Skip to content
CAI
Software that uses CAICheck a score

prooph/pdo-snapshot-store

48.6

Weak · 21 September 2026

330

lines of production code

PHP

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a PHP library that provides a PDO-based implementation for storing and retrieving event-sourcing snapshots in relational databases. It supports MySQL, MariaDB, and PostgreSQL, allowing users to persist aggregate state with configurable serialization and transaction handling. The library integrates with PSR-11 containers and includes comprehensive test coverage for its core snapshot store functionality.

Features

Added database schema scripts for snapshot tables

New SQL scripts were added to define the structure of the \snapshots\ table for both MySQL and PostgreSQL databases. These scripts establish the table schema, including columns for \aggregate\_id\, \aggregate\_type\, \last\_version\, \created\_at\, and \aggregate\_root\, with \aggregate\_id\ set as the primary key.

scripts · high confidence

New PDO-based snapshot store implementation

The library now includes a concrete \PdoSnapshotStore\ class that persists snapshots to a relational database using PDO. This implementation supports custom table mappings, configurable serialization, and optional transaction handling. It also introduces a new \RuntimeException\ class to wrap PDO error information for better debugging.

src · high confidence

Behavioural changes

Added CI configuration for running PHPUnit tests against multiple database backends

The project now supports automated testing against MariaDB, MySQL, and PostgreSQL. New configuration files in the \.laminas-ci\ directory define database-specific PHPUnit settings for each backend, and a pre-run script dynamically selects the appropriate configuration based on the active database vendor, enabling the CI pipeline to execute tests against all three database types.

.laminas-ci · high confidence

Migrated CI from Travis to GitHub Actions and updated test configuration

The project has replaced the Travis CI configuration with GitHub Actions, introducing a new \.laminas-ci.json\ file to specify required PHP extensions (pdo-mysql, pdo-pgsql) and a \docker-compose-tests.yml\ file to spin up PostgreSQL and MySQL containers for testing. The legacy \.travis.yml\ file has been removed, and \phpunit.xml.dist\ has been simplified to use the default schema, reflecting the shift in the testing and continuous integration infrastructure.

(repo-wide) · high confidence

Updated PdoSnapshotStoreFactory to support PSR-11 containers and configurable serializers

The factory for creating PdoSnapshotStore instances has been updated to accept a PSR-11 ContainerInterface, replacing the previous container abstraction. This change allows users to provide their own serializer instances or service names via the 'serializer' configuration key, offering more flexibility in how snapshot data is serialized. Additionally, the factory now supports disabling transaction handling via a new 'disable\_transaction\_handling' configuration option, giving users more control over database transaction behavior.

src/Container · medium confidence

Test coverage

Added tests for PdoSnapshotStoreFactory; Added tests for the PDO snapshot store.

Dependencies

Update PHP version support and modernize dependencies

The project now requires PHP 7.4 or 8.0, replacing the previous 7.1 constraint. Several dependencies have been updated or replaced: PHPUnit has been upgraded to version 9.5, Prophecy to 1.10.3, and interop-config to 2.0.1. The package name has changed from prooph/event-sourcing to prooph/snapshot-store, and the PSR-11 container interface (psr/container) is now used instead of container-interop. Additionally, the namespace organization has been updated from Prooph\\PDOSnapshotStore to Prooph\\SnapshotStore\\Pdo, and the repository configuration has been simplified.

(dependencies) · medium confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 44 → 49 (+4.7)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (+0.0)
  • Architecture 69 → 69 (+0.0)
  • Maturity 36 → 36 (+0.0)
  • Readiness 38 → 43 (+5.3)
  • Security 50 → 76 (+26.1)

Resolved (9)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No exposed public API
  • Test reliability not included
  • dormant codebase — no living knowledge left to concentrate

New (13)

  • Dependency hygiene PARTLY measured — Composer dependencies read, no committed lock to grade for currency
  • Documentation: no usage examples (README.md)
  • High IaC: WD-COMPOSE-0002 (docker-compose-tests.yml)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium IaC: WD-COMPOSE-0002 (docker-compose-tests.yml)
  • Medium IaC: WD-COMPOSE-0002 (docker-compose-tests.yml)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • No dependency advisory monitoring

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

prooph/pdo-snapshot-store was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit bd27746fa0b33af7a98ac89039ae24f310cc1305 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.