Skip to content
CAI
Software that uses CAICheck a score

serbanghita/Mobile-Detect

72.6

Strong · 26 September 2026

2.1k

lines of production code

PHP

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the Mobile Detect library, a PHP tool designed to identify mobile devices, tablets, and operating systems by analyzing user-agent strings. It provides a robust detection engine with structured exception handling and a bounded in-memory cache to prevent memory leaks in long-running environments. The library supports flexible integration through a Composer-managed package and a self-contained standalone distribution that bundles necessary interfaces.

Features

Introduction of dedicated exception classes and standalone distribution

The library now includes specific exception handling via the new \MobileDetectException\ class and \MobileDetectExceptionCode\ constants (e.g., \INVALID\_USER\_AGENT\_ERR\), replacing generic error handling with structured exceptions. Additionally, a \MobileDetectStandalone\ class is introduced to provide a self-contained distribution that loads its own autoloader, simplifying integration for users who prefer not to manage external dependencies.

src · high confidence

New Docker setup script for local development builds

A new Dockerfile.setup and build.sh script have been added to the docker directory to streamline local development builds. The setup script uses the official Composer image to copy project files and execute build.sh, which cleans the vendor directory and runs composer install with dev dependencies, ensuring a consistent environment for running tests locally.

docker · high confidence

New in-memory PSR-16 cache implementation with bounded memory usage

The library now includes a new in-memory cache implementation (\Detection\\Cache\\Cache\) that adheres to the PSR-16 standard. This cache is designed to prevent unbounded memory growth in long-running PHP environments (such as RoadRunner or Octane) by enforcing a configurable maximum entry count (defaulting to 1,000) using a FIFO eviction strategy. It also ensures compatibility with older PSR-16 versions (v1/v2) by avoiding strict scalar type declarations on method parameters, allowing it to coexist with other plugins or frameworks that may have already registered an older interface.

src/Cache · high confidence

New utility and example scripts for Mobile Detect

Added several new PHP and shell scripts to the scripts directory to aid development and integration. These include dump\_magic\_methods.php to generate method signatures, export\_to\_json.php to export detection rules for use in other languages, example.php and test.php as usage demonstrations, test\_standalone.php for the standalone library variant, and pre-commit-hook.sh to automate linting, unit tests, and performance benchmarks before commits.

scripts · high confidence

Repository initialization with development tooling and documentation

The repository has been initialized with a comprehensive set of configuration files and documentation to support the Mobile Detect library. This includes an \.editorconfig\ for consistent code formatting, \.gitignore\ rules for development artifacts, and PHP CS Fixer/PHPCS configurations to enforce PSR-12 standards. The project now provides a \docker-compose.yml\ setup for running unit tests, performance benchmarks, and static analysis (PHPStan) in isolated environments. Additionally, key documentation files such as \README.md\, \CHANGELOG.md\, \CONTRIBUTING.md\, \KNOWN\_LIMITATIONS.md\, and \SECURITY.md\ have been added to guide users and contributors, alongside a \MobileDetect.json\ file containing the current detection rules and version metadata.

(repo-wide) · high confidence

Standalone distribution with bundled PSR-16 cache interfaces

A new standalone distribution is now available, providing a self-contained autoloader that bundles the core Mobile Detect classes alongside the PSR-16 (Simple Cache) interface definitions. This allows users to integrate the library without relying on Composer or external package managers, as the necessary cache interfaces are included directly in the distribution.

standalone · high confidence

Test coverage

Added PHPBench performance regression tests for MobileDetect; Added vendor-specific user-agent test suites; Comprehensive test suite for Mobile Detect core components.

Dependencies

Initial Composer dependency configuration for Mobile\_Detect

The project now includes a \composer.json\ manifest to manage dependencies and autoloading. It requires PHP 8.2 or higher and \psr/simple-cache\ versions 1.0 through 3.0. Development dependencies are pinned to specific versions, including PHPUnit 9.6.34, PHP-CS-Fixer 3.95.1, PHP\_CodeSniffer 3.13.6, PHPBench 1.6.1, and PHPStan 2.1.47. Autoloading is configured via PSR-4 for the \Detection\ namespace in \src/\ and \DetectionTests\ in \tests/\. A standalone dependency file for \psr/simple-cache\ is also added to support bundling.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 42 → 73 (+30.6)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (+0.5)
  • Architecture 94 → 100 (+5.9)
  • Maturity 61 → 72 (+11.5)
  • Readiness 19 → 67 (+47.9)
  • Security 49 → 71 (+22.0)

Resolved (21)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low IaC: DS-0026 (docker/Dockerfile.setup)
  • No exposed public API
  • No tests found
  • Test reliability not included
  • …and 1 more

New (29)

  • Dependency hygiene PARTLY measured — Composer dependencies read, no committed lock to grade for currency
  • Documentation: hard to navigate (.github/docs/index.html)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • …and 9 more

Changes since last survey

  • 1 commits — 1 feature/other, 0 fixes

By area

  • (root) — 1 commit

Notable commits

  • change: build(deps-dev): bump squizlabs/php_codesniffer to 3.13.6 ([CVE redacted])

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

serbanghita/Mobile-Detect was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 6ab7b0404df1da8da2aa2c56634362842d9c2a23 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-a15879f6f801.