Skip to content
CAI
Software that uses CAICheck a score

roots/bedrock

52.3

Adequate · 19 September 2026

213

lines of production code

PHP

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is a Bedrock-based WordPress boilerplate designed to provide a modern, secure, and developer-friendly foundation for building WordPress applications. It establishes a standardized project structure with a dedicated web root, manages dependencies via Composer, and configures the environment using Dotenv for robust configuration management. The setup includes a containerized development environment with PHP 8.3 and Nginx, along with integrated tooling for code linting and testing to ensure consistent code quality.

Features

Add Bedrock development container environment

Introduces a new dev container setup for Bedrock, providing a local development environment with PHP 8.3, Nginx, and MariaDB 12. The configuration includes a Dockerfile with required extensions and tools (Composer, WP-CLI), a docker-compose.yml defining the app, web, and database services, and supporting configuration files for Nginx and PHP. This allows developers to spin up a consistent WordPress Bedrock environment directly in VS Code or compatible editors.

.devcontainer · high confidence

Initial project scaffolding and configuration

This change establishes the foundational structure for the Bedrock WordPress boilerplate. It introduces an \.editorconfig\ for consistent code formatting, a \pint.json\ configuration for the PHP Pint linter, and a \wp-cli.yml\ to define the web root and server document root. The \.env.example\ file is significantly expanded to include database credentials, WordPress URLs, debug settings, and security salts, while also supporting DSN-based database connections. The \.gitignore\ is updated to reflect the new folder structure (e.g., \web/wp\, \web/app\), ignoring Composer dependencies, logs, and specific WordPress directories. Additionally, the repository gains a \LICENSE.md\, a \phpunit.xml.dist\ for test configuration, and a \.gitattributes\ file to exclude development-specific files from exports. Legacy files such as \Capfile\, \index.php\, \CHANGELOG.md\, and \CONTRIBUTING.md\ are removed as part of this initial setup.

(repo-wide) · high confidence

Introduce Bedrock Autoloader mu-plugin and restructure web directory layout

This change introduces the Bedrock Autoloader as a new must-use plugin (mu-plugin) located at web/app/mu-plugins/bedrock-autoloader.php, which automatically loads standard plugins during the mu-plugin loading phase to simplify plugin management. Concurrently, the project's directory structure is reorganized: the app/plugins, app/themes, and vendor directories are moved under the new web/app/ prefix (plugins, themes, and uploads respectively), establishing a clearer separation between web-accessible assets and application logic.

web/app · high confidence

Behavioural changes

Major configuration overhaul with Dotenv v5 and new environment handling

The configuration system has been significantly restructured: the Capistrano deploy script has been removed, and application.php now uses Dotenv v5 with an immutable repository to load .env and optional .env.local files only if they exist. Environment detection defaults to production instead of development, and WP\_ENVIRONMENT\_TYPE is now automatically derived from WP\_ENV for standard environments. Database configuration now supports SSL via DB\_SSL, optional DB\_PREFIX, and DATABASE\_URL parsing, with DB\_CHARSET defaulting to utf8mb4. Security and debugging settings have been updated to disable file editing and modifications by default, allow disabling WP\_CRON via environment variable, enable WP\_DEBUG\_LOG optionally, and improve HTTPS detection behind reverse proxies.

config · high confidence

Refactor environment configuration to use Roots WPConfig and adjust development settings

The environment-specific configuration files (development, staging, production) have been refactored to use the \Roots\\WPConfig\\Config\ class instead of direct \define()\ calls, improving consistency and maintainability. In the development environment, fatal error handling is now disabled (\WP\_DISABLE\_FATAL\_ERROR\_HANDLER\), error display is explicitly enabled, and debug logging defaults to true via the \WP\_DEBUG\_LOG\ environment variable. The production environment configuration file has been removed, implying that production settings are now managed elsewhere or default to standard WordPress behavior, while staging retains indexing restrictions.

config/environments · high confidence

Removal of custom theme directory registration

The custom mu-plugin that explicitly registered the WordPress themes directory has been removed. This means the site no longer relies on this specific manual registration step for theme discovery, reverting to default WordPress theme loading behavior.

