Skip to content
CAI
Software that uses CAICheck a score

NginxProxyManager/nginx-proxy-manager

42.3

Weak · 20 September 2026

22.8k

lines of production code

TypeScript

with JavaScript

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is a self-hosted Nginx proxy manager that provides a web interface for configuring and managing reverse proxies, redirections, TCP/UDP streams, and dead hosts. It handles SSL certificate issuance and management via Let's Encrypt and custom uploads, while enforcing access controls through IP-based rules and two-factor authentication. The platform includes comprehensive audit logging, user role management, and multi-language support, all delivered through a modern React frontend and a Node.js backend.

How it got here

2017–2020 — Backend modernization and infrastructure overhaul

18 changes.

This period focused on a comprehensive backend rewrite, migrating the codebase to ES modules and upgrading core dependencies like Express and Knex. It introduced significant new features including two-factor authentication, access control lists, and audit logging, while restructuring Nginx configuration into modular templates. The work also established a robust Docker-based development and CI environment to support multi-architecture builds and extensive testing.

2021–2026 — Frontend rewrite and security hardening

41 changes.

The project underwent a major frontend rewrite, migrating from the legacy implementation to a modern React and Vite architecture with comprehensive UI components and internationalization. Concurrently, the Docker container infrastructure was hardened to enforce non-root execution, updated to S6-overlay v3, and enhanced with robust health checks and automated log rotation. Backend services were modernized with ES Modules, expanded API endpoints for audit logging, and strengthened by extensive Cypress end-to-end test coverage.

Features

Add development-only frontend service for local hot-reloading

A new s6-overlay service has been added to support development workflows. When the DEVELOPMENT environment variable is set to true, this service initializes the frontend build directory, installs dependencies, and starts the development server using Yarn. The service runs under the user and group IDs specified by PUID and PGID to ensure proper file permissions during development.

docker/rootfs/etc/s6-overlay/s6-rc.d/frontend · high confidence

Added brand assets and browser configuration files

The frontend now includes new static assets to support branding and browser integration. This adds a \site.webmanifest\ and \browserconfig.xml\ to define the app's appearance as a web app and for Windows tiles, alongside new SVG files for the logo (including a horizontal grey variant and a no-text version) and an 'unhealthy' status illustration.

frontend/public · high confidence

Automated locale file sorting tooling added

Added new scripts (locale-sort.cjs and locale-sort.sh) to the frontend locale tooling that automatically sort JSON keys alphabetically within locale files. This ensures consistent formatting and order across language definition files, simplifying maintenance and reducing merge conflicts in the localization assets.

frontend/src/locale/scripts · high confidence

Automated log rotation for Nginx Proxy Manager access and error logs

A new logrotate configuration has been added for Nginx Proxy Manager to automatically manage log files. Access logs are rotated weekly, keeping 4 weeks of history, while error logs are rotated weekly with 10 weeks of retention. Both configurations run under the 'npm' user, compress rotated logs, and send a USR1 signal to the Nginx process after rotation to ensure logs are reopened correctly.

docker/rootfs/etc/logrotate.d · high confidence

Dashboard now displays permission-aware host management cards

The Dashboard page has been implemented to present a summary of host management sections, including Proxy Hosts, Redirection Hosts, Streams, and Dead Hosts. Each section is displayed as a clickable card showing the current count of items, retrieved via the useHostReport hook. Access to these cards is controlled by the HasPermission component, ensuring that users only see sections they are authorized to view (PROXY\_HOSTS, REDIRECTION\_HOSTS, STREAMS, DEAD\_HOSTS). Clicking a card navigates the user to the corresponding management page (e.g., /nginx/proxy).

frontend/src/pages/Dashboard · high confidence

Database schema updates for proxy, redirection, and stream hosts

This update applies a series of database migrations to the backend schema. It introduces new capabilities and configuration options for proxy, redirection, and stream hosts, including support for HTTP/2, WebSocket upgrades, HSTS, custom locations, and SSL certificates for streams. It also adds fields for controlling forward schemes and status codes for redirections, enables host disabling, and introduces access list client management with authentication passing. Additionally, it renames columns for better clarity (e.g., forward\_ip to forward\_host) and adds a setting to trust forwarded protocol headers for SSL redirect handling.

