Skip to content
CAI
Software that uses CAICheck a score

mtarld/apip-ddd

67.1

Adequate · 22 September 2026

4.9k

lines of production code

PHP

primary language

7

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a modernized book store API built on Symfony 8.1 and API Platform 4, designed to manage books, authors, categories, and orders through a strict domain-driven architecture. It exposes REST endpoints for creating, updating, and querying bookstore entities, while supporting a subscription feature that notifies users via email when new books are published. The codebase enforces immutability and value objects within its domain layer and utilizes FrankenPHP for runtime execution.

Features

Bookstore API Platform integration and application commands

This change introduces the application-layer command handlers (CQRS) and the API Platform infrastructure for the Bookstore domain. It adds handlers for creating, amending, classifying, declassifying, discounting, reviewing, and anonymizing books, as well as creating authors, categories, and placing orders. The infrastructure layer provides the corresponding API Platform resources, payloads, state processors, and object mappers to expose these operations via REST endpoints, including specific endpoints for listing cheapest books and managing book classifications.

src/BookStore/Infrastructure · high confidence

Introduces BookStore domain value objects and exceptions

This change adds a comprehensive set of value objects to the BookStore domain, including identifiers (AuthorId, BookId, CategoryId, OrderId, ReviewId), descriptive fields (AuthorName, BookName, BookDescription, BookContent, CategoryName, ReviewComment), and business logic types (Price, Quantity, Discount, Isbn, Actor, AnonymizationReason, OrderItem, PurchasedBook). These objects enforce validation rules such as ISBN-13 check digits, price ranges, and string lengths, and are mapped as Doctrine embeddables. Additionally, specific domain exceptions (MissingAuthorException, MissingBookException, MissingCategoryException, MissingOrderException, MissingReviewException) are introduced to handle cases where domain entities cannot be found by their identifiers.

src/BookStore/Domain/ValueObject · high confidence

New book subscription feature with API and event-driven notifications

Users can now subscribe to book announcements via a new email-based subscription endpoint exposed through the API Platform resources. The system automatically notifies all subscribers when a new book is published, logging the announcement details (title, price, and subscriber email) for tracking purposes.

src/Subscription · high confidence

Removals

Removal of Book Library domain and application logic

The application no longer supports managing books in the library. This change removes the entire Book domain model, including the Book entity and its repository interface, as well as all associated application-layer command and query handlers (Create, Update, Anonymize, Find, and FindCheapest). Users can no longer create, update, search, or anonymize book records through the system.

src/Application, src/Domain · high confidence

Behavioural changes

Domain model rewritten for API Platform 4 with value objects and immutability

The domain entities in src/BookStore/Domain/Model (Book, Author, Category, Classification, Order, OrderLine, Review) have been completely rewritten to align with API Platform 4. This change introduces strict immutability by using value objects (e.g., BookId, Price, AuthorName) and readonly properties, replacing previous public writable fields. The Book entity now exposes read-only collections for reviews and classifications, enforces event recording via the RecordsEvents trait, and includes behavioral methods for renaming, describing, revising content, repricing, and applying discounts. Order creation is now controlled via a static factory method that validates non-empty purchases. These changes ensure the domain model is compatible with API Platform 4's serialization and validation expectations while improving encapsulation.

src/BookStore/Domain/Model · high confidence

Introduction of domain-specific repository interfaces

New repository interfaces have been added for the Author, Book, Category, and Order domain entities. These interfaces define the contract for data access, introducing methods such as \add\, \get\, and \all\ (with pagination support for Authors and Categories), as well as specific queries like \findByName\ for Authors and \idsByAuthor\ for Books. This establishes a collection-oriented repository pattern within the domain layer, separating the data access contracts from their implementations.

src/BookStore/Domain/Repository · high confidence

Migrate Symfony configuration from PHP to YAML

All package and route configuration files in the config directory have been converted from PHP-based configuration scripts (.php) to YAML files (.yaml). This change standardizes the configuration format, simplifying maintenance and readability for components such as API Platform, Doctrine, Messenger, and routing, while preserving the existing behavior and environment-specific overrides.

