Skip to content
CAI
Software that uses CAICheck a score

proophsoftware/event-machine-skeleton

42.0

Weak · 21 September 2026

1.1k

lines of production code

PHP

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a PHP-based Event Machine framework built on the Prooph ecosystem, designed for event-driven architecture with PostgreSQL persistence. It provides core infrastructure for managing commands, events, and queries, including automated projection handling and message bus routing. The application also features a real-time notification system via WebSockets and exposes a comprehensive OpenAPI v3 documentation interface for its API endpoints.

How it got here

2017 — Initial project scaffolding and infrastructure setup

10 changes.

This period marks the initial creation of the Prooph Event Machine skeleton, establishing a complete Dockerized development environment with PHP 7.1 and Zend Framework components. The work focused on configuring core infrastructure, including Postgres and RabbitMQ integration, service buses, and WebSocket-based real-time notifications. Additionally, the project introduced OpenAPI v3 documentation and automated event stream initialization scripts to support the application's event-driven architecture.

2018 — Event machine implementation and Postgres migration

5 changes.

This period focused on implementing the core event machine architecture, including API description classes and executable scripts for managing projections. Simultaneously, the project migrated its data persistence layer to PostgreSQL and established a new test infrastructure to support these changes.

Features

Add WebSocket-based notification system for real-time message updates

Added a new public-facing UI that connects to a RabbitMQ queue via WebSocket (STOMP protocol) to display real-time notifications. The entry includes the main entry point (index.php) which sets up the Zend Stratigility middleware pipeline, registers the ProblemDetails middleware, and configures routing for the /api and / paths. It also adds the stomp.min.js library for WebSocket communication and a ws.html page that uses jQuery and the notify.js library to show toast notifications when new messages arrive on the 'ui-queue'.

public · medium confidence

Added Postgres event-streams/projections tables and RabbitMQ broker configuration

The environment now includes database schema files for 'event\_streams' and 'projections' tables in Postgres, enabling event sourcing and state tracking. Additionally, RabbitMQ is configured with a 'ui-queue' and 'ui-exchange' (fanout) in the '/event-machine' vhost, with SSL enabled for the management interface and STOMP/WebSocket support on port 15691.

env · high confidence

Added Swagger UI for API documentation

The application now serves a static Swagger UI interface for API documentation. This is achieved by adding new static files in the public/swagger directory, including an HTML entry point (index.html) that loads the Swagger UI bundle and styles, along with an OAuth2 redirect handler (oauth2-redirect.html) to support authentication flows.

public/swagger · high confidence

Added infrastructure components for logging, service bus, and health checks

New files were added to the infrastructure layer to support error logging, command/query/event bus handling, and system health monitoring. Specifically, PsrErrorLogger was introduced to log request details and errors via PSR-3. Custom CommandBus, QueryBus, and EventBus classes were added to extend Prooph's service bus implementations, enabling specific message name resolution for GenericJsonSchemaMessage instances. An ErrorHandler plugin was created to manage exception handling within the message bus lifecycle. Additionally, a UiExchange marker interface and a HealthCheckResolver were added to support UI-related messaging and system health status resolution.

src/Infrastructure · high confidence

Added messageBox schema endpoint for OpenAPI v3 documentation

Users can now access a dynamic OpenAPI v3 schema for the application's message box, exposing all commands, events, and queries as documented endpoints. The new MessageSchemaMiddleware generates an OpenAPI 3.0.0 specification in JSON format, mapping each message type to specific paths and response codes (200 for queries, 202 for commands and events). This replaces the previous approach of returning individual message schemas, providing a unified view of the API's capabilities.

src/Http · high confidence

Added script to initialize the event stream

A new PHP script, create\_event\_stream.php, has been added to the scripts directory. This script initializes the 'event\_stream' in the event store by retrieving the EventStore from the container and creating a new stream, allowing users to set up the necessary infrastructure for event storage.

scripts · high confidence

Added scripts for running and resetting event machine projections

Two new executable scripts have been added to the bin directory: event\_machine\_projection.php, which runs projections in a loop, and reset.php, which resets the current version's projection. These scripts bootstrap the Prooph EventMachine and interact with the projection manager to manage event processing tasks.