backend/migrations · high confidence

Expanded Help Documentation with Multi-Language Support

The HelpDoc system now includes comprehensive documentation for core features—Access Lists, Certificates, Dead Hosts, Proxy Hosts, Redirection Hosts, and Streams—available in 23 languages including English, German, French, Spanish, Estonian, Irish, Hungarian, Indonesian, and Azerbaijani. The \index.ts\ module has been updated to manage these translations and provide English fallbacks, ensuring users can access detailed guidance on proxy configurations, SSL certificate validation (HTTP/DNS), and stream forwarding in their preferred language.

frontend/src/locale/src/HelpDoc · high confidence

Initial user setup wizard introduced

A new Setup page has been added to allow users to create the first administrator account. This interface collects the full name, email address, and password, then calls the backend API to create the user and automatically logs them in upon success. The page also includes UI controls for switching the application language and theme.

frontend/src/pages/Setup · high confidence

Login page now supports TOTP two-factor authentication

The login interface has been updated to include a dedicated two-factor authentication step. After entering credentials, users are presented with a form to input their TOTP code, which is validated against the backend. The page also displays the application version and includes locale and theme selectors.

frontend/src/pages/Login · high confidence

New API endpoints for audit logging, version checking, and reports

The backend now exposes new API routes for viewing audit logs (GET /api/audit-log and /api/audit-log/:event\_id), checking for available updates (GET /api/version/check), and retrieving host reports (GET /api/reports/hosts). These endpoints are registered in the main router and require JWT authentication, providing users with visibility into system activity, update status, and infrastructure reports.

backend/routes · high confidence

New Access Lists management page

A new Access Lists page has been added, allowing users to view, search, and manage access lists. The page displays a table with details such as owner, name, authorization items, access clients, and proxy hosts. Users with the MANAGE permission can add, edit, or delete access lists, while all users with VIEW permission can see the list. The page includes a search filter and integrates with existing modal components for editing and deletion confirmation.

frontend/src/pages/Access · high confidence

New Dead Hosts management page with search and sorting

A new Dead Hosts page has been added to the Nginx section, allowing users to view, search, and manage dead hosts. The interface includes a table with columns for the owner (displaying avatars), domain names, SSL certificate status, and online/offline status. Users can search for specific hosts by domain name, sort the table by domain, and perform actions such as editing, enabling/disabling, or deleting hosts (subject to permissions). The page also provides an option to add new dead hosts and access help documentation.

frontend/src/pages/Nginx/DeadHosts · high confidence

New Default Site configuration page for restricted users

A new Settings page has been added that allows administrators to configure the default site behavior for unknown hosts. Users can now choose between displaying a congratulations message, a 404 error, a 444 error, a custom redirect URL, or custom HTML content. This feature is gated by the ADMIN/VIEW permission, ensuring it is only accessible to users with the appropriate privileges.

frontend/src/pages/Settings · high confidence

New Docker build infrastructure and CI testing stack

The project introduces a new Dockerfile and CI infrastructure to support multi-arch builds and comprehensive testing. The Dockerfile now uses the \nginxproxymanager/nginx-full:certbot-node\ base image, installs \logrotate\, and configures the s6-overlay service manager. A new \.dive-ci\ file enforces image efficiency standards (99% efficiency, max 15MB wasted bytes). The CI stack is expanded with dedicated docker-compose files for isolated, MySQL, PostgreSQL, and SQLite test environments, adding services for PostgreSQL 17, MariaDB, Authentik (for authentication testing), PowerDNS, and Squid (for proxy testing).

