 'Advanced Settings' screen adds controls for enabling ASCII-armored encryption, configuring git signatures, and options to erase the password store or discard all local changes. Additionally, the 'General Settings' view consolidates privacy and display preferences, including toggles to hide unknown fields, hide OTP fields, auto-copy OTPs, hide password images, and show folder paths.

pass/Controllers · high confidence

Introduce self-maintained passcode lock and CoreData persistence

The app now includes a custom passcode lock mechanism (PasscodeLockPresenter and PasscodeLockViewController) that overlays the main window to require authentication before accessing content. This lock supports biometric authentication (Face ID/Touch ID) via LocalAuthentication, allows cancellation, and provides a 'Forgot Passcode' option that can reset the password store if the device passcode is set. Additionally, a new PersistenceController manages CoreData storage for the 'pass' model, handling store initialization, migration settings, and reinitialization on error.

passKit/Controllers · high confidence

Introduce structured error handling and YubiKey support in passKit

The passKit helper layer now includes a comprehensive AppError enum with localized descriptions for repository, PGP, and YubiKey operations, replacing ad-hoc error handling. It adds a KeyStore protocol and AppKeychain implementation to securely store PGP and SSH keys in the device-only Keychain, removing reliance on file-based storage. Additionally, YubiKit integration is introduced via YubiKeyConnection and YubiKeyAPDU helpers, enabling decryption via NFC, USB-C, or MFI accessories, while a new NotificationCenterDispatcher manages OTP push notifications with an optional auto-copy feature.

passKit/Helpers · high confidence

Introduction of passKit framework

A new passKit framework has been added to the project, exposing a public header (passKit.h) that imports ObjectiveCExceptionCatcher and exports version symbols. The framework bundle is configured via Info.plist with a package type of FMWK, establishing the structural foundation for this library component.

passKit · high confidence

Italian language support added

The app now includes a complete Italian localization, making the interface accessible to Italian-speaking users. This update adds Italian translations for all user-facing strings, including UI labels, settings, error messages, and PGP/Git synchronization notifications, as well as proper pluralization rules for Italian grammar.

pass/it.lproj · high confidence

New AutoFill extension interface with navigation and selection protocol

The passAutoFillExtension now includes a new MainInterface.storyboard that establishes a CredentialProviderViewController embedding a UINavigationController, which serves as the root for the SearchPassword view controller. Additionally, a PasswordSelectionDelegate protocol is introduced to handle password selection events, enabling the extension to communicate selected credentials back to the host application.

passAutoFillExtension/Base.lproj · high confidence

New pass extension controller and credential provider

The pass extension now uses a dedicated ExtensionViewController to manage the UI and a CredentialProvider service to handle credential delivery. The controller determines whether the extension is invoked for browser autofill or login lookup, extracts search context from attachments, and presents a passcode lock before showing the password list. Upon selection, the credential provider decrypts the password and either returns the username and password (and optional TOTP) via a property list for login actions, or copies the password to the clipboard and returns a dictionary for JavaScript-based browser autofill, while also triggering an OTP notification after decryption.

passExtension/Controllers · high confidence

New utility extensions and YubiKey decryption support in passKit

This update adds several new Swift extensions to the passKit library to improve code reuse and add hardware-backed decryption capabilities. It introduces \Array+Slices\ for splitting arrays, \Data+Mutable\ to facilitate Gomobile interoperability, and various \String\ extensions for localization, trimming, URL encoding, and newline splitting. UI helpers are added for \UIAlertAction\ (including shortcuts for navigation and key selection), \UIAlertController\ (for confirmation and error alerts), \UITextField\ (for input field chaining and shake animations), \UIViewController\ (for return-key navigation), and \UIView\ (for safe-area layout anchors). Additionally, \YKFSmartCardInterfaceExtension\ implements the logic to select the OpenPGP application, verify passwords, retrieve decryption algorithm details, and perform RSA deciphering on YubiKey devices.

