Skip to content
CAI
Software that uses CAICheck a score

slimphp/Slim

74.0

Strong · 26 September 2026

4.9k

lines of production code

PHP

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the core Slim 4 PHP micro-framework, providing a structured environment for building HTTP-based applications. It manages the request lifecycle through a PSR-15 compliant middleware stack, handles routing via FastRoute, and processes requests with support for various HTTP methods and content types. The framework includes built-in mechanisms for error handling with content-type negotiation, body parsing, and response emission, while offering factory classes to integrate with multiple PSR-17 HTTP implementations.

How it got here

2010–2015 — Slim 4 core architecture and scaffolding

7 changes.

This period established the foundational structure of the Slim 4 framework, including initial repository scaffolding, dependency management via Composer, and a comprehensive PHPUnit test suite. It introduced core infrastructure such as the application entry point, middleware dispatcher, and a robust set of interfaces for routing, error handling, and PSR-17 factory integration. Additionally, new route invocation strategies were implemented to support PSR-15 handlers and named arguments, solidifying the framework's request lifecycle contracts.

2017–2018 — PSR-15 middleware and error handling standardization

10 changes.

This period focused on modernizing the Slim framework by introducing PSR-15 compliant middleware components for request handling and establishing a robust, standardized error handling system. The work included implementing new HTTP exception classes, creating abstract error renderers for multiple formats (HTML, JSON, XML, Plain Text), and adding an error handler with content-type negotiation. Comprehensive test coverage was added to ensure the reliability of these new middleware and error handling features.

2019–2022 — PSR-17 factory integration and routing refactor

8 changes.

This period focused on decoupling the routing architecture from direct FastRoute dependencies and introducing comprehensive PSR-17 factory implementations for HTTP object creation. The work streamlined application bootstrapping through new AppFactory and ServerRequestCreatorFactory classes while expanding test coverage across the routing and factory subsystems.

Features

Add default error renderers for HTML, JSON, Plain Text, and XML

The Slim framework now includes built-in error renderers for HTML, JSON, Plain Text, and XML formats. These renderers provide structured error responses: HTML errors include a styled page with exception details when error details are enabled; JSON errors return a structured object with exception chains; Plain Text errors provide a readable stack trace; and XML errors wrap messages in CDATA sections to handle special characters. Each renderer respects the displayErrorDetails flag to control the verbosity of the output.

Slim/Error/Renderers · high confidence

Initial project scaffolding and documentation

The repository is initialized with the core Slim Framework source code and a comprehensive set of configuration files for development and distribution. This includes build and CI configurations (\.coveralls.yml\, \phpunit.xml.dist\, \phpstan.neon.dist\, \psalm.xml\, \phpcs.xml.dist\), repository management files (\.gitignore\, \.gitattributes\, \.editorconfig\), and essential documentation (README, CHANGELOG, UPGRADING, LICENSE, CODE\_OF\_CONDUCT, CONTRIBUTING, SECURITY, MAINTAINERS).

(repo-wide) · high confidence

Introduce PSR-17 factory implementations for multiple HTTP libraries

The Slim/Factory/Psr17 directory now provides concrete factory classes for creating PSR-17 HTTP objects (responses, streams, server requests) using several popular libraries: Slim PSR-7, HttpSoft, Nyholm, Laminas Diactoros, and Guzzle PSR-7. A central Psr17FactoryProvider manages the available factories, allowing the framework to automatically detect and use the installed HTTP library. Additionally, specific factories for Slim-Http are included to support decorated response and server request creation when the Slim-Http package is present.

Slim/Factory/Psr17 · high confidence

Introduce abstract error renderer base class

Added AbstractErrorRenderer as a new base class for error rendering implementations. This class implements ErrorRendererInterface and provides default error titles and descriptions, along with helper methods to extract specific titles and descriptions from HttpException instances, establishing a common foundation for JSON, XML, Plain Text, and HTML error output formats.

Slim/Error · high confidence

Introduction of PSR-15 compliant middleware components

The Slim/Middleware location now provides a suite of new middleware classes implementing the PSR-15 HTTP Server Request Handlers interface. This includes BodyParsingMiddleware for automatically parsing request bodies (JSON, form data, XML), RoutingMiddleware for handling route resolution and throwing specific HTTP exceptions, ErrorMiddleware for centralized error handling and logging, MethodOverrideMiddleware for supporting HTTP method spoofing via headers or form fields, OutputBufferingMiddleware for capturing and appending/prepending output, ContentLengthMiddleware for ensuring Content-Length headers are present, and ResponseFactoryMiddleware (implied by context of new files) for dependency injection. These components replace older patterns and provide a standardized, interoperable way to handle common HTTP tasks within the Slim framework pipeline.