config/packages · high confidence

Migrated to API Platform 4, FrankenPHP, and Castor-based development

The project has been rewritten to use API Platform 4, Symfony 8.1, and PHP 8.5, replacing the previous API Platform 3 and Symfony 6 stack. The development environment has shifted from Docker Compose to FrankenPHP, with container orchestration now managed via Castor tasks (e.g., \castor install\, \castor start\) instead of direct \docker-compose\ commands. Additionally, the repository now enforces architectural boundaries using Deptrac for both bounded contexts and hexagonal layers, and includes configuration for PHPStan, Rector, and PHP-CS-Fixer to maintain code quality.

(repo-wide) · high confidence

Migration to FrankenPHP and introduction of BookStore domain events

The application runtime has shifted from the standard Symfony PHP container to FrankenPHP, introducing a new Caddyfile configuration, specific PHP INI settings for development and production (including Xdebug and OPcache tuning), and an entrypoint script that handles dependency installation, database readiness checks, and migration execution. Concurrently, the BookStore domain layer now includes event-driven capabilities: a \RecordsEvents\ trait allows entities to track and release domain events, while specific event classes (\BookPublished\ and \BooksAnonymized\) have been added to capture book publication and author data anonymization activities.

frankenphp, src/BookStore/Domain/Event · high confidence

Refactor service configuration for API Platform 4 and directory restructuring

The service configuration has been rewritten to support API Platform 4, including a new definition for the URI variables converter in config/services/api\_platform.php. The directory structure has been reorganized: the previous monolithic library configuration is removed, and service loading is now split into specific files for the BookStore, Subscription, and Shared domains. Additionally, the configuration files have been renamed from the packages directory to the services directory (e.g., routing.php to book\_store.php, monolog.php to mcp.php), and the MCP registry alias is updated to resolve the new per-server registry structure introduced in symfony/mcp-bundle 0.13+.

config/services · high confidence

Refactored shared infrastructure to support API Platform 4 and domain-driven value objects

This change restructures the shared application layer to align with API Platform 4 and a stricter domain model. It introduces a new event bus interface and messenger-based implementation, replacing the previous query bus with a command bus that now returns void. The codebase now includes robust support for domain value objects: they are automatically unwrapped in API responses, validated via a new AssertValueObject constraint, and mapped as Doctrine embeddables. Additionally, pagination is standardized through a new PaginatedCollection and Pagination classes, and API resource links are handled via a dedicated ResourceLink attribute and resolver.

src/Shared · high confidence

Removal of custom ApiPlatform state providers, processors, and repository infrastructure

This change removes the custom ApiPlatform state providers and processors (such as BookCrudProvider, AnonymizeBooksProcessor, and DiscountBookProcessor) that previously bridged API operations to the application's command and query buses. It also deletes the custom metadata classes (CommandOperation, QueryOperation) used to define these operations, the Doctrine and InMemory repository implementations (DoctrineBookRepository, InMemoryBookRepository) along with their shared base classes and paginators, and the compiler pass that cleared native ApiPlatform tags. These removals indicate a shift away from the previous custom infrastructure layer for handling API state and data persistence.

src/Infrastructure · high confidence

Removal of legacy Docker infrastructure files

The Docker configuration for the application has been significantly cleaned up by removing several legacy files that are no longer needed. Specifically, the Caddyfile (which previously configured HTTP/3 and Mercure) has been deleted, along with the PHP production INI settings, the custom PHP entrypoint script, the healthcheck script, and the PHP-FPM configuration. This change simplifies the container setup by relying on default or external configurations instead of these specific local overrides.

docker · high confidence

Removal of legacy base HTML template

The \templates/base.html.twig\ file, which previously provided the standard HTML structure including Webpack Encore asset injection and basic block definitions, has been removed. This change eliminates the default layout foundation for the application's views, requiring templates to either define their own structure or rely on a new base template introduced elsewhere.