passKit/Extensions · high confidence

Pass extension now supports autofill for login credentials

The passExtension now includes a JavaScript preprocessing script (passProcessor.js) that enables the extension to automatically fill username and password fields on web pages. The script detects password and email/text input elements, sets their values, and dispatches 'input' and 'change' events to ensure compatibility with modern web forms and autofill systems in Safari and Chrome. This functionality is configured via the NSExtensionJavaScriptPreprocessingFile key in Info.plist and is supported by specific entitlements for keychain access and application groups for both the main and beta extension targets.

passExtension · high confidence

Behavioural changes

3 commits (0 fixes) modifying icon

A change to existing behaviour in icon — 3 commits, 5 files.

icon · medium confidence · unverified

App restructured with passcode lock, NFC support, and modern iOS lifecycle

The app has been significantly restructured: the old git repository management UI and password store logic have been removed in favor of a new architecture using the \passKit\ framework and \passcodeLockPresenter\ for secure, portrait-only passcode/Face ID locking. Support for YubiKey decryption has been added via new NFC entitlements and Info.plist configurations, alongside features like Siri shortcuts, 3D Touch search, and file sharing. The app now also blurs the screen when switching to the background and uses \SVProgressHUD\ for status updates.

pass · high confidence

Centralized extension action and key constants

A new file, ExtensionConstants.swift, has been added to the passExtension/Helpers directory to consolidate string literals used by the app extension. This change introduces the PassExtensionActions enum, which defines specific action identifiers for finding, saving, and changing passwords, as well as filling web views and browsers. It also includes the PassExtensionKey enum to standardize dictionary keys for login data such as URLs, usernames, passwords, and TOTP secrets. This centralization improves maintainability by ensuring consistent identifiers across the extension codebase.

passExtension/Helpers · high confidence

Clipboard auto-clear and password prompt improvements

The app now automatically clears the clipboard 45 seconds after copying a password to improve security, implemented via the new SecurePasteboard helper. Additionally, the password prompt UI has been updated to use SVProgressHUD for alert presentation, providing a more consistent visual experience when requesting passwords.

pass/Helpers · high confidence

Migration to App Store Connect API and CI-specific keychain management

The Fastlane configuration has been updated to authenticate with the App Store using API keys (via \app\_store\_connect\_api\_key\) instead of legacy password-based authentication, with the key content handled as base64-encoded environment variables. Additionally, the beta and release lanes now conditionally create and unlock a dedicated keychain only when running in a CI environment (\is\_ci?\), ensuring that local development builds are not affected by CI-specific credential provisioning steps.

fastlane · high confidence

New AutoFill extension interface with navigation support

The AutoFill extension now uses a dedicated storyboard (MainInterface.storyboard) that embeds a navigation controller, allowing for a structured view hierarchy starting with the Extension View Controller and linking to the SearchPassword interface. This change replaces the previous static interface setup, enabling better navigation flow and UI organization within the extension.

passExtension/Base.lproj · high confidence

New Xcode schemes for app and extensions

The project now includes explicit Xcode schemes for the main Pass app, the AutoFill extension, the main extension, the passKit framework, and the Shortcuts extension. These schemes define build, test, launch, and archive configurations, enabling developers to run and test individual components and extensions directly within Xcode.

pass.xcodeproj/xcshareddata · high confidence

New password detail and generator UI components

The password detail view now uses a dedicated \PasswordDetailTitleTableViewCell\ to display the entry name, category, and icon. Password fields are rendered in \LabelTableViewCell\, which supports revealing/concealing passwords, opening URLs, and generating new HOTP codes. The password generator settings are now presented in \SliderTableViewCell\ and \SwitchTableViewCell\ for adjusting length and options, while \FillPasswordTableViewCell\ provides an inline generator button in editable fields. Additional cells (\TextFieldTableViewCell\, \TextViewTableViewCell\) and labels (\UICodeHighlightingLabel\, \UILocalizedLabel\) support richer content editing and formatting.

pass/Views · high confidence

Refactored Git repository and credential management models

The passKit/Models layer has been restructured to improve Git integration and security. A new GitRepository class now encapsulates repository operations such as cloning, pulling, pushing, and branch management, replacing previous inline logic. Git credentials (HTTP passwords and SSH key passphrases) are now managed via a dedicated GitCredential struct that integrates with the Keychain, supporting a 'remember passphrase' option and limiting retry attempts. Additionally, the PasscodeLock model has been updated to migrate existing passcode storage from SharedDefaults to the Keychain for better persistence and security across app extensions.