Slim/Middleware · high confidence

New AppFactory and ServerRequestCreatorFactory for simplified application bootstrapping

Slim introduces two new factory classes, AppFactory and ServerRequestCreatorFactory, to streamline the creation of the application instance and server request creator. AppFactory::create() allows users to instantiate the App with optional dependencies like the container, callable resolver, and middleware dispatcher, automatically detecting and decorating PSR-17 response factories if available. Similarly, ServerRequestCreatorFactory::create() handles the creation of the server request creator, supporting automatic detection of PSR-17 implementations and optional Slim HTTP decorator application. These factories provide static methods to set these components globally or pass them directly, reducing boilerplate code for common setup scenarios.

Slim/Factory · high confidence

New core interfaces for routing, middleware, and PSR-17 factories

The Slim/Interfaces directory now exposes a comprehensive set of new contracts that define the framework's core capabilities. Routing is governed by RouteInterface, RouteCollectorInterface, RouteParserInterface, and RouteResolverInterface, enabling route definition, grouping, and URL generation. Middleware handling is standardized via MiddlewareDispatcherInterface and InvocationStrategyInterface, allowing for stack-based dispatch and flexible callable invocation. Error handling is abstracted through ErrorHandlerInterface and ErrorRendererInterface. Additionally, PSR-17 HTTP message factory integration is formalized via Psr17FactoryInterface and Psr17FactoryProviderInterface, while callable resolution is split into CallableResolverInterface and AdvancedCallableResolverInterface. These interfaces collectively establish the structural contracts for the application's request lifecycle.

Slim/Interfaces · high confidence

New default error handler with content-type negotiation

The Slim application now uses a new \ErrorHandler\ class in the \Slim\\Handlers\ namespace to manage error responses. This handler automatically negotiates the response content type (JSON, XML, HTML, or Plain Text) based on the client's \Accept\ header, allowing API consumers to receive structured error data. It also supports forcing a specific content type via \forceContentType()\ and provides configurable renderers for logging errors to the error log.

Slim/Handlers · high confidence

New route invocation strategies for PSR-15 handlers and named arguments

The framework introduces new route invocation strategies in the \Slim\\Handlers\\Strategies\ namespace. \RequestHandler\ allows PSR-15 \RequestHandlerInterface\ instances to be used as route callables, with an optional configuration to append route arguments as request attributes. \RequestResponseNamedArgs\ provides a strategy that passes route parameters as individual named arguments to the callable (using \...$routeArguments\), complementing the existing \RequestResponse\ (array of arguments) and \RequestResponseArgs\ (individual positional arguments) strategies.

Slim/Handlers/Strategies · high confidence

Slim 4.15.1 application entry point and core middleware infrastructure

The Slim framework introduces a new application entry point in \Slim/App.php\ that implements \RequestHandlerInterface\ and manages the middleware stack via \Slim/MiddlewareDispatcher.php\. This dispatcher supports adding middleware by instance, deferred class-name resolution, and callable binding, while \Slim/CallableResolver.php\ handles resolving route and middleware callables from strings or objects. The framework also provides \Slim/ResponseEmitter.php\ for sending HTTP responses to the client and \Slim/Logger.php\ as a basic PSR-3 logger implementation.

Slim · high confidence

Behavioural changes

Refactored HTTP exception hierarchy and added new exception classes

The HTTP exception system has been restructured to improve type safety and usability. The base HttpException class now extends RuntimeException and exposes the original request via getRequest(), while specialized exceptions (such as HttpBadRequestException, HttpNotFoundException, and the newly added HttpGoneException and HttpTooManyRequestsException) inherit from HttpSpecializedException. This change allows custom messages to be passed to specialized exceptions without overriding the default HTTP status code, and HttpMethodNotAllowedException now supports listing allowed methods via setAllowedMethods().

Slim/Exception · high confidence

Refactored routing architecture with new Dispatcher and FastRouteDispatcher classes

The Slim/Routing component has been restructured to introduce a new Dispatcher class that acts as a facade for the underlying FastRoute dispatcher, and a new FastRouteDispatcher class that extends FastRoute's GroupCountBased dispatcher to handle HEAD request fallbacks and method-not-allowed logic. This change decouples the routing resolution from the direct FastRoute implementation, allowing for better caching strategies and more flexible route matching behavior, while maintaining compatibility with existing RouteCollector and RouteParser interfaces.

Slim/Routing · high confidence

Test coverage

Added HeaderStack test asset for header output verification; Added PSR-7 object provider for test decoupling; Added test coverage for the Routing component; Added test mock classes for Slim framework components; Added tests for ErrorHandler content-type negotiation and forcing; Added tests for RequestResponseNamedArgs strategy; Added unit tests for AppFactory and ServerRequestCreatorFactory; Added unit tests for HTTP exception classes; Added unit tests for PSR-17 factory components; Added unit tests for core middleware components; Added unit tests for error renderers; Initial PHPUnit test suite for Slim 4.x core components.