docker · high confidence

New React Query hooks for frontend data management

The frontend now uses a comprehensive set of React Query hooks to manage data fetching and mutations for core resources. This change introduces hooks for Access Lists, Audit Logs, Certificates, Dead Hosts, DNS Providers, Proxy Hosts, Redirection Hosts, Streams, Settings, Users, and system Health/Version checks. These hooks standardize how the UI interacts with the backend API, providing consistent caching, optimistic updates, and automatic invalidation for related data.

frontend/src/hooks · high confidence

New React-based API client and notification system

The frontend now uses a new, structured API client library in \frontend/src/api/backend\ that replaces previous request handling. This library standardizes HTTP methods (GET, POST, PUT, DELETE) with automatic camelCase conversion, auth header injection, and 401 handling. It exposes typed functions for all backend resources (users, certificates, proxy hosts, streams, access lists, audit logs, settings) and includes support for two-factor authentication flows, login-as-user, and certificate management. Additionally, a new toast notification system (\frontend/src/notifications\) has been added to provide user feedback for success and error states.

frontend/src/api · high confidence

New Redirection Hosts management interface

A new UI page for managing Nginx redirection hosts has been added, featuring a sortable and searchable table that displays source domains, HTTP codes, schemes, destinations, SSL status, and online/offline state. Users can now create, edit, enable/disable, and delete redirection hosts directly from this interface, with actions gated by specific view and manage permissions.

frontend/src/pages/Nginx/RedirectionHosts · high confidence

A new Streams management interface has been added to the Nginx section, allowing users to view, search, and manage TCP/UDP proxy streams. The page includes a sortable table displaying stream details such as owner, incoming port, destination, protocol, SSL status, and online/offline state. Users can filter streams via a search bar, toggle stream enablement, edit or delete existing streams, and create new ones, all subject to appropriate permission checks.

frontend/src/pages/Nginx/Streams · high confidence

New UI component library and layout system

The frontend now includes a comprehensive set of reusable UI components and a structured layout system. Users will see a new \Page\ component that enforces a consistent header-main-footer grid layout, along with dedicated \SiteHeader\, \SiteMenu\, and \SiteFooter\ components that handle navigation, user profile dropdowns, and version information. The interface now features a \ThemeSwitcher\ for toggling between light and dark modes, a \LocalePicker\ for changing languages, and a \Button\ component with extensive styling options (variants, sizes, colors). Additional utility components like \Loading\, \EmptyData\, \HasPermission\ (for role-based UI visibility), and \NavLink\ are now available to standardize the user experience across the application.

frontend/src/components · high confidence

New Users management page with role-based access control

A new Users management interface has been added, allowing administrators to view, search, and manage user accounts. The page includes a table displaying user avatars, names, emails, roles, and status, along with actions to edit user details, modify permissions, set passwords, enable/disable accounts, delete users, and log in as another user. Access to this page is restricted by the ADMIN section and VIEW permission, ensuring only authorized users can manage the user list.

frontend/src/pages/Users · high confidence

New authentication, permissions, and validation modules

The frontend now includes dedicated modules for managing authentication state, user permissions, and input validation. The new AuthStore handles token storage and validation in localStorage, supporting a stack of tokens with expiration checks. A Permissions module defines access control rules for sections like proxy hosts, streams, and certificates, allowing for granular view and manage permissions based on user roles. Additionally, a Validations module provides reusable validators for strings, numbers, emails, and domains, including support for wildcard domains and internationalized error messages.

frontend/src/modules · high confidence

New backend internal modules for 2FA, access lists, audit logging, and host management

The backend/internal directory now contains dedicated modules for Two-Factor Authentication (2fa.js), Access List management (access-list.js), Audit Logging (audit-log.js), and core Host/Certificate/Proxy/Redirection/Dead-Host logic. This introduces TOTP-based 2FA support with backup codes, allows configuring IP-based and user-based access rules for proxy hosts, records all significant user actions (create, update, delete) into an audit log table, and centralizes the logic for managing proxy, redirection, and dead hosts including their SSL certificates and Nginx configuration generation.

