Skip to content
CAI
Software that uses CAICheck a score

Phineas/lanyard

50.8

Weak · 23 September 2026

2.4k

lines of production code

Elixir

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a self-hostable Discord presence monitoring service that aggregates user status data via WebSocket and REST APIs. It enables real-time presence tracking and allows users to store custom key-value pairs associated with their profiles through both bot commands and API endpoints. The architecture supports distributed deployments with Redis-based synchronization, comprehensive Prometheus metrics, and modern Elixir infrastructure.

Features

The quicklinks API now includes a new route that proxies avatar images directly from the Discord CDN. This implementation fetches the user's presence data to retrieve their avatar hash and constructs the appropriate CDN URL. It handles default avatar logic for users without avatars (using discriminator modulo for older accounts or user ID shift for newer ones) and intelligently defaults static GIFs to JPG format to avoid playback issues. The proxy uses the Finch HTTP client to fetch the image and returns it to the client with the original status code and headers, while also tracking request metrics.

lib/api/routes/quicklinks · high confidence

Initial public release with Docker support and comprehensive documentation

The repository is now publicly available with a complete MIT license, a detailed README covering API and socket usage, community projects, and a showcase. Docker support has been added via a new Dockerfile and .dockerignore, allowing users to self-host the service. The Elixir formatter configuration has been updated to enforce a 120-character line length, and the .gitignore file has been expanded to include VSCode Elixir LS artifacts and Redis dump files.

(repo-wide) · high confidence

Introduces KV storage interface with validation and limits

The \lib/kv/interface.ex\ module now provides the core API for user key-value storage, including \get\, \set\, \multiset\, and \del\ operations. This implementation enforces strict limits: a maximum of 512 keys per user, keys limited to 255 alphanumeric characters (a-z, A-Z, 0-9, \_), and values capped at 30,000 characters. Invalid inputs trigger validation failure metrics and return specific error messages, while successful writes sync state to Redis and update user presence.

lib/kv · high confidence

New Discord bot commands for key-value storage and API key management

Users can now manage custom data on their Lanyard profile directly through Discord using new bot commands. The \.apikey\ command generates or regenerates a secret API key via DM, which is required for data operations. Users can store data with \.set \<key\> \<value\>\, retrieve it with \.get \<key\>\, view all stored keys with \.kv\, and remove entries with \.del \<key\>\. A \.help\ command is also available to list these options. The system includes security measures that automatically regenerate the API key if it is accidentally posted in a public channel.

lib/bot/commands · high confidence

New Prometheus metrics endpoint for monitoring system health

A new /metrics HTTP endpoint has been added to expose Prometheus-compatible metrics, supporting both text and protobuf formats. This change introduces comprehensive monitoring for HTTP response codes (including a separate counter for 404s to distinguish them from other 4xx errors), Discord gateway connectivity and event statistics, Redis command performance, and Erlang VM resource usage such as memory and process counts, allowing users to track the service's operational status and performance.

lib/metrics · high confidence

New Redis connectivity module for presence sync and data operations

A new Redis client module has been added to handle global presence synchronization across Lanyard nodes and general key-value operations. It supports both IPv4 and IPv6 connections (configurable via the REDIS\_IPV6 environment variable) and subscribes to a global sync channel to apply presence diffs from other nodes. The module also exposes standard Redis commands (GET, SET, HSET, HGETALL, etc.) and tracks command metrics for observability.

lib/connectivity · high confidence

New WebSocket socket handler with subscription and metrics support

Introduces the \Lanyard.SocketHandler\ module to manage WebSocket connections, enabling clients to subscribe to presence data for specific IDs, a single ID, or all users. The handler validates incoming JSON payloads, rejecting invalid operations with specific error codes (e.g., 4005 for missing data, 4006 for invalid payloads), and integrates Prometheus metrics collection for inbound messages, connection counts, and socket lifecycle events.

lib/socket · high confidence

Behavioural changes

API router overhaul with CORS, metrics, and new endpoints

The API router has been significantly restructured to support new routing and observability features. A new /discord route is now available, alongside a /metrics endpoint for Prometheus data. Cross-Origin Resource Sharing (CORS) is now enabled by default for all origins and methods. The root endpoint now returns service status information, including the count of monitored users. Additionally, a quicklinks feature allows direct proxying of Discord CDN images in various formats (png, gif, webp, jpg, jpeg). Under the hood, the JSON library has been switched from Poison to Jason, and comprehensive HTTP request metrics (duration, status codes, exceptions) are now collected.

lib/api · high confidence

Configuration modernized with environment-driven settings and new runtime config

The application configuration has been updated to use the modern Elixir \import Config\ syntax instead of the deprecated \Mix.Config\. A new \config/runtime.exs\ file has been introduced to handle production-specific settings that require runtime evaluation, such as the \EXTERNAL\_URL\ and idempotency flags. Additionally, the configuration now supports a wider range of environment variables across all environments, including \PORT\, \COMMAND\_PREFIX\, \BOT\_PRESENCE\, \BOT\_PRESENCE\_TYPE\, \REDIS\_DSN\ (with fallbacks to \REDIS\_URI\/\REDIS\_URL\), \REDIS\_IPV6\, and \IS\_IDEMPOTENT\, allowing for more flexible deployment and operational control.