bin · high confidence

Initial configuration and routing setup for the application

The application is now configured with a new routing structure that maps POST requests to the MessageBox controller and GET requests to the message schema middleware. Additionally, the service container is set up to wire up key components like the event store, command bus, and event bus, while the configuration aggregator is initialized to load environment-specific settings and enable debug mode in development.

config · high confidence

Initial configuration for Event Machine and RabbitMQ integration

The application now includes a global configuration file that defines database (PDO) and RabbitMQ connection settings, alongside a list of API class descriptions (Type, Command, Event, Query, Aggregate, Projection, Listener) for the event machine. This establishes the foundational setup for the application's core components.

config/autoload · high confidence

Initial release of the Event Machine skeleton

The repository is initialized with a complete Dockerized development environment for the prooph software Event Machine. This includes configuration files (\.gitignore\, \app.env\, \docker-compose.yml\, \phpunit.xml.dist\) and a detailed \README.md\ that documents the setup, including Postgres and RabbitMQ integration, WebSocket support, and instructions for running the demo and tests.

(repo-wide) · high confidence

New API description classes for event machine configuration

The src/Api directory now contains a set of new PHP classes (Aggregate, Command, Event, Listener, Metadata, Payload, Projection, Query, Schema, and Type) that implement the EventMachineDescription interface. These classes provide the structural definitions for the application's API, including command and event schemas, query resolvers, and type registrations, enabling the event machine to validate payloads and resolve queries.

src/Api · high confidence

Behavioural changes

Added placeholder for data directory

A .gitkeep file was added to the data directory, ensuring the directory is tracked by version control and remains empty as a placeholder.

data · high confidence

Migrate event store and document store to Postgres

The service factory now instantiates the event store and document store using Postgres-backed implementations (PostgresEventStore and PostgresDocumentStore) instead of previous storage backends. This change updates the underlying data persistence layer for event sourcing and document storage to use PostgreSQL, requiring a Postgres connection in the application configuration.

src/Service · high confidence

Test coverage

Added base test infrastructure for event machine testing

Added new test helper classes, including a \BaseTestCase\ that initializes the \EventMachine\ with a \PrototypingFlavour\ and provides utility methods like \assertRecordedEvent\ and \assertNotRecordedEvent\ to verify recorded events in tests.

tests · high confidence

Dependencies

Initial project setup with Event Machine and Postgres Document Store

The project is initialized as a Dockerized skeleton for the Prooph Event Machine, establishing the core PHP dependencies for building event-driven applications. The configuration pins the 'proophsoftware/event-machine' library (alongside supporting packages like 'prooph/pdo-event-store' and 'prooph/humus-amqp-producer') and introduces 'proophsoftware/postgres-document-store' to enable PostgreSQL-based document storage. The environment is set to PHP 7.1 with Zend Framework components for routing and aggregation.

(dependencies) · medium confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 43 → 42 (-1.2)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 99 (+0.5)
  • Architecture 69 → 66 (-3.3)
  • Maturity 50 → 50 (+0.0)
  • Readiness 17 → 18 (+0.3)
  • Security 98 → 87 (-10.7)

Resolved (7)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (composer.lock)
  • No exposed public API
  • Test reliability not included
  • The 'Database' section describes a single Postgres database but does not mention RabbitMQ integration or event-sourced write model behavior. (README.md)
  • dormant codebase — no living knowledge left to concentrate

New (18)

  • Abandoned package: zendframework/zend-config-aggregator
  • Abandoned package: zendframework/zend-expressive-helpers
  • Abandoned package: zendframework/zend-problem-details
  • Abandoned package: zendframework/zend-stdlib
  • Abandoned package: zendframework/zend-stratigility
  • Coverage not measured — no coverage collector is wired up
  • Documentation: no architecture or design documentation (README.md)
  • High CVE: [GHSA redacted] (composer.lock)
  • High IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • Leaked secret: high-entropy-secret (env/rabbit/broker_definitions.json)
  • Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • Medium: security finding (details withheld)
  • Outdated: nikic/fast-route
  • Outdated: prooph/pdo-event-store
  • Outdated: psr/http-server-middleware

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

proophsoftware/event-machine-skeleton was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 3d3e83fe11333f90f40e2d33ea6e3e6c9f643f88 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.