backend/internal · high confidence

New backend scripts for certbot plugin installation and Nginx config regeneration

Added two new executable scripts to the backend: \install-certbot-plugins\ allows users to install DNS plugins (either all defined in \dns-plugins.json\ or specific ones) with error reporting, and \regenerate-config\ iterates over all enabled proxy, redirection, dead, and stream hosts to regenerate their Nginx configurations, supporting unattended (\-y\) and dry-run (\--dry-run\) modes.

backend/scripts · high confidence

New development environment with DNS routing, proxying, and certificate support

The \docker/dev\ directory now provides a complete local development stack. The Dockerfile builds on the \nginxproxymanager/nginx-full:certbot-node\ image, installing development tools like \logrotate\ and \task\, and configuring a self-signed CA for testing HTTPS. It includes a DNS router configuration (\dnsrouter-config.json\) to resolve example domains locally, a Squid proxy configuration (\squid.conf\) for intercepting traffic, and a PowerDNS database schema (\pdns-db.sql\) to support dynamic DNS records. Additionally, a Let's Encrypt configuration file (\letsencrypt.ini\) is provided to streamline certificate generation during development.

docker/dev · high confidence

New form field components for proxy host configuration

The frontend now includes a new set of reusable form components in \frontend/src/components/Form\ to support the proxy host modal. These components provide UI controls for managing access lists (\AccessField\, \AccessClientFields\), basic authentication (\BasicAuthFields\), domain names (\DomainNamesField\), and SSL certificates (\SSLCertificateField\, \SSLOptionsFields\). Additionally, \DNSProviderFields\ allows users to configure DNS challenges for certificate issuance, \LocationsFields\ enables the management of multiple proxy locations with filtering and collapsing, and \NginxConfigField\ provides a code editor for advanced Nginx configuration.

frontend/src/components/Form · high confidence

New internationalization infrastructure with expanded language support

The frontend now includes a dedicated internationalization module (IntlProvider) that manages locale switching, flag code resolution, and translation wrapping for the user interface. This change introduces support for a significantly expanded set of languages, including Polish, French, Spanish, Azerbaijani, Slovak, Irish, Portuguese (pt-PT), Italian, Russian, Chinese, Vietnamese, Japanese, Estonian, Czech, Indonesian, Ukrainian, and Hungarian, in addition to existing locales. It also implements safer date parsing and formatting utilities that handle Unix timestamps and ISO strings robustly, with specific locale-aware adjustments such as using a 24-hour clock for Estonian. The module includes comprehensive tests for date formatting, flag code mapping, and translation completeness to ensure reliability.

frontend/src/locale · high confidence

New shared table component with sorting and responsive layout

A new shared table component has been introduced in the frontend, built on TanStack Table v9. This component provides a consistent table layout with a sticky header, responsive design for mobile devices, and built-in column sorting capabilities. It includes features for empty state handling, pagination, filtering, and sorting state management, ensuring a uniform user experience across all tables in the application.

frontend/src/components/Table · high confidence

New table formatters for certificates, access lists, and audit logs

The frontend now includes a new set of table column formatters to improve the display of specific data types. Users will see certificates formatted by their provider (e.g., Let's Encrypt, custom), access lists displayed as clickable buttons that open a detail modal, and audit log events rendered with contextual icons and color-coded actions. Additionally, dates can now be highlighted as past or nearly expired (within 30 days), domains are shown as clickable badges (with wildcards handled safely), and boolean statuses use a standardized animated dot indicator. These components replace previous inline logic with reusable, consistent UI elements across the application's tables.

frontend/src/components/Table/Formatter · high confidence

Security

Security and configuration hardening in backend library

The backend library now enforces stricter security and configuration handling. JWT key files are generated with restricted permissions (0600) to prevent unauthorized access. Token validation has been strengthened to invalidate any tokens issued before a password change, ensuring that compromised sessions are terminated immediately upon credential updates. Additionally, the configuration system now supports MySQL SSL options and automatically migrates legacy MySQL engine references to mysql2, while the certbot plugin installation process is hardened to prevent command injection by using safer execution methods.

