Skip to content
CAI
Software that uses CAICheck a score

philc/vimium

35.9

Weak · 25 September 2026

12.7k

lines of production code

JavaScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Add script to generate static command listing page

A new build script (write\_command\_listing\_page.js) has been added to generate a static version of the command\_listing.html page for hosting on vimium.github.io. The script processes the page, copies required CSS files to the dist directory, removes external JavaScript references, and outputs a self-contained index.html file.

_build\scripts · medium confidence

Initial project commit and release notes

The repository was initialized with the core project files, including a comprehensive CHANGELOG.md documenting the history of Vimium releases from version 1.67.7 back to the initial commit. The commit also added standard project documentation files: a .gitignore to exclude the dist directory, a CONTRIBUTING.md guide for developers, a CREDITS file listing authors and contributors, an MIT-LICENSE.txt, and a README.md detailing installation and usage.

(repo-wide) · high confidence

New test harnesses for development and debugging

Several new test harnesses have been added to the test\_harnesses directory to aid in the development and debugging of Vimium features. These include pages for testing cross-origin iframes, event capture, form elements, link hints (including image maps and padding), visibility checks, and the Vomnibar UI. These pages provide isolated environments to test specific browser behaviors, element visibility states, and UI components without needing to navigate to external sites or complex page structures.

_test\harnesses · high confidence

Architecture

Refactored content scripts into separate directories for background and content execution

Content scripts and background scripts are now organized into separate directories, clarifying their respective execution modes and purposes. This structural change is accompanied by the conversion of several core modules—including link hints, modes (normal, insert, find, visual), and the HUD—into JavaScript, alongside CSS and utility file reorganizations.

_content\scripts · high confidence

Behavioural changes

Migrate to new Settings API and refactor lib modules

Vimium now uses a new Settings API that stores each setting as a top-level key in chrome.storage.sync, replacing the previous JSON-encoded object structure. A migration is provided to upgrade pre-2.0.0 settings from their old format. The lib directory has been refactored into separate JavaScript modules (e.g., settings.js, utils.js, dom\_utils.js) to improve modularity and testability. Additionally, the codebase has been ported to use Deno for testing, with corresponding stubs for Chrome APIs and test utilities added to support this new testing environment.

lib · high confidence

Redesigned options and settings pages with improved layout and dark mode support

The options page has been completely rewritten to use a modern grid layout, moving custom key mappings and search engines above the fold for better discoverability. The interface now supports dark mode, and the footer is fixed to the bottom of the page. Additionally, the action popup has been redesigned to display exclusion rules directly, allowing users to manage per-page exclusions without leaving the current page. The help dialog and command listing pages have also been updated with dark mode styles and improved typography.

pages · high confidence

Refactor background scripts into modular, ES6 modules

The background scripts have been converted from CoffeeScript to ES6 modules, improving code clarity and separation of concerns. Key changes include the creation of dedicated modules for commands (commands.js, all\_commands.js), tab operations (tab\_operations.js), and exclusions (exclusions.js). The command registry is now a structured data object in all\_commands.js, which is used by the help dialog and command listing. The key mapping parser has been extracted into a dedicated class in commands.js, allowing the options page to display validation errors for invalid key mappings. Additionally, the TabRecency tracker has been moved to its own module (tab\_recency.js) and persisted to chrome.storage.session for better state management.

_background\scripts · medium confidence

Refactored completion system into modular components

The completion logic has been reorganized into separate files: completers.js defines the Suggestion class and UI rendering, ranking.js handles relevance scoring, search\_engines.js contains the completion engine implementations, and search\_wrapper.js manages the request flow and caching. This modularization improves code maintainability and separation of concerns within the Vomnibar's suggestion system.

_background\scripts/completion · medium confidence

Test coverage

Add DOM test suite for link hints, DOM utilities, and mode state; Added shoulda.js test framework to vendor directory; Added unit tests for completion system; Added unit tests for core Vimium components.

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 33 → 36 (+3.3)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 47 → 37 (-10.1)
  • Architecture 89 (new)
  • Maturity 57 → 50 (-6.6)
  • Readiness 14 → 29 (+14.8)
  • Security 54 → 97 (+42.5)
  • Accessibility 30 (new)

Resolved (38)

  • (anonymous) (cognitive 18) (background_scripts/main.js)
  • Change coupling: link_hints.js ↔ marks.js (content_scripts/link_hints.js)
  • Change coupling: mode_find.js ↔ scroller.js (content_scripts/mode_find.js)
  • Change coupling: mode_insert.js ↔ scroller.js (content_scripts/mode_insert.js)
  • Change coupling: mode_visual.js ↔ scroller.js (content_scripts/mode_visual.js)
  • Dimension evaluation failed
  • FileTooLong: content_scripts/mode_find.js (content_scripts/mode_find.js)
  • FileTooLong: content_scripts/mode_normal.js (content_scripts/mode_normal.js)
  • FileTooLong: content_scripts/vimium_frontend.js (content_scripts/vimium_frontend.js)
  • FileTooLong: dom_tests/dom_tests.js (tests/dom_tests/dom_tests.js)
  • Hotspot: background_scripts/commands.js (background_scripts/commands.js)
  • Hotspot: content_scripts/mode.js (content_scripts/mode.js)
  • No exposed public API
  • Rotate the exposed credentials — git history can't be un-committed
  • Secret: generic-api-key (deno.lock)
  • Secret: generic-api-key (deno.lock)
  • Secret: generic-api-key (deno.lock)
  • Secret: generic-api-key (deno.lock)
  • Secret: generic-api-key (deno.lock)
  • Secret: generic-api-key (deno.lock)
  • …and 18 more

New (36)

  • (anonymous) (cognitive 23) (background_scripts/main.js)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • FilterHints.scoreLinkHint (cognitive 16) (content_scripts/link_hints.js)
  • HandlerStack.bubbleEvent (cyclomatic 16) (lib/handler_stack.js)
  • InsertMode.constructor (cognitive 18) (content_scripts/mode_insert.js)
  • InsertMode.constructor (cyclomatic 16) (content_scripts/mode_insert.js)
  • LinkHintsMode.activateLink (cognitive 28) (content_scripts/link_hints.js)
  • LinkHintsMode.onKeyDownInMode (cognitive 49) (content_scripts/link_hints.js)
  • LinkHintsMode.onKeyDownInMode (cyclomatic 27) (content_scripts/link_hints.js)
  • LinkHintsMode.rotateHints (cognitive 22) (content_scripts/link_hints.js)
  • Medium: security finding (details withheld)
  • Mode.init (cyclomatic 24) (content_scripts/mode.js)
  • Movement.runMovement (cognitive 35) (content_scripts/mode_visual.js)
  • Movement.runMovement (cyclomatic 20) (content_scripts/mode_visual.js)
  • Off-boarding risk: anonymized user #1
  • Repeated repair: tests/unit_tests/completion/completers_test.js (tests/unit_tests/completion/completers_test.js)
  • VisualMode.init (cyclomatic 36) (content_scripts/mode_visual.js)
  • VomnibarUI.actionFromKeyEvent (cyclomatic 26) (pages/vomnibar_page.js)
  • VomnibarUI.handleEnterKey (cognitive 20) (pages/vomnibar_page.js)
  • …and 16 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

philc/vimium was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 5aa29614bf1dce05e0d316f8c38722e17f9b38c3 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-dd72cc24c749.