sebastienrousseau/password-generator
61.1
Adequate · 21 September 2026
16.4k
lines of production code
JavaScript
primary language
4
measurements over time
What this system is
jspassgen is a cross-platform JavaScript library and CLI tool for generating cryptographically secure passwords and passphrases. It supports a wide variety of password types, including quantum-resistant, diceware, and honeyword options, while providing detailed entropy analysis and strength auditing. The system is designed to run consistently in both Node.js and browser environments through a modular adapter architecture, exposing a fluent API for programmatic use and a feature-rich interactive interface for command-line and web users.
How it got here
2022 — Rebranding and monorepo restructuring
8 changes.
The project was rebranded to jspassgen and restructured into a monorepo with npm workspaces, updating the license to a dual Apache-2.0 OR MIT model. This period involved migrating to modern tooling, removing legacy modules, and introducing new utility libraries for cryptography and password generation. Comprehensive test coverage was added for the new core logic, CLI entry points, and UI components.
2023–2026 — Cross-platform architecture and web UI
24 changes.
The project established a platform-agnostic core library with dedicated adapters for Node.js and browser environments, enabling consistent password generation across CLI and web interfaces. This architectural shift was accompanied by the introduction of a fluent builder API, expanded password types including quantum-resistant options, and a comprehensive web-based demo with modern styling and accessibility features. Extensive testing and benchmarking were implemented to ensure parity between interfaces and validate performance and security baselines.
Features
Added TypeScript type definitions for the password generator library
This change introduces a new centralized TypeScript declaration file (types/index.d.ts) for the @sebastienrousseau/jspassgen package. It provides type definitions for the core password generation API, including the PasswordGenerator function and specific generators for strong, base64, and memorable passwords. The file also defines configuration interfaces for CLI options and utility types for cryptographic operations, enabling better type safety and IntelliSense support for TypeScript users of the library.
types · high confidence
Added Web Worker-based parallel password generation
Introduced a new \src/workers\ module that enables non-blocking, parallel password generation using Web Workers. This includes a \PasswordWorkerPool\ class for managing worker lifecycles, load balancing, and progress tracking, along with utility functions like \generatePasswordsBulk\ and \generateIdenticalPasswords\ for easy bulk operations. The implementation offloads cryptographic operations to background threads to prevent UI freezing during large-scale generation tasks.
src/workers · high confidence
Added benchmark suite for performance and security analysis
The benchmarks directory now includes a comprehensive suite of performance tests, including scripts for bulk generation, password generation across types and sizes, entropy calculation, and a security baseline comparison between crypto.randomBytes and Math.random(). A runner script (run-all.js) executes these benchmarks and outputs results in a hyperfine-compatible JSON format, enabling CI integration and performance tracking.
benchmarks · high confidence
Introduces browser-specific adapters and UI state management layer
This change adds the browser-side implementation of the application's port interfaces and the UI state management layer. New adapter classes (BrowserClock, BrowserCryptoRandom, BrowserStorage) in src/ui/web/adapters implement core ports using native browser APIs like Web Crypto, Performance, and localStorage/sessionStorage. Additionally, the src/ui/web/state directory introduces FormState to represent raw UI form data and StateToCoreMapper to transform this UI state into core service configuration, including specific handling for quantum-resistant password types.
src/ui/web/adapters, src/ui/web/state · high confidence
Introduction of WebUIController as a thin adapter for the Web UI
A new WebUIController has been added to the web UI layer to act as a thin adapter between the browser interface and the core password generation service. This controller manages the wiring of browser-specific adapters (for cryptography, storage, and time) to the core service, delegates all validation and password generation logic to the core, and transforms results into view models for rendering. It exposes methods for validating form state, generating passwords with entropy information, calculating entropy, and retrieving supported password types, effectively centralizing the interaction between the UI and the backend logic.