backend/lib · high confidence

Behavioural changes

API schema validation and documentation restructured

The backend schema module has been refactored to use a centralized JSON Schema and OpenAPI 3.1.0 specification. A new JavaScript module now compiles and caches the Swagger schema to provide runtime validation for API requests, ensuring that inputs like domain names and email addresses adhere to stricter patterns. This change also updates the API documentation to reflect the current endpoint structure and security schemes.

backend/schema · high confidence

Audit log page now displays owner avatars and event details

The Audit Log page has been updated to show a column of user avatars (Gravatars) for the event owner, with sorting disabled for this column. The table now displays the event type and includes a 'View details' button that opens a modal for each log entry. Access to this page is restricted to users with ADMIN and VIEW permissions.

frontend/src/pages/AuditLog · high confidence

Backend and Nginx services now run as configurable non-root user

The Docker container's init scripts for the backend and Nginx services have been updated to support running as a specific user and group defined by the PUID and PGID environment variables. Previously, these services likely ran as root; now, the s6-overlay scripts use s6-setuidgid to switch to the specified user (defaulting to npmuser if PUID/PGID are not set or are zero) before executing Node.js and Nginx processes. This change improves security by avoiding root execution and allows users to map container file permissions to their host system's user/group IDs.

docker/rootfs/etc/s6-overlay/s6-rc.d/backend · high confidence

Backend application structure and startup logic introduced

The backend directory now contains the core application entry points and configuration files, including \app.js\ (Express server setup with security headers and error handling), \index.js\ (startup sequence handling database migrations, initial setup, and IP range fetching), \db.js\ (Knex database connection management), \setup.js\ (logic for creating default admin users, settings, and certbot plugins), and \migrate.js\ (database migration execution). This change establishes the foundational runtime environment for the backend service, replacing previous implicit or external structures with explicit ESM modules for configuration, logging, and initialization.

backend · high confidence

Backend models refactored to ESM with new access list and multi-database support

The backend models have been converted to ES modules and now support multiple database engines (including PostgreSQL) via a new \now\_helper\ that adapts timestamp generation. This change introduces new data models for Access Lists and their associated authentication and client details, allowing users to restrict access to proxy hosts. Additionally, the Certificate model now tracks usage across streams, and the Proxy Host model includes a new \trust\_forwarded\_proto\ option to improve SSL redirect handling in reverse proxy scenarios.

backend/models · high confidence

Certificates page rewritten with React Table and new UI components

The Certificates page has been rebuilt using the React Table library (TanStack Table) and a new component structure (Table, TableWrapper). This change introduces a modernized user interface with features such as client-side search filtering, improved status indicators for certificate usage (proxy/redirect/dead hosts), and a permission-gated action menu for renewing, downloading, or deleting certificates. The view now supports adding new certificates via HTTP, DNS, or custom upload directly from the header, replacing the previous implementation.

frontend/src/pages/Certificates · high confidence

Comprehensive Nginx reverse proxy configuration overhaul

This change introduces a new modular Nginx configuration structure in the include directory, significantly enhancing security, performance, and reliability. Security is improved by adding \block-exploits.conf\ to filter SQL injections, file injections, and common exploits, while \assets.conf\ now supports modern web formats (WebP, WOFF2) and enforces strict caching rules. SSL handling is refined with \force-ssl.conf\, which introduces a \trust\_forwarded\_proto\ option to correctly manage HTTPS redirections behind reverse proxies, and \ssl-ciphers.conf\ updates protocols to TLSv1.2/1.3 with a modern cipher suite. Reliability is boosted by \letsencrypt-acme-challenge.conf\ allowing ACME challenges through authentication layers, and \proxy.conf\ standardizes header forwarding (including \X-Real-IP\ and \X-Forwarded-Proto\) to ensure accurate client identification and protocol detection.