config · high confidence

Discord bot now supports session resumption and automatic restarts on crash

The bot now maintains resume data to reconnect to the Discord gateway without losing state after disconnections, and automatically restarts its internal gateway client if the process crashes. This change also introduces a new command handler structure for managing bot commands and switches the underlying HTTP client from HTTPoison to Finch with Jason for JSON encoding.

lib/bot · high confidence

Gateway upgrades to Discord API v10 and switches to JSON encoding

The gateway client now connects using the v10 Discord API version and transmits data using JSON instead of the previous Erlang term (etf) format. This change requires the client to handle text-based payloads, updates the heartbeat mechanism to track latency metrics, and enforces session resuming on disconnect to maintain state across reconnections. Additionally, the client now requests specific gateway intents (such as guild members and presences) to align with the new API requirements.

lib/gateway · high confidence

New Discord redirect and metrics routes; removal of legacy user presence endpoint

The API now exposes a new /discord route that redirects users to the official Discord server, and a /metrics route that integrates with the Prometheus exporter for observability. Additionally, the previous /users/:id endpoint, which returned presence data, has been removed from the API.

lib/api/routes · high confidence

New V1 API router with @me support and KV operations

The API now exposes a structured V1 router that includes a new GET /@me endpoint, allowing users to retrieve their own presence data using their API key without specifying a user ID. Additionally, the /:id/kv routes have been implemented to support key-value storage operations (PUT, PATCH, DELETE), enabling users to manage custom key-value pairs associated with their presence. The router also normalizes authentication handling and supports @me as a valid user ID for these KV routes, simplifying client interactions for self-referential operations.

lib/api/routes/v1 · high confidence

Presence updates now include KV data and fan out to all subscribers

Presence updates now include the user's KV data alongside standard Discord presence fields. The system has been refactored to fan out these updates to all active subscribers using Manifold, ensuring that multiple clients receive real-time presence changes. Additionally, the presence module now handles subscriber lifecycle management, preventing duplicate subscriptions and cleaning up resources when subscribers disconnect.

lib/presence · high confidence

Switch to Bandit HTTP server and add presence caching

The application now uses Bandit instead of Plug.Cowboy for handling HTTP requests, with the server port configurable via the \http\_port\ environment variable. Additionally, ETS tables are introduced to cache presences and manage global subscribers, supporting the new ability to subscribe to all Lanyard presences. The supervisor also now includes a Finch HTTP client and a dedicated metrics module, while an idempotency check based on an environment variable has been added to support running multiple replicas.

lib · high confidence

Test coverage

Removal of test suite files

The test suite files \test/lanyard\_test.exs\ and \test/test\_helper.exs\ have been deleted, removing the existing unit tests and ExUnit configuration from the project.

test · high confidence

Dependencies

Major dependency overhaul and Elixir runtime upgrade

The project has upgraded its Elixir requirement from version 1.11 to 1.19 and performed a comprehensive update of its dependency tree. The HTTP server backend was switched from Plug/Cowboy to Bandit, and JSON handling moved from Poison to Jason. New dependencies were added to support CORS (Corsica), HTTP client operations (Finch), Redis connectivity (Redix), and Prometheus metrics (Prometheus\_ex), while older packages like Plug\_Cowboy and Poison were removed.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 52 → 51 (-1.4)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 94 → 96 (+2.4)
  • Architecture 100 → 79 (-21.0)
  • Maturity 40 → 50 (+9.8)
  • Readiness 44 → 34 (-9.8)
  • Security 71 → 80 (+8.4)

Resolved (10)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — no supported dependency manifest was read
  • Duplicated block (15 lines × 2) (lib/gateway/client.ex)
  • High IaC: DS-0025 (Dockerfile)
  • Low IaC: DS-0005 (Dockerfile)
  • Medium IaC: CKV_DOCKER_3 (Dockerfile)
  • Medium IaC: CKV_DOCKER_4 (Dockerfile)
  • Medium IaC: CKV_DOCKER_4 (Dockerfile)
  • No exposed public API
  • The 'In a React app' section begins but is cut off mid-sentence ('Many Lanyard users render...') before the recommended library or how to integrate it into a React project is fully stated. (README.md)

New (21)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (18–19 lines × 2) (lib/gateway/client.ex)
  • Duplicated block (6 lines × 3) (lib/bot/commands/del.ex)
  • High IaC: DS-0025 (Dockerfile)
  • High IaC: DS-0025 (Dockerfile)
  • Low IaC: DS-0005 (Dockerfile)
  • Low IaC: DS-0005 (Dockerfile)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium IaC: WD-DOCKER-0003 (Dockerfile)
  • Medium IaC: WD-DOCKER-0003 (Dockerfile)
  • Medium: security finding (details withheld)
  • No ADRs found
  • No automated tests
  • No dependency advisory monitoring
  • No tests found
  • Outdated: bandit
  • Outdated: redix
  • Repeated repair: lib/api/routes/v1/users.ex (lib/api/routes/v1/users.ex)
  • …and 1 more

Changes since last survey

  • 2 commits — 1 feature/other, 1 fixes

By area

  • lib/api — 1 commit
  • lib/bot — 1 commit

Notable commits

  • fix: fix: resume
  • change: Separate metrics for 404 from rest of 4xx

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

Phineas/lanyard was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit d58672b96e468b3bf272203ba87448fe71999f49 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.