nathena/zeus-php
47.8
Weak · 21 September 2026
4.8k
lines of production code
PHP
primary language
4
measurements over time
What this system is
This system is a PHP-based web application framework named 'Zeus' that provides a structured environment for building web applications. It features a domain-driven architecture with entities for accounts, bookings, and transportation, supported by a robust database abstraction layer with XA transaction support. The framework includes built-in authentication, role-based access control, and security measures like XSS and CSRF protection, alongside utilities for encryption, validation, and internationalization.
How it got here
2016 — Framework refactoring and security hardening
9 changes.
This period focused on a comprehensive refactoring of the Zeus framework's core architecture, introducing a centralized configuration system, a singleton-based application container, and improved MVC patterns. Concurrently, the application layer implemented structured authentication, role-based access control, and XSS protection, while removing legacy components like the custom PDO wrapper and obsolete utility classes.
2017 — Core framework and domain model initialization
10 changes.
This period focused on establishing the foundational architecture of the Zeus framework, introducing key components such as the database abstraction layer, command/event handling, and utility classes for security and validation. Simultaneously, domain models for accounts, bookings, and customers were implemented alongside corresponding database specifications and view templates, laying the groundwork for the application's business logic.
Features
Added database specification classes for CRUD operations
The \zeus/database/specification\ directory now contains a new set of PHP classes that implement the Specification pattern for database interactions. This includes \AbstractSpecification\ and \AbstractWhereSpecification\ as base classes, alongside concrete implementations for \QuerySpecification\ (selecting data), \InsertSpecification\ and \InsertBatchSpecification\ (adding records), \UpdateSpecification\ (modifying records), \DeleteSpecification\ (removing records), and \PaginationSpecification\ (handling list and count queries). These classes provide a structured way to build and execute SQL statements with parameterized queries, supporting features like pagination, sorting, grouping, and batch operations.
zeus/database/specification · high confidence
Added encryption, file handling, and validation utilities
The \zeus/utils\ namespace now includes new utility classes: \Aes\ and \Des\ for AES and DES encryption/decryption; \Downloader\ for handling file downloads with browser-specific header encoding; \Il8n\ for internationalization with support for current data retrieval; \Uploader\ for managing file uploads with size and MIME type validation; \Validator\ for checking email, mobile, phone, and other formats; and \XssCleaner\ for sanitizing user input to prevent XSS attacks. These classes provide core functionality for security, data handling, and validation across the application.
zeus/utils · high confidence
Added login, welcome, and error view templates
The application now includes dedicated HTML templates for the login page (views/login.html), the post-login welcome page (views/welcome.html), and a generic error display page (views/error.html). These views provide the user interface for authentication, the main landing experience, and error reporting respectively.
views · high confidence
Introduce structured authentication and routing
The application now features a structured authentication system with login, logout, and role-based access control. Users can log in via /login and /do\_login, with sessions managed through tokens. The system enforces login requirements for protected routes using base controllers like LoginedPlatformController and LoginedB2BPlatformController. Additionally, a new router configuration in boot.php maps URLs to controllers, and an i18n configuration file (chinese.ini) supports internationalization.
application · high confidence
Introduced base framework components for commands, events, and configuration
Added new base classes and interfaces in the \zeus/base\ directory to support command and event handling, including \AbstractComponent\ for raising events, \ApplicationContext\ for managing the application context and retrieving command/event buses, and \ConfigManager\ for centralized configuration management. The update also introduces \CommandDispatcher\ and \EventDispatcher\ to route commands and events to their respective handlers, alongside corresponding interfaces (\CommandInterface\, \CommandHandlerInterface\, \EventInterface\, \EventListenerInterface\). Additionally, the \Autoloader\ was moved to \zeus/base\ and refactored to support namespace-based autoloading, and several exception classes were reorganized under \zeus/base/exception\.
zeus/base · high confidence
Introduced domain models for account, booking, bus, and customer entities
The application now includes new domain classes for managing accounts, bookings, bus operations, and customers. Specifically, the Account class provides methods for user authentication (check\_passwd), updating user information (update\_info), and updating passwords (update\_passwd). Booking-related entities (Order, OrderCheck, OrderTourist, OrderVehicle) and customer/transportation entities (Customer, Bus, BusSupplier, Driver) have been added as aggregate roots, each mapping to their respective database tables. This change introduces new capabilities for managing user accounts and booking-related data, while also restructuring the codebase to separate the booking aggregate.
php · high confidence
Introduction of Zeous Database Abstraction Layer
A new database management component has been added to the codebase, introducing the \DbManager\ class to handle standard and XA (distributed) database sessions via PDO. This includes a \DmlType\ class defining supported data manipulation operations such as SELECT, INSERT, UPDATE, DELETE, BATCH, and PAGING. Additionally, a specific \DbCofigNotFoundException\ is introduced to handle missing database configuration scenarios.
zeus/database · high confidence
New PDO database dialects with XA transaction support
The \zeus/database/pdo\ area introduces a new PDO-based database abstraction layer. \AbstractPdoDialect\ provides a base implementation for executing SQL statements, including support for pagination and batch operations, while \Pdo\ adds support for nested transactions. Additionally, \XaPdo\ and \XaIdGenerator\ are added to enable XA distributed transaction support, allowing applications to manage multi-phase commit transactions across multiple databases or services.