docker/rootfs/etc/nginx/conf.d/include · high confidence

Container startup now enforces root execution and configures runtime user/group ownership

The container's initialization scripts have been updated to require that the container is initially run as root, rejecting any attempt to start as a non-root user. During startup, the system now creates or updates a dedicated \npmuser\ and \npmgroup\ based on the \PUID\ and \PGID\ environment variables, ensuring that critical directories (such as \/data\, \/etc/nginx\, and certbot paths) are owned by this user. This change allows the container to manage file permissions securely while allowing processes to run as a specific non-root user defined at runtime. Additionally, the admin port can now be customized via the \NPM\_ADMIN\_PORT\ environment variable, and IPv6 settings in nginx configurations are dynamically adjusted based on the \DISABLE\_IPV6\ flag.

docker/rootfs/etc/s6-overlay/s6-rc.d/prepare · high confidence

Default Nginx welcome page updated to use Bootstrap 3.4.1

The default landing page served by Nginx Proxy Manager when accessing an unconfigured host has been updated. The new index.html file now utilizes Bootstrap version 3.4.1 for styling, replacing the previous version. Users will see a refreshed 'Congratulations!' message with updated CSS classes and layout when visiting the default site.

docker/rootfs/var · high confidence

Frontend application restructured with React, React Router, and Tabler UI

The frontend application has been rebuilt using React and Vite, replacing the previous implementation. This change introduces a new component-based architecture with lazy-loaded routes for pages such as Setup, Login, Dashboard, and Nginx host management. It integrates the Tabler UI framework for styling, including specific CSS adjustments for dark mode support, modal backdrops, and dropdown visibility within tables. The application now utilizes React Query for data fetching, React Router for navigation, and a centralized modal manager, providing a more modern and responsive user experience.

frontend/src · high confidence

Frontend migration to Vite and Biome tooling

The frontend build system has been migrated to Vite, replacing the previous bundler, and code quality is now enforced by Biome (schema v2.5.10) instead of the prior linter. This change introduces a new TypeScript configuration (targeting ES2020 with React JSX transform) and a locale compilation pipeline that automatically runs during development and CI builds. Additionally, the application now uses Vitest with Happy-DOM for testing, and the HTML entry point has been updated to preload the logo to improve performance.

frontend · high confidence

Health check and common utility scripts added to container rootfs

The container image now includes a new health check script at /usr/bin/check-health that verifies the status of the Nginx Proxy Manager API by querying the admin port (defaulting to 81, but configurable via the NPM\_ADMIN\_PORT environment variable) and returning a simple OK/NOT OK status. Additionally, a common.sh utility script has been added to /usr/bin/common.sh, providing shared environment variables (such as PUID, PGID, NPMUSER, NPMGROUP), color-coded logging functions (log\_info, log\_error, log\_fatal), and helper utilities like is\_true and is\_mounted, which standardize user/group handling and logging across the container's entrypoint scripts.

docker/rootfs/usr · high confidence

New default, development, and production Nginx server configurations

The Nginx configuration now includes three distinct server block files: a default configuration for handling unconfigured HTTP/HTTPS traffic with specific fallback logging, a development configuration serving the frontend from a dist directory and proxying API requests to local ports 3000 and 5173, and a production template that supports a configurable admin port via the NPM\_ADMIN\_PORT environment variable while proxying API calls to port 3000.

docker/rootfs/etc/nginx/conf.d · high confidence

New development environment scripts using Docker Compose

The repository now includes a new set of shell scripts in the \scripts/\ directory to manage the local development environment. These scripts, including \start-dev\, \stop-dev\, \destroy-dev\, \cypress-dev\, \docs-build\, \docs-upload\, \buildx\, and \wait-healthy\, rely on the \docker compose\ CLI (replacing the legacy \docker-compose\ command) and a shared configuration file (\.common.sh\). This change provides a standardized way to spin up the full dev stack (including DNS, database, and application services), run end-to-end tests, build documentation, and perform multi-architecture Docker builds.