src/ui/web/controllers · high confidence
New CLI entry point and programmatic API for jspassgen
The \src/bin\ directory now contains the primary entry point (\password-generator.js\) and its TypeScript definitions (\password-generator.d.ts\) for the rebranded JavaScript Password Generator (jspassgen). This file wires the core service with Node.js-specific adapters (NodeCryptoRandom, EFFDicewareDictionary) and exposes a backward-compatible \PasswordGenerator\ function for programmatic use, while also handling CLI execution when run directly. It serves as the bridge between the command-line interface and the underlying password generation logic.
src/bin · high confidence
New build, deployment, and core-isolation verification scripts
Added three new automation scripts to the project: \build-web-demo.js\ bundles the web demo source into \dist/web/\ for GitHub Pages, \deploy-gh-pages.js\ automates the build and push to the \gh-pages\ branch, and \verify-core-deps.js\ (along with its shell counterpart) enforces that the \packages/core\ library remains platform-agnostic by scanning for forbidden Node.js built-ins, browser globals, CLI libraries, and UI frameworks.
scripts · high confidence
New fluent builder API and expanded password generation capabilities
The core library now exposes a fluent \PasswordBuilder\ API that allows users to construct passwords using method chaining (e.g., \.length(16).includeSymbols().excludeSimilar().generate()\). This update significantly expands the range of supported password types, adding dedicated generators and entropy calculations for quantum-resistant, honeyword, pronounceable, and diceware passphrases, alongside the existing strong, base64, memorable, and custom options. The change also introduces a template-based generation system for pattern-specific passwords (e.g., \\[A-Z\]{3}-\[0-9\]{4}\) and a comprehensive strength analyzer that detects common weakness patterns like sequences, keyboard walks, and leetspeak to provide security feedback.
packages/core/src · high confidence
New interactive onboarding flow and centralized CLI configuration
The application now includes a guided onboarding experience for first-time users, featuring a two-step interactive menu with keyboard navigation (arrow keys, numbers, Ctrl+K for command palette) and a 'Command Learning' panel that displays the equivalent CLI command and its breakdown after generation. This is supported by a new centralized configuration module (\src/config.js\ and \src/config.d.ts\) that defines all valid password types (including \quantum-resistant\, \diceware\, \honeyword\, and \pronounceable\), preset profiles (\quick\, \secure\, \memorable\, \quantum\, \diceware\, \pronounceable\), and CLI option defaults. The onboarding flow is implemented in \src/onboarding.js\ with type definitions in \src/onboarding.d.ts\, and the command learning presenter is located in \src/presenters/CommandLearningPresenter.js\. Error messages are also centralized in \src/errors.js\.
src · high confidence
New modular UI architecture with terminal capabilities, command palette, and web integration
The src/ui directory has been restructured into a modular design system. The CLI now features a command palette (invoked via Ctrl+K) for quick access to presets and actions, supported by a focus manager for nested navigation and a capabilities module that detects terminal color depth, theme (light/dark), and Unicode support to ensure graceful degradation. The visual design has been updated to a pastel, Charm-inspired theme with improved accessibility contrast. Additionally, a new web UI layer is introduced, providing a thin adapter pattern with browser-specific implementations (Web Crypto, localStorage) and optional React hooks for easy integration into web applications.
src/ui · high confidence
New platform-specific adapters for Node.js and browser environments
The application now includes dedicated adapter implementations to support both Node.js and web browser runtimes. For Node.js, new modules provide cryptographically secure random generation (using the \crypto\ module), file-system-based persistent storage with path-traversal protection, a structured console logger, and a system clock. For web environments, corresponding adapters leverage the Web Crypto API (\crypto.getRandomValues\) for randomness, \localStorage\ for configuration persistence (with an in-memory fallback), and a browser-compatible console logger. These adapters implement core ports (RandomGenerator, Storage, Logger, Clock) to allow the password generator to function consistently across different JavaScript environments.
