Skip to content
CAI
Software that uses CAICheck a score

sasa1977/site_encrypt

71.1

Strong · 3 October 2026

2.4k

lines of production code

Elixir

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

SiteEncrypt is an Elixir library that automates HTTPS certificate management for web applications by integrating with the ACME protocol. It provides native and Certbot-based clients to handle certificate issuance, renewal, and backup, while offering adapters for Phoenix endpoints to seamlessly inject SSL enforcement. The system supports multiple web server adapters, including Cowboy and Bandit, and includes tools for testing certificate lifecycles in development environments.

How it got here

2018 — Native ACME client migration

8 changes.

The project replaced its internal ACME server and external Certbot dependency with a native Elixir ACME client, consolidating certificate management and verification logic. This overhaul introduced a new configuration schema, automatic certificate backup capabilities, and support for modern Elixir and Phoenix versions.

2020 — ACME protocol and Phoenix integration

9 changes.

This period focused on implementing the core ACME protocol handling, including a native client, local server, and low-level API for certificate management. It also introduced a dedicated Phoenix adapter to integrate these capabilities into web applications, supported by a demo app and comprehensive test coverage for certificate lifecycle and renewal scheduling.

Features

Add Phoenix demo application with SiteEncrypt integration

Introduces a new Phoenix demo application (\PhoenixDemo\) that demonstrates how to integrate the \site\_encrypt\ library for automatic HTTPS certificate management. The demo includes a minimal Phoenix endpoint configuration that uses \SiteEncrypt.Phoenix.Endpoint\ to handle ACME challenges and enforce SSL, with configurable domains, emails, and database folder paths. It also provides a simple 'hello' response to verify the encrypted connection and includes standard project setup files like \.formatter.exs\, \.gitignore\, and a \README.md\ with usage instructions.

demos/phoenix · high confidence

Add SiteEncrypt adapter for Phoenix endpoints

Introduces \SiteEncrypt.Phoenix.Endpoint\ and \SiteEncrypt.Phoenix.Test\ modules to integrate certificate management into Phoenix applications. The endpoint adapter allows developers to replace \use Phoenix.Endpoint\ with \use SiteEncrypt.Phoenix.Endpoint\, automatically injecting ACME challenge handling and certificate lifecycle management while supporting both Cowboy2 and Bandit adapters. A test helper module is also provided to facilitate certification testing using an internal ACME server.

_lib/site\encrypt/phoenix · high confidence

Introduce low-level ACME client API

A new low-level API for interacting with ACME CA servers has been added, providing functions to create sessions, manage accounts, place orders, and handle authorizations and challenges. This module implements the core ACME protocol logic using Mint for HTTP communication, allowing users to invoke these operations from separate processes to avoid blocking. Additionally, a supporting crypto module has been introduced to handle private key generation and Certificate Signing Request (CSR) creation.

_lib/site\encrypt/acme/client · high confidence

Introduce native ACME client and configurable key sizes for certificate management

The certification module now includes a new native ACME client implementation (SiteEncrypt.Certification.Native) alongside the existing Certbot adapter, allowing certificate operations to be performed without relying on the external certbot binary. This change also makes the RSA key size configurable via the config (defaulting to 4096 bits) and introduces randomized renewal scheduling to reduce load on Certificate Authorities. Users benefit from a more robust, dependency-light certificate management path and better control over security parameters.

_lib/site\encrypt/certification · high confidence

New ACME client and local server implementation

This change introduces the core ACME protocol handling for SiteEncrypt, adding a new client module (\SiteEncrypt.Acme.Client\) that automates account creation, domain validation via HTTP-01 challenges, and certificate issuance. It also adds a local ACME server (\SiteEncrypt.Acme.Server\) that can run locally using either Cowboy or Bandit to support development and testing workflows, including DNS resolution and challenge processing.

_lib/site\encrypt/acme · high confidence

Removals

Removal of legacy AcmeServer modules

The \lib/acme\_server\ directory has been cleaned up by removing several internal modules: \Account\, \Crypto\, \Db\, \Jobs\, \JoseJasonAdapter\, \JWS\, \Nonce\, and \Standalone\. These deletions eliminate the previous in-memory ETS-based database, the OpenSSL-dependent certificate signing logic, the custom JWS/JWT handling, and the standalone HTTP server adapter, indicating a consolidation or migration to a different implementation for these capabilities.