app/mu-plugins · high confidence

Removal of local Capistrano deployment configurations

The local Capistrano deployment configuration files for the production and staging environments have been removed from the repository. This change eliminates the in-repo server definitions and SSH settings, indicating that deployment configuration has been migrated to an external repository or management system.

config/deploy · high confidence

Restructure web root and update autoload paths

The application's web root has been moved into a dedicated \web/\ directory. The \wp-config.php\ file has been relocated to this new directory, and its internal paths for \vendor/autoload.php\ and \config/application.php\ have been updated to use \dirname(\_\DIR\\_)\ to correctly resolve the parent directory from the new location. A new \web/index.php\ entry point has been added to bootstrap the WordPress view.

web · high confidence

Test coverage

Added Pest testing scaffold

Added a basic test setup using the Pest testing framework, including a configuration file (tests/Pest.php) and a placeholder feature test (tests/Feature/ExampleTest.php) that verifies a simple assertion.

tests · high confidence

Dependencies

Major dependency overhaul and removal of Capistrano deployment tooling

This change removes the Ruby-based Capistrano deployment dependencies (Gemfile and Gemfile.lock) and performs a comprehensive upgrade of the PHP dependency stack in composer.json. The project now requires PHP 8.3, replaces the legacy WordPress package with roots/wordpress v7.1.1, updates the environment variable library to vlucas/phpdotenv ^5.0 and oscarotero/env ^2.0, and introduces new dev dependencies for testing (pestphp/pest ^4.0) and code linting (laravel/pint ^1.0). Additionally, the default theme is updated to Twenty Twenty-Five, and the folder structure is adjusted to install WordPress core in web/wp with plugins and themes located under web/app/.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 52.

Lenses

  • Code Health 100
  • Architecture 66
  • Maturity 36
  • Readiness 61
  • Security 70

Changes since last survey

  • 300 commits — 246 feature/other, 54 fixes

By area

  • (root) — 229 commits
  • (repo) — 22 commits
  • config/application.php — 17 commits
  • .github/workflows — 15 commits
  • .circleci/config.yml — 4 commits
  • .devcontainer/docker-compose.yml — 4 commits
  • .github/renovate.json — 3 commits
  • web/app — 3 commits
  • .github/dependabot.yml — 2 commits
  • .devcontainer/config — 1 commit

Notable commits

  • fix: Fix GitHub Actions CI Workflow (#650)
  • fix: Merge pull request #461 from roots/revert-455-log1x-phpcs
  • fix: Merge pull request #510 from roots/fix/509
  • fix: Revert "Require project autoloader in wp-cli.yml" (#720)
  • fix: Revert "Use inline phpcs rules instead of phpcs.xml"
  • fix: chore(mu-plugins): Bump bedrock-autoloader version fix(mu-plugins): A more sane fix for #510
  • fix: fix(ci): Change 7.4 workflow to latest (and maybe not fail)
  • fix: fix(deps): ⬆️ bump composer/installers to v2.3.0 (#729)
  • fix: fix(deps): ⬆️ bump oscarotero/env to v2.1.1 (#745)
  • fix: fix(deps): ⬆️ bump roots/wordpress to v6.2 (#673)
  • fix: fix(deps): ⬆️ bump roots/wordpress to v6.2.1 (#676)
  • fix: fix(deps): ⬆️ bump roots/wordpress to v6.2.2 (#677)
  • fix: fix(deps): ⬆️ bump roots/wordpress to v6.3 (#682)
  • fix: fix(deps): ⬆️ bump roots/wordpress to v6.3.1 (#685)
  • fix: fix(deps): ⬆️ bump roots/wordpress to v6.3.2 (#689)
  • fix: fix(deps): ⬆️ bump roots/wordpress to v6.4.1 (#693)
  • fix: fix(deps): ⬆️ bump roots/wordpress to v6.4.2 (#701)
  • fix: fix(deps): ⬆️ bump roots/wordpress to v6.4.3 (#708)
  • fix: fix(deps): ⬆️ bump roots/wordpress to v6.5 (#712)
  • fix: fix(deps): ⬆️ bump roots/wordpress to v6.5.2 (#715)
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

roots/bedrock was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit b6e35ffbd05e17292b19a5b97ac264a4448158fb — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.