zeus/database/pdo · high confidence
New domain entity and aggregate root base classes
Added new base classes for the domain layer: AbstractEntity, AggregateRoot, EventSouringAggregateRoot, and LocalCacheManager. AbstractEntity provides a base for domain entities with property management, versioning, and array access support. AggregateRoot adds persistence methods (save, update, remove) and static query methods (get, fetch, fetchAll, paging, command) for database operations. EventSouringAggregateRoot extends AbstractEntity to support event sourcing by tracking and committing domain events. LocalCacheManager provides a static local cache mechanism for entities.
zeus/domain · high confidence
Removals
Removed obsolete multiprocess utility class
The \zeus\\util\\Multiprocess\ class has been removed from the codebase. This class previously handled HTTP-based process execution and listener functionality, which is no longer used.
zeus/util · high confidence
Behavioural changes
Added empty README file in logs directory
An empty file named 'READEME' was added to the logs directory. This appears to be a placeholder or documentation file, though the filename contains a typo ('READEME' instead of 'README').
logs · low confidence
Refactored HTTP component with improved security and architecture
The HTTP component has been significantly refactored to improve security and structure. Session handling now uses a singleton pattern and retrieves configuration via a ConfigManager, with a new InitSessionSaveHandlerException for better error reporting. The Cookie class now implements ArrayAccess for easier data access. A new XssWapperRequest class automatically sanitizes input data using an XssCleaner to prevent cross-site scripting attacks. Additionally, the HttpClient has been moved to the zeus amespace and now safely handles missing query parameters, while the framework removes deprecated filter interfaces and session handlers (Memcache, Memcached, Redis) in favor of the new centralized session management.
zeus/http · medium confidence
Refactored MVC core with new Application, ModelMap, and Controller architecture
The MVC framework has been significantly refactored to improve separation of concerns and security. A new singleton Application class now manages the request/response lifecycle and dispatches routes, while a new ModelMap class provides a unified container for passing data between controllers and views. The abstract Controller class has been updated to integrate with the new Application context and includes built-in CSRF token generation and validation for POST requests. Additionally, the View class now supports array-style access and direct data injection, and new exception classes (ControllerNotFoundException, RoutingRepeatedException) have been introduced for better error handling.
zeus/mvc · medium confidence
Removal of helloword template file
The 'helloword' template file has been removed from the application. Users will no longer be able to access or render this specific template.
template · high confidence
Removal of legacy PDO database wrapper
The \zeus/db/PDOp.php\ file, which provided a custom PDO wrapper for database operations, has been removed from the codebase. This change eliminates the legacy database access layer in favor of the current database implementation.
zeus/db · high confidence
Simplified webroot entry point
The main entry point for the application has been significantly simplified. The previous implementation included a complex PHP class with multiple properties and methods for testing, which has been removed. The file now simply includes the new 'application/boot.php' script, indicating a shift in how the application is bootstrapped.
webroot · high confidence
Zeus framework bootstrapping and configuration refactored
The Zeus framework's initialization process has been restructured. The previous \Env\ class, which managed configuration loading for various subsystems, has been removed and replaced by a new \zeus/config.php\ file that centralizes settings for timezones, uploads, sessions, routing, views, logging, and database connections. Additionally, the \bootstrap.php\ entry point has been simplified to use a new \ApplicationContext\-based startup mechanism, removing the previous autoloader, router execution, and exception handling logic from the bootstrap file.
zeus · medium confidence
Test coverage
Added test suite for Zeus framework components
Added a comprehensive set of test files in the 'test' directory to verify the functionality of the Zeus framework's core components. This includes controllers (IndexController), command and event handlers (EchoCommand, EchoedEvent), database specifications (Insert, Query, Update, Delete), and utility scripts (RSA encryption, trie tree for sensitive word filtering). These files serve as integration and functional tests for the application's routing, MVC structure, and business logic.
test · high confidence
Dependencies
Initial Composer package configuration for nathena/zeus-php
Added a new composer.json file that defines the package metadata, including the package name 'nathena/zeus-php', author details, and an empty 'require' section. The configuration also sets up PSR-0 autoloading for the 'zeus' namespace and specifies a custom repository URL for Packagist.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 49 → 48 (-1.1)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 96 → 97 (+1.4)
- Architecture 100 → 89 (-10.5)
- Maturity 44 → 44 (+0.0)
- Readiness 24 → 24 (+0.0)
- Security 100 → 100 (+0.0)
Resolved (8)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (10 lines × 2) (application/base/LoginedB2BPlatformController.php)
- Duplicated block (8 lines × 2) (zeus/database/pdo/AbstractPdoDialect.php)
- Duplicated block (8 lines × 2) (zeus/http/HttpClient.php)
- No exposed public API
- Test reliability not included
- single-maintainer — knowledge-concentration (bus factor) risk
New (7)
- Duplicated block (10 lines × 2) (application/base/LoginedB2BPlatformController.php)
- Duplicated block (10 lines × 2) (zeus/database/pdo/AbstractPdoDialect.php)
- Duplicated block (13–15 lines × 2) (zeus/http/HttpClient.php)
- Duplicated block (24 lines × 2) (zeus/base/command/CommandDispatcher.php)
- Duplicated block (36 lines × 2) (zeus/utils/Aes.php)
- Duplicated block (5 lines × 2) (zeus/http/HttpClient.php)
- TodoComment (zeus/base/ApplicationContext.php)
Architecture
- Unchanged — 0 containers · 1 contexts · 0 edges
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
nathena/zeus-php was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit e38b55fb811ff0a314de27d082b99f437f567eed — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.