Skip to content
CAI
Software that uses CAICheck a score

sebastienrousseau/password-generator

61.1

Adequate · 21 September 2026

16.4k

lines of production code

JavaScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

jspassgen is a cross-platform JavaScript library and CLI tool for generating cryptographically secure passwords and passphrases. It supports a wide variety of password types, including quantum-resistant, diceware, and honeyword options, while providing detailed entropy analysis and strength auditing. The system is designed to run consistently in both Node.js and browser environments through a modular adapter architecture, exposing a fluent API for programmatic use and a feature-rich interactive interface for command-line and web users.

How it got here

2022 — Rebranding and monorepo restructuring

8 changes.

The project was rebranded to jspassgen and restructured into a monorepo with npm workspaces, updating the license to a dual Apache-2.0 OR MIT model. This period involved migrating to modern tooling, removing legacy modules, and introducing new utility libraries for cryptography and password generation. Comprehensive test coverage was added for the new core logic, CLI entry points, and UI components.

2023–2026 — Cross-platform architecture and web UI

24 changes.

The project established a platform-agnostic core library with dedicated adapters for Node.js and browser environments, enabling consistent password generation across CLI and web interfaces. This architectural shift was accompanied by the introduction of a fluent builder API, expanded password types including quantum-resistant options, and a comprehensive web-based demo with modern styling and accessibility features. Extensive testing and benchmarking were implemented to ensure parity between interfaces and validate performance and security baselines.

Features

Added TypeScript type definitions for the password generator library

This change introduces a new centralized TypeScript declaration file (types/index.d.ts) for the @sebastienrousseau/jspassgen package. It provides type definitions for the core password generation API, including the PasswordGenerator function and specific generators for strong, base64, and memorable passwords. The file also defines configuration interfaces for CLI options and utility types for cryptographic operations, enabling better type safety and IntelliSense support for TypeScript users of the library.

types · high confidence

Added Web Worker-based parallel password generation

Introduced a new \src/workers\ module that enables non-blocking, parallel password generation using Web Workers. This includes a \PasswordWorkerPool\ class for managing worker lifecycles, load balancing, and progress tracking, along with utility functions like \generatePasswordsBulk\ and \generateIdenticalPasswords\ for easy bulk operations. The implementation offloads cryptographic operations to background threads to prevent UI freezing during large-scale generation tasks.

src/workers · high confidence

Added benchmark suite for performance and security analysis

The benchmarks directory now includes a comprehensive suite of performance tests, including scripts for bulk generation, password generation across types and sizes, entropy calculation, and a security baseline comparison between crypto.randomBytes and Math.random(). A runner script (run-all.js) executes these benchmarks and outputs results in a hyperfine-compatible JSON format, enabling CI integration and performance tracking.

benchmarks · high confidence

Introduces browser-specific adapters and UI state management layer

This change adds the browser-side implementation of the application's port interfaces and the UI state management layer. New adapter classes (BrowserClock, BrowserCryptoRandom, BrowserStorage) in src/ui/web/adapters implement core ports using native browser APIs like Web Crypto, Performance, and localStorage/sessionStorage. Additionally, the src/ui/web/state directory introduces FormState to represent raw UI form data and StateToCoreMapper to transform this UI state into core service configuration, including specific handling for quantum-resistant password types.

src/ui/web/adapters, src/ui/web/state · high confidence

Introduction of WebUIController as a thin adapter for the Web UI

A new WebUIController has been added to the web UI layer to act as a thin adapter between the browser interface and the core password generation service. This controller manages the wiring of browser-specific adapters (for cryptography, storage, and time) to the core service, delegates all validation and password generation logic to the core, and transforms results into view models for rendering. It exposes methods for validating form state, generating passwords with entropy information, calculating entropy, and retrieving supported password types, effectively centralizing the interaction between the UI and the backend logic.

