Skip to content
CAI
Software that uses CAICheck a score

picocms/Pico

52.2

Weak · 19 September 2026

3.9k

lines of production code

PHP

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is Pico, a lightweight, PHP-based static site generator that converts Markdown content into HTML using the Twig templating engine and Parsedown parser. It provides a plugin architecture for extensibility and supports flexible content sorting and configuration via YAML. The project manages its dependencies through Composer and includes build scripts for generating release archives and documentation.

Removals

Removal of Twig library and documentation

The Twig template engine library and its associated documentation have been removed from the project. This change deletes the \lib/twig\ directory, including the source code, changelog, license, and all documentation files (such as \doc/advanced.rst\, \doc/api.rst\, and filter/function references). The \AUTHORS\ file and the PEAR packaging script (\bin/create\_pear\_package.php\) are also removed, indicating a shift away from the previous distribution and maintenance model for this component.

lib/twig · high confidence

Removal of legacy default theme assets

The default theme's HTML template, CSS styles, and the Modernizr 1.7 JavaScript library have been removed from the repository. This cleanup eliminates the legacy styling and browser-detection scripts that were previously bundled with the default theme, likely as part of a migration to a new theme structure or external dependency management.

themes · high confidence

Behavioural changes

New YAML-based configuration system with expanded theme and content options

Pico now uses a YAML configuration file (config.yml.template) instead of its previous method, introducing a structured set of settings for users. Key additions include explicit configuration for theme URLs (themes\_url), plugin URLs (plugins\_url), and asset directories (assets\_dir/assets\_url). The content section now allows pages to be sorted by arbitrary meta values (e.g., by 'author') in addition to alphabetical or date sorting. Users can also enable debug mode, set a specific locale, and configure the Parsedown Markdown parser (e.g., enabling Parsedown Extra, handling line breaks, and escaping HTML). Additionally, Twig template engine settings such as autoescape, strict variables, and caching paths are now directly configurable.

config · high confidence

Pico CMS v2.1 core rewrite with new plugin API and Twig extension

The library has been upgraded to Pico v2.1.4 (API version 3), replacing the legacy \lib/pico.php\ and \lib/markdown.php\ files with a modern, object-oriented architecture. This introduces a new plugin system via \PicoPluginInterface\ and \AbstractPicoPlugin\, allowing plugins to declare dependencies, manage enable/disable states, and hook into events. The core \Pico\ class now uses lazy initialization for Twig, Parsedown, and YAML parsing, and exposes a new \PicoTwigExtension\ that centralizes filters (markdown, map, sort\_by, link, url) and functions (url\_param, form\_param, pages). Configuration is now loaded from \config/\ using YAML, and the engine supports UTF-8 BOM, per-directory 404 pages, and arbitrary page sorting by meta values.

lib · high confidence

Refactored build and deployment scripts for release archives and documentation

The build system scripts in .build have been rewritten to use picocms/ci-tools, introducing new scripts for cleaning the environment, initializing build variables, and installing dependencies. Release creation (release.sh) now explicitly manages Composer dependencies for Pico, themes, and deprecated packages, and enforces a beta minimum stability to accommodate Parsedown 1.8. Deployment (deploy-release.sh, deploy-branch.sh) now conditionally generates and publishes phpDocumentor documentation, version badges, version files, and cloc statistics based on environment flags, with badge and stats updates restricted to stable releases.

.build · high confidence

Removal of cached Twig template file

A pre-compiled Twig template file for the site's index page has been removed from the lib/cache directory. This change eliminates the specific cached bytecode for the HTML layout that renders the document structure, meta tags, and theme assets, likely to force regeneration of the cache or as part of a cleanup process.

lib/cache · high confidence

Restructure project layout and enforce Composer-based installation

The repository has been reorganized to support a Composer-managed dependency model. The legacy \config.php\ file is removed in favor of a \config/\ directory, and the \lib/\ directory is no longer bundled in the source distribution, requiring users to run \composer install\ to fetch dependencies like Twig and Parsedown. The root \index.php\ now loads the \vendor/autoload.php\ and instantiates the \Pico\ class with explicit directory paths. Additionally, \.htaccess\ is updated to deny direct access to sensitive directories (config, content, lib, vendor) and files (CHANGELOG.md, composer.json), and the \MultiViews\ Apache feature is disabled to prevent path resolution conflicts.

(repo-wide) · high confidence

Updated DummyPlugin template for Pico 2.0 API

The DummyPlugin template in the plugins directory has been updated to align with the Pico 2.0 API, specifically declaring API version 3. This change includes refactoring core event signatures (such as onPluginsLoaded, onThemeLoaded, and onConfigLoaded) to match the new parameter structures and type hints, providing developers with an accurate starting point for building compatible plugins.

plugins · high confidence

Dependencies

Adopts Composer for dependency management and removes bundled Twig

The project now uses Composer to manage its PHP dependencies, explicitly requiring Twig ^1.36, Symfony YAML ^2.8, Parsedown 1.8.0-beta-7, and Parsedown Extra 0.8.0-beta-1, along with PHP \>=5.3.6 and the mbstring extension. As part of this shift, the previously bundled Twig library (lib/twig/composer.json) has been removed, meaning Twig is no longer shipped within the repository but is instead installed via Composer.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 52.

Lenses

  • Code Health 89
  • Architecture 100
  • Maturity 55
  • Readiness 27
  • Security 100

Changes since last survey

  • 300 commits — 276 feature/other, 24 fixes

By area

  • (root) — 123 commits
  • lib/Pico.php — 71 commits
  • (repo) — 30 commits
  • lib/AbstractPicoPlugin.php — 13 commits
  • config/config.yml.template — 10 commits
  • content-sample/index.md — 10 commits
  • lib/PicoTwigExtension.php — 9 commits
  • .build/create-release.sh — 6 commits
  • plugins/DummyPlugin.php — 4 commits
  • _build/tools — 3 commits
  • .github/stale.yml — 2 commits
  • .github/workflows — 2 commits
  • _build/deploy-branch.sh — 2 commits
  • content-sample/_meta.md — 2 commits
  • themes/default — 2 commits
  • .build/deploy-release.sh — 1 commit
  • .build/release.sh — 1 commit
  • .github/FUNDING.yml — 1 commit
  • .github/PULL_REQUEST_TEMPLATE.md — 1 commit
  • _build/create-release-archive.sh — 1 commit

Notable commits

  • fix: Build system: Fix GitHub release creation
  • fix: Build system: Fix _build/create-release-archive.sh
  • fix: Build system: Fix cloc statistics generation
  • fix: Build system: Fix release deployment
  • fix: Build system: Fix release package deployment
  • fix: Build system: Improve and fix deployment
  • fix: Fix $this->config['twig_config'] handling in Pico::loadTheme()
  • fix: Fix @deprecated notice for Pico::getBaseThemeUrl() and AbstractPicoPlugin::__call()
  • fix: Fix DummyPlugin declaring API version 3
  • fix: Fix PHP Syntax Error
  • fix: Fix Pico's REQUEST_URI routing method when installed to /
  • fix: Fix Pico's sample contents
  • fix: Fix Pico::loadPlugin() when called before Pico::loadPlugins()
  • fix: Fix Pico::parseFileMeta()
  • fix: Fix Travis build
  • fix: Fix auto-publishing of pre-bundled releases
  • fix: Fix detection of Windows-based server environments
  • fix: Fix directory separator in Pico::getUrlFromPath()
  • fix: Fix page tree
  • fix: Fix sorting of Pico::$nativePlugins
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

picocms/Pico was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 5e8e0a03f4a14d4f70a109e8f5d905fbbad897f6 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.