Dependencies

Initial composer.json release for Slim 4

The project now includes a composer.json manifest defining Slim 4 as a PHP micro-framework. It requires PHP 7.4–8.5 and standard PSR interfaces (container, http-factory, http-message, http-server-handler, http-server-middleware, log). Development dependencies include guzzlehttp/psr7, laminas/laminas-diactoros, nyholm/psr7, phpunit (9–12), phpstan (1–2), and psalm (5–6) to support testing and static analysis across multiple PSR-7 implementations and PHP versions.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 52 → 74 (+22.0)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (-0.3)
  • Architecture 94 → 99 (+5.3)
  • Maturity 57 → 56 (-1.0)
  • Readiness 30 → 84 (+54.1)
  • Security 77 → 94 (+16.2)

Resolved (9)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No exposed public API
  • No tests found
  • Test reliability not included

New (42)

  • Ambiguous naming for request execution. run and handle are used interchangeably across App and Route to execute the request handler and return a response. In App, run accepts an optional request (implying auto-detection), while handle requires it. In Route, both signatures are identical. This creates inconsistency in intent: does run imply 'bootstrapping' and handle imply 'processing'?
  • Change coupling: CallableResolver.php ↔ CallableResolverInterface.php (Slim/CallableResolver.php)
  • Dependency hygiene PARTLY measured — Composer dependencies read, no committed lock to grade for currency
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Further sole-owners (lower concentration)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Inconsistent resolution method naming. CallableResolver has a generic resolve method plus specific resolveRoute and resolveMiddleware methods. AdvancedCallableResolverInterface only exposes the specific methods. This suggests resolve might be a fallback or legacy method, while the specific ones are preferred, but the hierarchy doesn't enforce this clearly.
  • No assertions (empty test): testGroup (tests/Routing/RouteCollectorProxyTest.php)
  • No assertions: testComputeRoutingResults (tests/Routing/RouteResolverTest.php)
  • No assertions: testCreateAppWithEmptyContainer (tests/Factory/AppFactoryTest.php)
  • No assertions: testDoesNotUseContainerAsServiceLocator (tests/AppTest.php)
  • No assertions: testErrorHandlerHandlesThrowables (tests/Middleware/ErrorMiddlewareTest.php)
  • No assertions: testHandleMultipleExceptionsAddedAsArray (tests/Middleware/ErrorMiddlewareTest.php)
  • No assertions: testLogErrorRenderer (tests/Handlers/ErrorHandlerTest.php)
  • No assertions: testResolveRoute (tests/Routing/RouteResolverTest.php)
  • No assertions: testRespond (tests/ResponseEmitterTest.php)
  • No assertions: testRespondIndeterminateLength (tests/ResponseEmitterTest.php)
  • …and 22 more

Changes since last survey

  • 20 commits — 13 feature/other, 7 fixes

By area

  • (repo) — 8 commits
  • (root) — 4 commits
  • Slim/Routing — 3 commits
  • Slim/Handlers — 2 commits
  • Slim/Error — 1 commit
  • tests/Error — 1 commit
  • tests/Factory — 1 commit

Notable commits

  • fix: Merge branch '4.x' into fix-intermittent-text-failure
  • fix: Merge branch '4.x' into fix/error-handler-content-type-caching
  • fix: Merge branch '4.x' into fix/json-error-renderer-invalid-utf8
  • fix: Merge pull request #3464 from iliaal/fix/error-handler-content-type-caching
  • fix: Merge pull request #3465 from iliaal/fix/json-error-renderer-invalid-utf8
  • fix: Merge pull request #3468 from kaii-k/fix/sec02-bound-allowed-methods-cache
  • fix: Merge pull request #3470 from akrabat/fix-intermittent-text-failure
  • change: Bound FastRouteDispatcher::getAllowedMethods() cache size
  • change: Isolate testDetermineResponseFactoryThrowsRuntimeException on PHPUnit 10+
  • change: Merge commit from fork
  • change: Negotiate error handler content type on every request
  • change: Prove JSON error renderer substitutes invalid UTF-8
  • change: Remove unnecessary comments and test
  • change: Restore negotiation when forceContentType(null) is called
  • change: Simplify to single-entry memo per akrabat review feedback
  • change: Stop decoding route arguments twice
  • change: Substitute invalid UTF-8 in JSON error renderer output
  • change: Update CHANGELOG
  • change: Update CHANGELOG
  • change: Update changelog

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

slimphp/Slim was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 3675bf6baac66b07032575b7bef4200b60b7974b — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-a9cd699f3cd5.