paragonie/random_compat
55.7
Weak · 26 September 2026
1.4k
lines of production code
PHP
primary language
4
measurements over time
What this system is
Features
Add repository configuration and testing infrastructure
The repository now includes a .gitattributes file to manage file exports and a .gitignore file to exclude build artifacts and dependencies. Additionally, the project has introduced a .scrutinizer.yml file for code quality checks, a CHANGELOG.md for release history, a RATIONALE.md explaining design decisions, and a SECURITY.md file outlining the vulnerability disclosure policy. The project also added a build script for PHP archives and configuration files for PHPUnit and Psalm static analysis tools.
(repo-wide) · high confidence
Added IDE and static analysis stubs for COM, com\_exception, and libsodium
New PHP stub files have been added to the \other/ide\_stubs\ directory to improve IDE autocomplete and reduce false positive errors in PHPStorm and other IDEs. Specifically, stubs for the \COM\ class (with a \GetRandom\ method), the \com\_exception\ class, and the \libsodium\ namespace (including \randombytes\_buf\, \randombytes\_random16\, and \randombytes\_uniform\ functions) are now available. These files also provide type information for Psalm static analysis. The \libsodium\ stubs are designed to be harmless if the actual extension is loaded, while the \COM\ stubs help with IDE intelligence without affecting runtime behavior.
_other/ide\stubs · high confidence
Added PHP 5 compatibility polyfills for random number generation
The library now includes a set of PHP 5 polyfill files in the lib directory to provide the PHP 7 random\\ API (random\_bytes, random\_int) for older PHP versions. This includes byte-safe string functions (strlen, substr) that handle mbstring.func\_overload, a safe integer casting utility, and error class polyfills (Error, TypeError). The main random.php entry point dynamically loads specific backends (libsodium, /dev/urandom, mcrypt, COM) to generate random bytes, ensuring secure random number generation across different environments and PHP versions.
lib · high confidence
Added build script and PHPUnit shim
Added a new PHP script, build\_phar.php, which packages the library into a PHAR archive and optionally signs it with OpenSSL. Also added phpunit-shim.php to provide backward compatibility for older PHPUnit test cases.
other · high confidence
Behavioural changes
Added PHAR signature verification files
The dist directory now includes the public key (random\_compat.phar.pubkey) and its corresponding PGP signature file (random\_compat.phar.pubkey.asc). These files enable users to verify the authenticity and integrity of the random\_compat.phar archive.
dist · medium confidence
Test coverage
Added full test suite for statistical and compression checks; Added specific test files for each CSPRNG source; Added unit tests for random number generation and utility functions; Added unit tests for random\_bytes, random\_int, and utility functions.
Dependencies
Initial release of paragonie/random\_compat package
The project has been packaged as a Composer library named paragonie/random\_compat. This library provides a polyfill for the random\_bytes() and random\_int() functions from PHP 7, ensuring compatibility with PHP 5.2.0 and later. The package includes autoloading for the random functions and suggests using the libsodium extension for improved cryptographic security.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 47 → 56 (+8.3)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 100 (+0.0)
- Architecture 69 → 69 (+0.0)
- Maturity 59 → 37 (-22.6)
- Readiness 25 → 62 (+36.9)
- Security 73 → 100 (+27.4)
Resolved (15)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- No exposed public API
- No tests found
- Test reliability not included
New (18)
- Documentation: no contributor guidance (README.md)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- No dependency advisory monitoring
- Orphaned files with no living knowledge
- Skipped (documented): testIntval (tests/unit/UtilityTest.php)
- Skipped (documented): testStrlen (tests/unit/UtilityTest.php)
- Workflow token permissions not restricted
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
paragonie/random_compat was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit b5d188cc9d5e02f94d2c41da23093f1ef557c5b1 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-a15879f6f801.