Skip to content
CAI
Software that uses CAICheck a score

processone/fast_xml

55.6

Adequate · 2 October 2026

6.3k

lines of production code

Erlang

with C

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

fast\_xml is an Erlang library for high-performance XML parsing and manipulation, leveraging Expat via C NIFs for efficient stream and structure processing. It provides capabilities for serializing XML with compliant attribute encoding and header support, alongside tools for generating XML-RPC codecs. The system includes robust test coverage for encoding order and security compliance, such as handling specific CVEs.

Features

Initial release of fast\_xml as an Apache 2.0 licensed Erlang XML library

This entry marks the initial commit and release of the fast\_xml project, an Expat-based Erlang XML parsing and manipulation library. The codebase is now licensed under the Apache License 2.0, replacing previous licensing terms. The library provides fast XML stream and structure parsing, with C NIFs (fxml.so, fxml\_stream.so) replacing older driver-based implementations. It includes build support for rebar and rebar3, integrates with p1\_utils for dependency management, and adds initial XML-RPC codec generation capabilities. Documentation, including a README, Code of Conduct, and Contributing guide, is added to support community adoption.

(repo-wide) · high confidence

Behavioural changes

Introduce fxml\_gen.hrl with always\_encode attribute support

The legacy xml.hrl header has been removed and replaced by new include files, most notably fxml\_gen.hrl, which defines the internal records for the XML generator. A key behavioral addition is the new always\_encode field on the attr record, allowing attributes to be encoded regardless of their content, alongside other generator-specific fields like label and default handling.

include · high confidence

Library renamed from xml to fast\_xml with updated application structure

The library has been renamed from 'xml' to 'fast\_xml' (version 1.1.61), including the application module (fast\_xml.app.src), the main application behavior (src/fast\_xml.erl, formerly xml\_app.erl), and the supervisor (src/fxml\_sup.erl, formerly xml\_sup.erl). The old gen\_server-based xml and xml\_stream modules have been removed in favor of NIF-based implementations (fxml and fxml\_stream) that load native code via p1\_nif\_utils. The application now depends on p1\_utils and uses an Apache 2.0 license instead of GPL.

src · high confidence

XML serialization now supports XML headers and uses proper attribute encoding

The \fxml\ NIF module now supports generating XML headers (e.g., \\<?xml version='1.0'?\>\) when serializing elements, controlled by the new \is\_header\ parameter in the underlying C implementation. Additionally, XML attribute values are now correctly escaped using standard entities (such as \&amp;\, \&lt;\, \&quot;\, \&apos;\, and numeric character references for whitespace) instead of the previous custom \crypt\ function, ensuring compliant XML output. The \element\_to\ function has been updated to reflect these changes, allowing callers to request header-inclusive serialization.

_c\src · high confidence

Test coverage

Added XML-RPC codec specification and generation documentation; Added tests for XML generator reference order and [CVE redacted] compliance.

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 56 → 56 (+0.0)
  • Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 90 → 90 (+0.0)
  • Architecture 100 → 100 (+0.0)
  • Maturity 39 → 39 (+0.0)
  • Readiness 68 → 68 (+0.0)
  • Security 61 → 61 (+0.0)

Resolved (4)

  • Coverage not measured — no coverage collector is wired up
  • Documentation: no architecture or design documentation (README.md)
  • Documentation: no usage examples (README.md)
  • Off-boarding risk: anonymized user #1

New (3)

  • Dependency hygiene PARTLY measured — rebar3 pinning read, dependency currency not (no rebar.lock-pinned Hex declaration to grade)
  • No dependency lockfile committed (rebar.config)
  • Off-boarding risk: anonymized user #1

Changes since last survey

  • 5 commits — 5 feature/other, 0 fixes

By area

  • .github/workflows — 2 commits
  • src/fast_xml.app.src — 2 commits
  • (root) — 1 commit

Notable commits

  • change: Release 1.1.61
  • change: Remove R25 from workflows too as it fails too
  • change: Update changelog
  • change: Update license name to make hex happy
  • change: Update workflow files

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

processone/fast_xml was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 2 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 0cda644e41cbde84f434e85d40fb359e0d7a47e2 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.