templates · high confidence

Updated Symfony kernel preload path and registered MCP bundle

The application's preload configuration now targets the renamed kernel container class (App\_Shared\_Infrastructure\_Symfony\_KernelProdContainer) to align with the new kernel naming convention. Additionally, the Symfony AI MCP Bundle has been registered to enable Model Context Protocol support, while the Security Bundle has been removed from the default bundle list.

config · high confidence

Updated bin scripts for API Platform 4 and namespace reorganization

The bin/phpunit script has been rewritten to support API Platform 4, adding logic to prioritize the local vendor phpunit binary while falling back to the Symfony PHPUnit Bridge. Additionally, the bin/console script has been updated to reflect a namespace reorganization, changing the Kernel import from App\\Infrastructure\\Shared\\Symfony\\Kernel to App\\Shared\\Infrastructure\\Symfony\\Kernel.

bin · high confidence

Updated public entry point for PHP 8+ syntax and namespace alignment

The public/index.php entry point has been refactored to use modern PHP syntax, including strict types, a static arrow function for the kernel instantiation, and explicit directory resolution. Additionally, the Kernel class import has been updated to reflect a new namespace structure (App\\Shared\\Infrastructure\\Symfony\\Kernel), aligning the public interface with the internal codebase reorganization.

public · high confidence

Test coverage

Added acceptance and functional tests for the BookStore API; Added acceptance tests for subscription management and book announcement; Added test bootstrap and PHPStan object-manager configuration; Added test service configuration for Book Store and shared spies.

Dependencies

Upgrade to Symfony 8.1 and API Platform 4.3

This update upgrades the project's core dependencies, moving from Symfony 6.0 to Symfony 8.1 and from API Platform 2.x (dev-main) to API Platform 4.3. The PHP requirement has been raised to version 8.5 or higher. Additionally, Doctrine ORM and Doctrine Bundle have been upgraded to versions 3.6 and 3.2 respectively, and several new development tools including Deptrac, PHP-CS-Fixer, and PHPUnit 13.1 have been added to the dev dependencies. The project license has also been changed from proprietary to MIT.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 54 → 67 (+13.2)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (+0.0)
  • Architecture 100 → 74 (-25.9)
  • Maturity 44 → 61 (+17.6)
  • Readiness 44 → 72 (+28.7)
  • Security 59 → 87 (+28.3)
  • Domain Modelling 100 → 66 (-34.0)

Resolved (37)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (composer.lock)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Further orphaned files (smaller)
  • High CVE: [GHSA redacted] (composer.lock)
  • High CVE: [GHSA redacted] (composer.lock)
  • High CVE: [GHSA redacted] (composer.lock)
  • High CVE: [GHSA redacted] (composer.lock)
  • High CVE: [GHSA redacted] (composer.lock)
  • High CVE: [GHSA redacted] (composer.lock)
  • High IaC: DS-0002 (Dockerfile)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 17 more

New (21)

  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium IaC: WD-DOCKER-0003 (Dockerfile)
  • Medium IaC: WD-DOCKER-0003 (Dockerfile)
  • Medium: security finding (details withheld)
  • No ADRs found
  • No assertions: testItHandsEveryFieldOfTheEventToTheAuditTrail (tests/BookStore/Unit/RecordAnonymizationListenerTest.php)
  • No dependency advisory monitoring
  • Outdated: doctrine/doctrine-bundle
  • Outdated: doctrine/orm
  • Outdated: symfony/console
  • Outdated: symfony/framework-bundle
  • Outdated: symfony/json-streamer
  • Outdated: symfony/messenger
  • Outdated: symfony/monolog-bundle
  • Outdated: symfony/property-info
  • Outdated: symfony/twig-bundle
  • Outdated: symfony/validator
  • …and 1 more

Changes since last survey

  • 1 commits — 1 feature/other, 0 fixes

By area

  • src/BookStore — 1 commit

Notable commits

  • change: Rewrite for API Platform 4

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

mtarld/apip-ddd was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 55a4b3b955823ccb11a799e85e32004d68e62be0 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.