passKit/Models · high confidence

Refactored OTP parsing and token building infrastructure

The passKit/Parser module has been restructured to improve maintainability and testability. The previous Password class logic has been separated into dedicated components: a new TokenBuilder class now handles the construction of TOTP and HOTP tokens from parsed data, while a Constants file centralizes OTP-related strings and keywords. A new AdditionField struct replaces the previous TableCell struct for handling additional password file fields, and the core Parser class now uses a lazy evaluation strategy for parsing addition fields. These changes support more precise handling of OTP parameters (such as algorithm, period, and digits) and introduce support for Steam OTP representations.

passKit/Parser · high confidence

Refactored QR key scanning logic into dedicated model classes

The QR key scanning implementation has been consolidated into new \QRKeyScanner\ and \ScannableKeyType\ model classes. This change centralizes the logic for parsing PGP and SSH key segments from QR codes, handling state transitions (looking for start, detecting wrong key type, completed) and segment accumulation. It specifically addresses issues with footer detection by ensuring all scanned segments are checked for the correct key block footer, improving reliability when reading multi-segment QR keys.

pass/Models · high confidence

Refactored password management services and added YubiKey decryption support

The pass/Services layer has been restructured into dedicated modules: PasswordDecryptor, PasswordEncryptor, PasswordManager, and PasswordNavigationDataSource. This refactoring introduces a new PasswordYubiKeyDecryptor class that enables decryption of passwords using a YubiKey via the YubiKit framework, including handling of OpenPGP application selection and PIN verification. The PasswordManager now centralizes the logic for copying passwords to the pasteboard and adding new passwords, while the PasswordNavigationDataSource handles the table view data source logic for displaying and filtering password entries. Additionally, the decryptPassword function now explicitly prevents YubiKey usage within app extensions, showing an alert to guide users to the main app instead.

pass/Services · high confidence

Removal of PasswordEntity Core Data model

The Core Data model file for the app has been deleted, removing the \PasswordEntity\ and its associated attributes (\name\, \raw\, \rawPath\) from the data layer. This indicates a structural change to how password data is persisted or managed, likely preceding a migration to a different storage mechanism or a refactoring of the data model.

pass/pass.xcdatamodeld · high confidence

Rewritten AutoFill extension with credential identity support and password suggestions

The AutoFill extension has been rewritten to support selecting credentials from the QuickType bar and displaying suggested passwords. The new implementation includes a CredentialProvider service that handles decryption and persists credential identities via ASCredentialIdentityStore, and a PasswordsTableDataSource that manages UI sections for 'Suggested Passwords' versus 'Other Passwords' based on matching logic.

passAutoFillExtension/Services · high confidence

Rewritten AutoFill extension with improved credential selection and security controls

The AutoFill extension's user interface and interaction flow have been completely rewritten. Users now see a dedicated password selection screen with a search bar and suggested matches when the extension is triggered, rather than the previous interface. The extension now properly handles passcode authentication via a dedicated lock view controller, ensuring that credentials are only provided after successful verification (or if no passcode is set). It also supports automatic credential provision for known identities via the QuickType bar while maintaining security by requiring user interaction when a passcode is active. The new implementation includes better handling of service identifiers and displays the URL host as a prompt to help users identify the correct entry.

passAutoFillExtension/Controllers · high confidence

Support for dummy (unlocked) private keys in GopenPGP integration

The patch applied to the crypto module adapts the key handling logic to work with ProtonMail's GopenPGP library. Specifically, the \Unlock\ function now checks if a private key is a 'dummy' (already unlocked) key before attempting to decrypt it, preventing unnecessary or erroneous decryption steps. Additionally, the \IsLocked\ function has been updated to correctly identify dummy keys as locked (returning true), ensuring consistent state reporting for keys that do not require passphrase decryption.

