thedevs-network/kutt
33.0
Weak · 2 October 2026
6.7k
lines of production code
JavaScript
primary language
2
measurements over time
What this system is
This system is a self-hosted URL shortening service that provides core link management, custom domain support, and detailed visit analytics. It features a server-rendered interface powered by HTMX and Handlebars, offering an interactive experience for creating, editing, and tracking shortened URLs without full page reloads. The backend supports multiple relational databases (PostgreSQL, MySQL, SQLite) and includes robust administrative controls for managing users, domains, and links, along with OIDC authentication and optional email notifications.
How it got here
2018 — v3 architecture rewrite
25 changes.
This period involved a comprehensive rewrite of the application's architecture, migrating the server from Next.js to a standalone Express backend with HTMX and replacing the Neo4j database with relational options like PostgreSQL and SQLite. The legacy React client components and Redux state management were entirely removed to make way for a new server-side rendering approach and TypeScript-based structure.
2019–2025 — HTMX migration and admin overhaul
21 changes.
The project underwent a significant architectural shift, migrating the frontend from Next.js to an HTMX-driven server-rendered model with Handlebars templates. This period also focused on expanding administrative capabilities through a comprehensive admin panel, OIDC authentication, and custom domain management, while restructuring the database and query layers for improved performance and modularity.
Features
Add password reset flow UI components
Added Handlebars partials for the password reset experience: a form to request a reset link via email, a form to set a new password (with correct autocomplete attributes to prevent browser autofill issues), and a success confirmation page with a link to log in.
_server/views/partials/reset\password · high confidence
Added PWA manifest and robots.txt for static assets
The static directory now includes a manifest.webmanifest file that configures the application as a Progressive Web App (PWA) with specific icons, theme colors, and standalone display settings, alongside a robots.txt file that disallows all web crawlers from indexing the site.
static · high confidence
Added placeholder for custom style configurations
A new \.gitkeep\ file has been added to the \custom\ directory to ensure the folder persists in the repository. This directory is intended for users to place supported customization files, such as styles, and should be mounted when using Docker.
custom · high confidence
Added server-side icon partials for UI components
The server now includes a set of Handlebars partials in \server/views/partials/icons\ containing SVG definitions for common interface elements (such as arrow, check, cog, and trash icons). This change supports the migration toward an HTMX-driven rendering approach by providing the necessary icon assets directly on the server side, ensuring consistent UI rendering without relying on client-side icon libraries.
server/views/partials/icons · high confidence
Custom domain management interface added to settings
Users can now manage custom domains for their short URLs directly from the settings page. This update introduces a new UI section that displays existing domains in a table, allows adding new domains via a form (with optional homepage redirection), and supports deleting domains through a confirmation dialog. The interface uses HTMX for asynchronous interactions, providing immediate feedback for adding, deleting, and listing domains without full page reloads.
server/views/partials/settings/domain · high confidence
Docker deployment support and configuration overhaul
The application now supports containerized deployment via a new Dockerfile and multiple docker-compose configurations for SQLite, Postgres, and MariaDB backends, including optional Redis caching. Configuration has shifted from JavaScript files to environment variables, documented in a new .example.env file, enabling zero-config setup with SQLite as the default database. Additionally, the project has migrated from Travis CI to GitHub Actions for Docker image releases.
(repo-wide) · high confidence
New admin management interface for links, users, and domains
The admin panel now includes a comprehensive UI for managing links, users, and domains, featuring searchable and filterable tables for each entity. Administrators can create new users (with role and verification options) and domains, as well as edit link details directly within the table. The interface supports banning and deleting users and domains, with specific options to cascade bans or deletions to associated resources (e.g., banning a user also removes their links and domains). All interactions are handled via HTMX for a responsive, page-load-free experience.
server/views/partials/admin · high confidence
Removals
Removal of Header and NeedToLogin components
The Header component and its sub-components (HeaderLogo, HeaderLeftMenu, HeaderRightMenu, HeaderMenuItem) have been removed from the application, along with the NeedToLogin component. This eliminates the previous navigation bar structure and the specific login prompt UI that appeared when users were not authenticated.