src/adapters · high confidence
New service layer for configuration, generation, and structured output
The \src/services\ directory now contains a dedicated service layer that centralizes password generation logic and user interaction. \ConfigurationService\ and \config-service.js\ handle merging presets with user options, validating required fields (type, iteration, separator), and normalizing configurations. \password-service.js\ acts as the core interface, delegating generation to a shared core service instance and providing utilities for strength analysis and bulk generation. \cli-service.js\ implements the terminal output logic, including command generation, strength calculation, and minimal aesthetic rendering. \output-formatter.js\ adds the capability to export generated passwords in structured formats (JSON, YAML, CSV, and text), while \audit-service.js\ provides a wrapper for security audit sessions.
src/services · high confidence
New utility modules for cryptography, password generation, and string manipulation
This change introduces a suite of new utility modules in src/utils to support password generation and data handling. The crypto module provides cryptographically secure random generation via generateRandomBase64 and generateBase64Chunk, with the latter using crypto.randomInt to avoid bias. A new security-audit module tracks entropy usage and algorithm details for transparency when audit mode is enabled. Password generation helpers (randomNumber, randomVowel, randomConsonant, randomSyllable) are added to build syllable-based passwords. A password-strength-analyzer module detects common weak patterns (sequences, keyboard walks, repetitions) and checks against a list of common passwords. Finally, a strings module adds case-conversion utilities (camel, kebab, snake, title case) and currency formatting.
src/utils · high confidence
New view models for entropy, password, and validation display
The web UI now uses dedicated view models in src/ui/web/view-models to transform core generation and validation results into UI-ready data. EntropyViewModel formats entropy bits into a strength label, color, and progress bar percentage (capped at 256 bits). PasswordViewModel presents the generated password with masking, configuration summary, and advanced strength analysis (including score-based indicators, feedback, patterns, dictionaries, and crack time), falling back to entropy-based indicators when advanced analysis is unavailable. ValidationViewModel maps core validation errors to specific form fields (type, length, iteration, separator) and provides convenience flags for UI binding. These changes improve how strength and validation information are presented to users without altering the underlying generation or validation logic.
src/ui/web/view-models · high confidence
New web-based password generator demo with accessibility and theme support
A new interactive web demo has been added to the project, providing a standalone user interface for generating passwords. The interface features a segmented control for selecting password types (Random, Passphrase, Speakable, Base64, Quantum), a length slider, and advanced options for chunks and separators. It includes a strength indicator, keyboard shortcuts, and dark/light theme toggling. The demo is built with ES modules, adheres to WCAG 2.1 AA accessibility standards, and integrates with the core generator via a WebUIController adapter.
src/ui/web/demo · high confidence
Removals
Removal of bin/index.js entry point
The file bin/index.js has been deleted from the repository. This removes the primary entry point for the command-line interface, meaning the script can no longer be executed directly via this path.
bin · high confidence
Removal of password-generator module
The password-generator module has been removed from the library, eliminating the functionality previously provided by this component.
lib · high confidence
Behavioural changes
CLI restructured with new bootstrap and controller architecture
The CLI entry point has been refactored to use a new \cli-bootstrap.js\ module that wires Node.js-specific adapters (such as \NodeCryptoRandom\ and \EFFDicewareDictionary\) to the core password generation service. A new \CLIController.js\ acts as a thin adapter using Commander.js to parse arguments and delegate business logic, while \onboarding.js\ now serves as a compatibility bridge re-exporting functions from the unified onboarding module. This change introduces a cleaner separation between CLI concerns and core business logic, supporting features like optional clipboard functionality and security audit reports.
src/cli · high confidence
Migrated to ESLint flat config and added platform-agnostic enforcement rules
The core package now uses the ESLint flat config format (eslint.config.js) instead of the legacy .eslintrc.json, ensuring compatibility with ESLint 9. This configuration enforces the package's zero-dependency architecture by blocking imports of Node.js-specific modules (such as crypto, fs, path, and http) in core source files, requiring developers to use the defined port interfaces instead.
packages/core · high confidence
Project rebrand to jspassgen and dual-licensing under Apache-2.0 OR MIT
The project has been rebranded from 'Password Generator' to 'jspassgen' (JavaScript Password Generator), updating the package name, website references, and documentation. The license has changed from MIT-only to a dual-license model (Apache-2.0 OR MIT), with the corresponding license files added and the main LICENSE file updated to reflect this. The NPM package name has been corrected to @sebastienrousseau/jspassgen, and the ESLint configuration has been migrated to the new flat config format (eslint.config.js) to support modern Node.js versions.