src/ui/web/controllers · high confidence

New CLI entry point and programmatic API for jspassgen

The \src/bin\ directory now contains the primary entry point (\password-generator.js\) and its TypeScript definitions (\password-generator.d.ts\) for the rebranded JavaScript Password Generator (jspassgen). This file wires the core service with Node.js-specific adapters (NodeCryptoRandom, EFFDicewareDictionary) and exposes a backward-compatible \PasswordGenerator\ function for programmatic use, while also handling CLI execution when run directly. It serves as the bridge between the command-line interface and the underlying password generation logic.

src/bin · high confidence

New build, deployment, and core-isolation verification scripts

Added three new automation scripts to the project: \build-web-demo.js\ bundles the web demo source into \dist/web/\ for GitHub Pages, \deploy-gh-pages.js\ automates the build and push to the \gh-pages\ branch, and \verify-core-deps.js\ (along with its shell counterpart) enforces that the \packages/core\ library remains platform-agnostic by scanning for forbidden Node.js built-ins, browser globals, CLI libraries, and UI frameworks.

scripts · high confidence

New fluent builder API and expanded password generation capabilities

The core library now exposes a fluent \PasswordBuilder\ API that allows users to construct passwords using method chaining (e.g., \.length(16).includeSymbols().excludeSimilar().generate()\). This update significantly expands the range of supported password types, adding dedicated generators and entropy calculations for quantum-resistant, honeyword, pronounceable, and diceware passphrases, alongside the existing strong, base64, memorable, and custom options. The change also introduces a template-based generation system for pattern-specific passwords (e.g., \\[A-Z\]{3}-\[0-9\]{4}\) and a comprehensive strength analyzer that detects common weakness patterns like sequences, keyboard walks, and leetspeak to provide security feedback.

packages/core/src · high confidence

New interactive onboarding flow and centralized CLI configuration

The application now includes a guided onboarding experience for first-time users, featuring a two-step interactive menu with keyboard navigation (arrow keys, numbers, Ctrl+K for command palette) and a 'Command Learning' panel that displays the equivalent CLI command and its breakdown after generation. This is supported by a new centralized configuration module (\src/config.js\ and \src/config.d.ts\) that defines all valid password types (including \quantum-resistant\, \diceware\, \honeyword\, and \pronounceable\), preset profiles (\quick\, \secure\, \memorable\, \quantum\, \diceware\, \pronounceable\), and CLI option defaults. The onboarding flow is implemented in \src/onboarding.js\ with type definitions in \src/onboarding.d.ts\, and the command learning presenter is located in \src/presenters/CommandLearningPresenter.js\. Error messages are also centralized in \src/errors.js\.

src · high confidence

New modular UI architecture with terminal capabilities, command palette, and web integration

The src/ui directory has been restructured into a modular design system. The CLI now features a command palette (invoked via Ctrl+K) for quick access to presets and actions, supported by a focus manager for nested navigation and a capabilities module that detects terminal color depth, theme (light/dark), and Unicode support to ensure graceful degradation. The visual design has been updated to a pastel, Charm-inspired theme with improved accessibility contrast. Additionally, a new web UI layer is introduced, providing a thin adapter pattern with browser-specific implementations (Web Crypto, localStorage) and optional React hooks for easy integration into web applications.

src/ui · high confidence

New platform-specific adapters for Node.js and browser environments

The application now includes dedicated adapter implementations to support both Node.js and web browser runtimes. For Node.js, new modules provide cryptographically secure random generation (using the \crypto\ module), file-system-based persistent storage with path-traversal protection, a structured console logger, and a system clock. For web environments, corresponding adapters leverage the Web Crypto API (\crypto.getRandomValues\) for randomness, \localStorage\ for configuration persistence (with an in-memory fallback), and a browser-compatible console logger. These adapters implement core ports (RandomGenerator, Storage, Logger, Clock) to allow the password generator to function consistently across different JavaScript environments.