scripts · high confidence

Nginx configuration restructured with explicit MIME types and custom include points

The Nginx configuration has been reorganized to explicitly define MIME types via a new mime.types file and to introduce specific hooks for custom configurations. The main nginx.conf now includes custom directives at the root level, within the events block, and at the top and bottom of the http and stream blocks, allowing users to inject settings without modifying core templates. Additionally, the configuration now explicitly sets real IP determination to trust only local subnets and NPM-generated CDN IP ranges, and it includes dynamic resolvers and log formats for both HTTP and stream proxies.

docker/rootfs/etc/nginx · high confidence

Nginx configuration templates restructured into modular includes

The Nginx configuration generation logic has been refactored from monolithic template files into a modular system using shared includes. Common features such as SSL certificates, HSTS headers, access control lists, and exploit blocking are now handled by dedicated partial templates (e.g., \_certificates.conf, \_access.conf, \_hsts.conf) included within host-specific templates (proxy, redirection, dead, and stream). This change ensures consistent application of security settings like HSTS and access rules across all host types and simplifies the maintenance of shared Nginx directives.

backend/templates · high confidence

Nginx resource API routes converted to ESM

The backend API route handlers for Nginx resources (access lists, certificates, dead hosts, proxy hosts, redirection hosts, and streams) have been rewritten to use ES Modules (import/export syntax) instead of CommonJS. This change modernizes the server-side codebase, aligning these specific route files with the project's broader migration to ESM, while preserving the existing REST endpoints and validation logic.

backend/routes/nginx · high confidence

The Proxy Hosts page has been rebuilt using React components (Table and TableWrapper) to replace the previous implementation. This update introduces client-side column sorting for domain names and destinations, a text-based search filter for domains and hosts, and a more detailed delete confirmation modal that displays the host's domain names and destination address. The view also integrates permission checks for managing proxy hosts and uses standard UI components for status indicators and action menus.

frontend/src/pages/Nginx/ProxyHosts · high confidence

Refactor CI scripts to use Docker Compose v2 and new frontend build process

The CI pipeline scripts in \scripts/ci\ have been restructured to replace the legacy \docker-compose\ command with the \docker compose\ (v2) plugin. A new \frontend-build\ script has been introduced to handle frontend compilation, linting, and testing within a dedicated Docker container (\nginxproxymanager/nginx-full:certbot-node\), while \test-and-build\ now manages backend testing and the main Docker image build. The \fulltest-cypress\ script has been updated to orchestrate the full-stack test environment using \docker compose\, including dynamic DNS configuration and container health checks.

scripts/ci · high confidence

Refactored API schema validation with new validator modules

The backend's validation logic has been restructured into two new modules: \api.js\ and \index.js\. The new \api.js\ module provides an async validator using AJV (2020 spec) that returns the validated payload on success or throws a \ValidationError\ with debug details on failure. The new \index.js\ module offers a synchronous-style validator (wrapped in a Promise) that also uses AJV, includes common schema definitions, and returns a deep clone of the payload on success or rejects with an \InternalValidationError\ on failure. This change replaces the previous validation implementation, altering how validation errors are reported and how payloads are handled (returned vs cloned).

backend/lib/validator · high confidence

Refactored backend middleware to ESM and expanded CORS support

The backend middleware in backend/lib/express has been converted to ES modules (ESM) and restructured into individual files. This change introduces support for PUT and DELETE HTTP methods in the CORS configuration, addressing issues with cross-origin requests for these methods. Additionally, the JWT decoding middleware now properly initializes access control, and a new middleware allows resolving 'me' to the authenticated user's ID in API routes.

backend/lib/express · high confidence

Replaced legacy modals with new React-based components

The frontend's modal dialogs have been rewritten in React to improve maintainability and user experience. This change introduces new, dedicated modal components for managing proxy hosts, redirection hosts, dead hosts, access lists, and user permissions, as well as for handling certificate creation (including custom uploads, DNS, and HTTP challenges) and user password changes. A new centralized modal manager and a reusable delete-confirmation modal have also been added to standardize dialog behavior across the application.