client/components/Header · high confidence
Removal of Redux store configuration files
The Redux store setup files (index.js, store.dev.js, and store.prod.js) have been removed from the client/store directory. This eliminates the legacy store creation logic that previously initialized the Redux store with reducers and thunk middleware, indicating a shift away from this specific store configuration pattern in the client application.
client/store · high confidence
Removal of client-side helper modules
The analytics, animations, and reCAPTCHA helper modules have been removed from the client codebase. This eliminates the Google Analytics integration (including page view and event logging), the styled-components keyframe animations (fadeIn and spin), and the custom reCAPTCHA rendering logic, meaning these specific client-side functionalities are no longer available via these helper files.
client/helpers · high confidence
Removal of legacy Footer component
The legacy Footer component implementation (Footer.js and its index export) has been removed from the client codebase. This change eliminates the previous footer structure which displayed attribution to 'The Devs', a link to the project's GitHub repository, and a link to the Terms of Service.
client/components/Footer · high confidence
Removal of legacy JavaScript authentication and URL controllers
The legacy JavaScript controllers for authentication (authController.js), URL handling (urlController.js), and body validation (validateBodyController.js) have been removed from the server. This deletion eliminates the previous implementation of user signup, login, password reset, URL shortening, custom domain management, and basic input validation, reflecting the project's migration to a new architecture (TypeScript/MongoDB) where these responsibilities are handled by different components.
server/controllers · high confidence
Removal of legacy JavaScript login components
The JavaScript-based login form implementation (Login.js, LoginBox.js, LoginInputLabel.js) and its index export have been removed from the client. This deletion eliminates the previous React class component logic, including the specific validation rules (e.g., 8-character minimum password), reCAPTCHA integration, and Redux-connected authentication handlers, as part of the broader migration to TypeScript and Postgres.
client/components/Login · high confidence
Removal of legacy Table body components
The \TBody\ directory has been completely removed, deleting the \TBody\, \TBodyButton\, \TBodyCount\, \TBodyShortUrl\, and \index.js\ files. This eliminates the previous implementation of the table body row rendering, including the logic for displaying short URLs, copy-to-clipboard functionality, click-to-view stats navigation, and row deletion triggers.
client/components/Table/TBody · high confidence
Removal of legacy URL table components
The legacy URL table UI components (Table, TableNav, TableOptions, and their index) have been removed from the client. This eliminates the previous implementation for displaying, searching, paginating, and deleting shortened links, indicating a shift to a new table interface or architecture elsewhere in the application.
client/components/Table · high confidence
Removal of legacy client UI components
The Button, Error, PageLoading, Table (specifically THead), and TextInput components have been deleted from the client codebase. This removes the underlying implementation for these specific UI elements, indicating a shift away from the previous styling and structure for buttons, error messages, loading states, table headers, and text inputs.
(repo-wide) · high confidence
Removal of the BodyWrapper component
The BodyWrapper component, which previously handled global layout structure (including the Header), page loading states, Google Analytics initialization, and authentication token renewal, has been removed from the client codebase.
client/components/BodyWrapper · high confidence
Removed Features section component
The Features section, which previously displayed a list of product capabilities (such as link management, custom domains, API access, and open-source status) with associated icons and descriptions, has been removed from the client interface. The \Features.js\, \FeaturesItem.js\, and \index.js\ files in \client/components/Features\ are deleted, meaning this specific marketing or informational block is no longer rendered on the page.
client/components/Features · high confidence
Removed legacy Stats page components
The Stats page components (Stats, StatsError, StatsHead, and the index entry) have been removed from the client. This eliminates the previous implementation that fetched URL statistics via a POST request to /api/url/stats and displayed them using styled React components, indicating a shift in how this feature is handled or a replacement with a different implementation elsewhere.
client/components/Stats · high confidence
Removed legacy StatsCharts components
The \StatsCharts\ directory has been completely removed, deleting the \Area\, \Bar\, \Pie\, and \StatsCharts\ components along with their \withTitle\ wrapper and index entry. This eliminates the previous implementation of view trend, referrer, browser, country, and OS charts that relied on \recharts\ and \styled-components\, indicating a shift away from this specific charting architecture in the stats display.