patch · high confidence

Switch PGP encryption backend to GopenPGP with ObjectivePGP fallback

The passKit/Crypto module now uses ProtonMail's GopenPGP library as the primary engine for PGP encryption and decryption, replacing the previous implementation. To ensure stability, the system includes a fail-safe mechanism: if GopenPGP initialization fails, it automatically falls back to the ObjectivePGP library. This change also introduces improved handling for malformed keys and specific decryption errors (such as wrong passphrases or expired keys), preventing crashes and providing clearer error states to the user.

passKit/Crypto · high confidence

Updated Xcode workspace configuration for Swift Package Manager migration

The Xcode workspace settings have been updated to support the migration from CocoaPods to Swift Package Manager. This includes adding the IDE workspace checks file, disabling previews in the workspace settings, and correcting the project reference location in the workspace data file to ensure proper project loading.

pass.xcodeproj/project.xcworkspace · high confidence

Updated storyboard to iOS 17 design standards and restructured main views

The Main.storyboard has been upgraded to use Xcode 23.504 tooling and targets iOS 17 (CocoaTouch 23506), introducing system color support and modern layout guides. The interface has been restructured to use inset-grouped table views for the Password Store and Settings screens, with updated cell styles and navigation items. This change reflects a broader UI modernization effort, aligning the visual appearance with current iOS design language while maintaining the core functionality of password management and configuration.

pass/Base.lproj · high confidence

Test coverage

Added test bundle configuration for passKitTests; Added unit test helper for PersistenceController; Added unit tests for AppKeychain and KeyFileManager helpers; Added unit tests for Array and String extensions; Added unit tests for CoreData password entity persistence and import logic; Added unit tests for PersistenceController; Added unit tests for QR key scanning logic and key type definitions; Added unit tests for passKit parser components; Added unit tests for password generator configuration and generation logic; Added unit tests for password store, Git integration, and credential models; Added unit tests for the Crypto and PGP Agent frameworks; New test infrastructure for PGP key management and decryption; Updated test fixtures for password store repositories.

Dependencies

Migration to Swift Package Manager and project restructuring

The project has moved from CocoaPods to Swift Package Manager (SPM), removing all CocoaPods-related configurations and dependencies from the Xcode project file. This change includes updating the project file format version (objectVersion 46 to 54) and reorganizing the build files to reflect the new package-based dependency management system, which simplifies dependency resolution and improves build consistency for users.

pass.xcodeproj · high confidence

Updated Ruby and Swift package dependencies

This change updates the project's dependency manifests. The Ruby Gemfile now includes the 'rest-client' gem alongside 'fastlane' and 'xcodeproj', with the lockfile reflecting updated versions for gems such as 'fastlane' (2.237.0), 'faraday' (1.10.6), and 'jmespath' (1.6.2). The Swift Package Manager resolved file pins several libraries to newer versions, including 'ObjectivePGP' (0.99.4), 'YubiKit' (4.7.0), 'KeychainAccess' (4.2.2), and 'SwiftFormat' (0.55.5).

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 63 → 55 (-8.7)
  • Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 96 → 96 (-0.1)
  • Architecture 92 → 81 (-10.8)
  • Maturity 54 → 54 (+0.1)
  • Readiness 52 → 35 (-16.8)
  • Security 88 → 91 (+3.7)
  • Domain Modelling 100 → 100 (+0.0)

Resolved (4)

  • Documentation: no installation or build instructions (README.md)
  • Off-boarding risk: anonymized user #1
  • Off-boarding risk: anonymized user #2
  • Outdated: fastlane

New (10)

  • Floating branch dependency: base32
  • Floating branch dependency: objective-git-swift-package
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • LabelTableViewCell.cellData (cognitive 16) (pass/Views/LabelTableViewCell.swift)
  • Off the main sequence: passKit
  • Off-boarding risk: anonymized user #1
  • Off-boarding risk: anonymized user #2
  • Outdated: swift-collections
  • Outdated: swiftformat
  • Outdated: swiftlintplugins

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

mssun/passforios was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit cb836aaeda1828fd9aff55773c3d355d049dc426 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.