src/adapters · high confidence

New service layer for configuration, generation, and structured output

The \src/services\ directory now contains a dedicated service layer that centralizes password generation logic and user interaction. \ConfigurationService\ and \config-service.js\ handle merging presets with user options, validating required fields (type, iteration, separator), and normalizing configurations. \password-service.js\ acts as the core interface, delegating generation to a shared core service instance and providing utilities for strength analysis and bulk generation. \cli-service.js\ implements the terminal output logic, including command generation, strength calculation, and minimal aesthetic rendering. \output-formatter.js\ adds the capability to export generated passwords in structured formats (JSON, YAML, CSV, and text), while \audit-service.js\ provides a wrapper for security audit sessions.

src/services · high confidence

New utility modules for cryptography, password generation, and string manipulation

This change introduces a suite of new utility modules in src/utils to support password generation and data handling. The crypto module provides cryptographically secure random generation via generateRandomBase64 and generateBase64Chunk, with the latter using crypto.randomInt to avoid bias. A new security-audit module tracks entropy usage and algorithm details for transparency when audit mode is enabled. Password generation helpers (randomNumber, randomVowel, randomConsonant, randomSyllable) are added to build syllable-based passwords. A password-strength-analyzer module detects common weak patterns (sequences, keyboard walks, repetitions) and checks against a list of common passwords. Finally, a strings module adds case-conversion utilities (camel, kebab, snake, title case) and currency formatting.

src/utils · high confidence

New view models for entropy, password, and validation display

The web UI now uses dedicated view models in src/ui/web/view-models to transform core generation and validation results into UI-ready data. EntropyViewModel formats entropy bits into a strength label, color, and progress bar percentage (capped at 256 bits). PasswordViewModel presents the generated password with masking, configuration summary, and advanced strength analysis (including score-based indicators, feedback, patterns, dictionaries, and crack time), falling back to entropy-based indicators when advanced analysis is unavailable. ValidationViewModel maps core validation errors to specific form fields (type, length, iteration, separator) and provides convenience flags for UI binding. These changes improve how strength and validation information are presented to users without altering the underlying generation or validation logic.

src/ui/web/view-models · high confidence

New web-based password generator demo with accessibility and theme support

A new interactive web demo has been added to the project, providing a standalone user interface for generating passwords. The interface features a segmented control for selecting password types (Random, Passphrase, Speakable, Base64, Quantum), a length slider, and advanced options for chunks and separators. It includes a strength indicator, keyboard shortcuts, and dark/light theme toggling. The demo is built with ES modules, adheres to WCAG 2.1 AA accessibility standards, and integrates with the core generator via a WebUIController adapter.

src/ui/web/demo · high confidence

Removals

Removal of bin/index.js entry point

The file bin/index.js has been deleted from the repository. This removes the primary entry point for the command-line interface, meaning the script can no longer be executed directly via this path.

bin · high confidence

Removal of password-generator module

The password-generator module has been removed from the library, eliminating the functionality previously provided by this component.

lib · high confidence

Behavioural changes

CLI restructured with new bootstrap and controller architecture

The CLI entry point has been refactored to use a new \cli-bootstrap.js\ module that wires Node.js-specific adapters (such as \NodeCryptoRandom\ and \EFFDicewareDictionary\) to the core password generation service. A new \CLIController.js\ acts as a thin adapter using Commander.js to parse arguments and delegate business logic, while \onboarding.js\ now serves as a compatibility bridge re-exporting functions from the unified onboarding module. This change introduces a cleaner separation between CLI concerns and core business logic, supporting features like optional clipboard functionality and security audit reports.

src/cli · high confidence

Migrated to ESLint flat config and added platform-agnostic enforcement rules

The core package now uses the ESLint flat config format (eslint.config.js) instead of the legacy .eslintrc.json, ensuring compatibility with ESLint 9. This configuration enforces the package's zero-dependency architecture by blocking imports of Node.js-specific modules (such as crypto, fs, path, and http) in core source files, requiring developers to use the defined port interfaces instead.

packages/core · high confidence

Project rebrand to jspassgen and dual-licensing under Apache-2.0 OR MIT

The project has been rebranded from 'Password Generator' to 'jspassgen' (JavaScript Password Generator), updating the package name, website references, and documentation. The license has changed from MIT-only to a dual-license model (Apache-2.0 OR MIT), with the corresponding license files added and the main LICENSE file updated to reflect this. The NPM package name has been corrected to @sebastienrousseau/jspassgen, and the ESLint configuration has been migrated to the new flat config format (eslint.config.js) to support modern Node.js versions.