frontend/src/modals · high confidence

Updated S6-overlay to version 3.2.3.0

The Docker build process now installs S6-overlay version 3.2.3.0. This update is handled by a new installation script that supports linux/arm64 and linux/amd64 architectures, replacing previous versions to ensure the container runtime uses the latest overlay features.

docker/scripts · high confidence

Version 2.15.1 release with security policy and documentation updates

This release updates the project to version 2.15.1, introducing a formal security policy via a new SECURITY.md file that outlines supported versions and directs vulnerability reports to GitHub's private advisory system. The documentation has been refreshed to reflect the current version, and the .gitignore file has been updated to exclude additional local IDE and development artifacts.

(repo-wide) · high confidence

Test coverage

Added Cypress backend API plugin for test automation; Added Cypress configuration files for CI and development environments; Expanded Cypress API test coverage; New Cypress plugin configuration for test infrastructure; New Cypress test support infrastructure.

Dependencies

Major dependency upgrades across backend, frontend, test, and docs

This release performs a comprehensive upgrade of dependencies across all project areas. The backend migrates to Express 5, Knex 3, Objection 3, and bcrypt 6, while also adding better-sqlite3 support and switching the module system to ESM. The frontend upgrades to React 19, Vite 8, and TypeScript 7, and adds react-qr-code for TOTP authentication. The test suite moves to Cypress 16 and Mocha 12, and the documentation site switches to VitePress 1.6.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 42.

Lenses

  • Code Health 72
  • Architecture 62
  • Maturity 60
  • Readiness 23
  • Security 72
  • Accessibility 53

Changes since last survey

  • 300 commits — 255 feature/other, 45 fixes

By area

  • (repo) — 129 commits
  • frontend/src — 33 commits
  • test/yarn.lock — 20 commits
  • frontend/package.json — 15 commits
  • backend/internal — 12 commits
  • backend/certbot — 10 commits
  • backend/package.json — 9 commits
  • backend/yarn.lock — 9 commits
  • backend/lib — 6 commits
  • frontend/yarn.lock — 6 commits
  • test/cypress — 6 commits
  • (root) — 5 commits
  • docker/rootfs — 5 commits
  • test/package.json — 5 commits
  • .github/PULL_REQUEST_TEMPLATE.md — 4 commits
  • docs/src — 4 commits
  • backend/biome.json — 3 commits
  • backend/models — 3 commits
  • backend/setup.js — 3 commits
  • docs/yarn.lock — 3 commits

Notable commits

  • fix: Attempt to fix #5335 by allowing resovler generation to be opt-out with a env var
  • fix: Fix #5284 for older sqlite3 configurations
  • fix: Fix #5802 404 hosts disable missing async/await paradigm
  • fix: Fix backend linting
  • fix: Fix certificates getting null domain names whgen no cn exists
  • fix: Fix cypress suite
  • fix: Fix frontend linting
  • fix: Fix incorrect html description
  • fix: Fix missing new on PermissionError in access.can()
  • fix: Fix nulls showing in certificate rows
  • fix: Fix regression of null domains in db creates
  • fix: Fix ru.json
  • fix: Fix silent config corruption in 50-ipv6.sh on NFS volumes
  • fix: Fix translation in streams table ignoring current enable/disable state
  • fix: Fix uploading of custom certificates
  • fix: Fixed Estonian flag bug
  • fix: Fixes for upgraded debian trixie
  • fix: Merge pull request #5308 from YTKme/ytkme/fix-sqlite-internal-error
  • fix: Merge pull request #5317 from Tech-no-1/fix-custom-certificates
  • fix: Merge pull request #5334 from bill-mahoney/fix/atomic-ipv6-config-write
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

NginxProxyManager/nginx-proxy-manager was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 568c10594517b999dbb2240d9f7a6014b1c4bb2a — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.