(repo-wide) · high confidence
Redesigned Web UI with modern styling and accessibility improvements
The web demo interface has been visually overhauled with a new design system featuring CSS custom properties for consistent theming, an animated ethereal background, and enhanced accessibility. The update includes WCAG 2.2 AAA-compliant focus indicators, support for high-contrast and reduced-motion preferences, and a refined layout for form elements and cards, resulting in a more polished and user-friendly experience.
src/ui/web/demo/styles · high confidence
Web UI demo rebranded with theme support and enhanced password type controls
The web demo has been rebranded as the JavaScript Password Generator (jspassgen) and now includes a new theme management system that supports light, dark, and system preferences, persisting the choice in local storage. The main entry point introduces a 'quantum-resistant' password preset and refines the UI behavior for different password types: the length slider is hidden for word-based, quantum, and pronounceable types, while the iteration label dynamically updates to reflect 'Words', 'Syllables', or 'Chunks' depending on the selection.
src/ui/web/demo/scripts · high confidence
Test coverage
Added comprehensive test coverage for UI components and utility functions; Added comprehensive test coverage for browser, node, and web adapter modules; Added comprehensive test coverage for core password generation domain; Added parity tests for CLI and Web UI adapters; Added test coverage for CLI, configuration, and password generation services; Added unit and CLI integration tests for the password generator; Added unit and integration tests for CLI components; Added unit tests for configuration, entry point, and onboarding modules; Added unit tests for web UI controllers and view models.
Dependencies
Migrate to monorepo structure and update Node.js requirement
The project has been restructured into a monorepo using npm workspaces, introducing a new \packages/core\ directory for platform-agnostic password generation logic and a \benchmarks\ directory for performance testing. The root \package.json\ has been updated to require Node.js 22 or higher, upgraded to use modern versions of development tools (such as ESLint 9, Prettier 3.9, and Babel 8), and renamed to \@sebastienrousseau/password-generator\ with a dual Apache-2.0 OR MIT license.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 58 → 61 (+3.0)
- Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 65 → 61 (-4.4)
- Architecture 57 → 55 (-2.0)
- Maturity 60 → 76 (+16.1)
- Readiness 56 → 70 (+13.9)
- Security 56 → 75 (+18.7)
Resolved (55)
- Concentrated knowledge decay
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High vulnerability: [GHSA redacted] (package-lock.json)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 35 more
New (75)
- CLIController.handleCliAction (cognitive 24) (src/cli/CLIController.js)
- CLIController.handleCliAction (cyclomatic 19) (src/cli/CLIController.js)
- CODEOWNERS assigns no owner to any path
- Dependency advisory scan runs only on code events
- FunctionTooLong: service.createService (packages/core/src/service.js)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 55 more
Changes since last survey
- 7 commits — 6 feature/other, 1 fixes
By area
- (root) — 4 commits
- (repo) — 2 commits
- src/adapters — 1 commit
Notable commits
- fix: chore(lint): format strings and fix jsdoc config for v1.1.5
- change: Merge pull request #217 from sebastienrousseau/feat/v1.1.5
- change: chore(deps): bump esbuild and clear the high-severity audit findings (#264)
- change: chore(deps): consolidate dependency updates and migrate to ESLint flat config (#262)
- change: chore(deps-dev): bump mocha from 11.8.0 to 12.0.0 (#267)
- change: chore(license): ship Apache-2.0 OR MIT (#265)
- change: chore(merge): resolve merge conflicts with master (ESLint 9, dual-licensing, v1.1.5)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
sebastienrousseau/password-generator was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit aba33397214c1378181d530bc46069df92323b50 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.