_lib/acme\server · high confidence

Removed legacy HTTP verification job implementation and supporting infrastructure

The \AcmeServer.Jobs\ module has been refactored by removing the \HttpVerifier\ GenServer, the \Registry\ for job naming, and the \Supervisor\ that managed job processes. This change eliminates the previous mechanism for handling ACME HTTP-01 verification challenges via a dedicated, dynamically supervised GenServer with retry logic, indicating that this specific verification path is no longer supported or has been replaced by a different implementation elsewhere in the system.

_lib/acme\server/jobs · high confidence

Behavioural changes

Dropped support for Elixir versions prior to 1.16

The library no longer supports Elixir versions older than 1.16. Users must upgrade their Elixir runtime to at least version 1.16 to use this version of the library, as indicated by the new \.tool-versions\ file specifying Elixir 1.19.2 and the changelog entry for version 0.7.0.

(repo-wide) · high confidence

Major configuration schema overhaul and removal of internal ACME server

The library's configuration structure has been significantly reworked: the single \domain\ and \email\ fields are replaced by \domains\ and \emails\ lists, \ca\_url\ is renamed to \directory\_url\ (supporting both external URLs and an internal test server tuple), and new options like \client\ (native vs. certbot), \backup\, \key\_size\, and \mode\ are introduced. Additionally, the internal \AcmeServer\ module, which previously implemented the ACME protocol logic within this library, has been removed entirely, shifting the responsibility of ACME communication to the selected client implementation.

lib · high confidence

Migrate to Config v2 and set test logger level

The application configuration has been updated to use the modern \import Config\ syntax instead of the deprecated \use Mix.Config\, which is required for compatibility with newer Elixir/Phoenix versions. Additionally, the logger level is now explicitly set to \:warning\ when running in the test environment to reduce output noise during testing.

config · high confidence

Phoenix demo now uses Bandit adapter and Jason library

The Phoenix demo configuration has been updated to use the Bandit.PhoenixAdapter instead of the previous default adapter, and explicitly sets Jason as the JSON library. Additionally, logger verbosity is reduced to warning level in the test environment to improve test output clarity.

demos/phoenix/config · high confidence

Refactored ACME server into modular components under new namespace

The ACME server implementation has been reorganized into distinct modules (Account, Challenge, Crypto, Db, JWS, Nonce, and Plug) within the \SiteEncrypt.Acme.Server\ namespace, replacing the previous \AcmeServer\ module structure. This change introduces a dedicated database abstraction using ETS for storing accounts, orders, and nonces, and implements a robust challenge handling process with retry logic and error isolation. Additionally, the cryptographic module now enforces RSA key sizes of at least 2048 bits for CA and server certificates to comply with TLS 1.3 requirements, and the plug has been simplified to streamline request handling.

_lib/site\encrypt/acme/server · high confidence

Refactored certificate management with native ACME client and backup support

The library has replaced the external \certbot\ binary with a native Elixir ACME client (\SiteEncrypt.HttpClient\), removing the \SiteEncrypt.Certbot\ module and its associated file-based challenge logic. This change introduces a new \SiteEncrypt.Adapter\ behavior and a simplified supervision tree that manages ACME servers and certificate renewal jobs internally. Users gain automatic backup and restore capabilities for certificates, improved handling of unknown ACME challenges (returning 404 instead of crashing), and the ability to refresh endpoint configuration dynamically via \SiteEncrypt.refresh\_config/1\. The \SiteEncrypt.Certifier\ and \SiteEncrypt.Phoenix\ modules have been removed in favor of this new, more robust native architecture.

_lib/site\encrypt · high confidence

Test coverage

Added tests for Phoenix demo certificate handling; Added tests for periodic certificate renewal scheduling; Expanded test coverage for certificate lifecycle and configuration changes.

Dependencies

Update dependencies and add Phoenix demo

The main library (site\_encrypt) has been updated to require Elixir 1.16+, switched the parent dependency from a Git repository to Hex (parent 0.12.1), and added optional support for the Bandit web server alongside existing Cowboy support. Development tooling now includes Dialyxir 1.4.7 and ExDoc 0.39.1 for documentation generation. A new Phoenix demo application has been added to demonstrate integration with Phoenix 1.7.11 and Bandit 1.2.1.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 72 → 71 (-0.9)
  • Rubric changed (rubric-2026.09.15 → rubric-2026.10.1) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (+0.0)
  • Architecture 91 → 93 (+2.1)
  • Maturity 58 → 57 (-1.0)
  • Readiness 78 → 75 (-3.5)
  • Security 89 → 91 (+2.3)

Resolved (2)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

sasa1977/site_encrypt was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 3 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 7d8e2e70288a006e601e7def10b0ef2f3fb82f6d — the exact code this score is about.
  • Scored under rubric-2026.10.1 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-8fe32cd45d00.