(repo-wide) · high confidence

Redesigned Web UI with modern styling and accessibility improvements

The web demo interface has been visually overhauled with a new design system featuring CSS custom properties for consistent theming, an animated ethereal background, and enhanced accessibility. The update includes WCAG 2.2 AAA-compliant focus indicators, support for high-contrast and reduced-motion preferences, and a refined layout for form elements and cards, resulting in a more polished and user-friendly experience.

src/ui/web/demo/styles · high confidence

Web UI demo rebranded with theme support and enhanced password type controls

The web demo has been rebranded as the JavaScript Password Generator (jspassgen) and now includes a new theme management system that supports light, dark, and system preferences, persisting the choice in local storage. The main entry point introduces a 'quantum-resistant' password preset and refines the UI behavior for different password types: the length slider is hidden for word-based, quantum, and pronounceable types, while the iteration label dynamically updates to reflect 'Words', 'Syllables', or 'Chunks' depending on the selection.

src/ui/web/demo/scripts · high confidence

Test coverage

Added comprehensive test coverage for UI components and utility functions; Added comprehensive test coverage for browser, node, and web adapter modules; Added comprehensive test coverage for core password generation domain; Added parity tests for CLI and Web UI adapters; Added test coverage for CLI, configuration, and password generation services; Added unit and CLI integration tests for the password generator; Added unit and integration tests for CLI components; Added unit tests for configuration, entry point, and onboarding modules; Added unit tests for web UI controllers and view models.

Dependencies

Migrate to monorepo structure and update Node.js requirement

The project has been restructured into a monorepo using npm workspaces, introducing a new \packages/core\ directory for platform-agnostic password generation logic and a \benchmarks\ directory for performance testing. The root \package.json\ has been updated to require Node.js 22 or higher, upgraded to use modern versions of development tools (such as ESLint 9, Prettier 3.9, and Babel 8), and renamed to \@sebastienrousseau/password-generator\ with a dual Apache-2.0 OR MIT license.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 58 → 61 (+3.0)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 65 → 61 (-4.4)
  • Architecture 57 → 55 (-2.0)
  • Maturity 60 → 76 (+16.1)
  • Readiness 56 → 70 (+13.9)
  • Security 56 → 75 (+18.7)

Resolved (55)

  • Concentrated knowledge decay
  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High vulnerability: [GHSA redacted] (package-lock.json)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 35 more

New (75)

  • CLIController.handleCliAction (cognitive 24) (src/cli/CLIController.js)
  • CLIController.handleCliAction (cyclomatic 19) (src/cli/CLIController.js)
  • CODEOWNERS assigns no owner to any path
  • Dependency advisory scan runs only on code events
  • FunctionTooLong: service.createService (packages/core/src/service.js)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 55 more

Changes since last survey

  • 7 commits — 6 feature/other, 1 fixes

By area

  • (root) — 4 commits
  • (repo) — 2 commits
  • src/adapters — 1 commit

Notable commits

  • fix: chore(lint): format strings and fix jsdoc config for v1.1.5
  • change: Merge pull request #217 from sebastienrousseau/feat/v1.1.5
  • change: chore(deps): bump esbuild and clear the high-severity audit findings (#264)
  • change: chore(deps): consolidate dependency updates and migrate to ESLint flat config (#262)
  • change: chore(deps-dev): bump mocha from 11.8.0 to 12.0.0 (#267)
  • change: chore(license): ship Apache-2.0 OR MIT (#265)
  • change: chore(merge): resolve merge conflicts with master (ESLint 9, dual-licensing, v1.1.5)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

sebastienrousseau/password-generator was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit aba33397214c1378181d530bc46069df92323b50 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.