client/components/Stats/StatsCharts · high confidence
Shortener component suite removed
The entire Shortener component hierarchy (including Shortener, ShortenerInput, ShortenerOptions, ShortenerResult, ShortenerCaptcha, and ShortenerTitle) along with the shared Modal component has been deleted from the client. This removes the previous React-based UI for creating shortened URLs, custom aliases, and password protection, as well as the modal dialog used for confirmations.
client/components/Shortener · high confidence
Behavioural changes
Authentication, Admin, and Domain Management Handlers
The server/handlers directory has been restructured into dedicated modules for authentication, domains, helpers, links, locals, rendering, users, and validators. This change introduces OIDC authentication support, a new admin interface for managing users and domains, and rate limiting capabilities. It also adds an initial admin setup flow for new instances, custom domain management with ban capabilities, and refined link creation/editing logic with validation.
server/handlers · high confidence
Database directory structure created for SQLite storage
A new 'db' directory has been added to the project to organize database files. This change establishes a dedicated location for file-based databases, specifically noting that SQLite database files will be stored within this folder, helping to keep the project root clean and data files centralized.
db · low confidence
Database query layer restructured into modular Knex-based files with Redis caching
The server's database access logic in the \server/queries\ directory has been reorganized into distinct modules (\domain\, \host\, \link\, \user\, \visit\) using the Knex query builder. This change introduces Redis caching for frequently accessed records (domains, hosts, links, users, and stats) to improve performance, and implements database-agnostic query patterns to support MySQL, SQLite, and PostgreSQL. The \visit\ module now aggregates analytics data (countries, referrers, browsers, OS) in hourly buckets within a transaction to ensure accurate counting under concurrency.
server/queries · high confidence
Database schema restructured with new migration models
The database schema has been reorganized into individual Knex migration files for core entities (domains, hosts, IPs, links, users, and visits). This change introduces a UUID column to both domains and links for unique identification, adds a user\_id foreign key to the domains table, and updates the visits table to track browser and operating system statistics via dedicated integer columns. Additionally, the visits table now includes an updated\_at timestamp and enforces cascade deletion for associated links and users.
server/models · high confidence
Database schema updates: user roles, visit tracking, and index optimizations
This release introduces several database schema changes to support new features and improve performance. A 'role' column is added to the users table to distinguish between standard users and administrators, with existing users matching the ADMIN\_EMAILS environment variable automatically promoted. The visits table now includes a user\_id foreign key to track which user generated each visit, with a migration that safely backfills this data for smaller datasets while skipping high-volume tables to prevent locking. Additionally, multiple indexes are created on links, domains, hosts, and visits tables to speed up queries, and the unique constraint on the users.apikey column is enforced. Legacy columns related to cooldowns and malicious attempts are removed from the users table.
server/migrations · high confidence
Email system refactored with optional sending and new change-email flow
The mail module has been rewritten to support optional email sending via a new \MAIL\_ENABLED\ environment variable, preventing errors when the feature is disabled. It now reads HTML templates from disk and injects site-specific text (like \{{site\_name}}\ and \{{domain}}\) at runtime. A new \changeEmail\ function has been added to handle email verification for address changes, and the existing verification and reset password flows have been updated with corrected phrasing and new URL paths.
server/mail · high confidence
Migrate database backend from Neo4j to MongoDB
The server's database layer has been switched from the Neo4j graph database to MongoDB. This change removes the previous Neo4j-specific drivers and query logic (including Cypher queries for URLs, users, and visits) and replaces them with MongoDB implementations, fundamentally altering how data is stored and retrieved for core features like URL shortening, user management, and visit tracking.
server/db · high confidence
Migrate frontend from Next.js to HTMX with new client-side logic
The application's frontend has shifted from a Next.js-based architecture to an HTMX-driven model, introducing new client-side behavior in \static/scripts/main.js\ and \static/scripts/stats.js\. Users will experience interactive features such as custom HTMX extensions for path parameters, automatic form resets for password and email changes, and enhanced table pagination controls. Additionally, the stats dashboard now features dynamic chart rendering (using Chart.js) for views and browser statistics, with support for switching between daily, weekly, monthly, and yearly periods, as well as QR code generation and link copying capabilities.
static/scripts · high confidence
Migrate server views from Next.js to HTMX-based Handlebars templates
The server-side rendering layer has been replaced with a set of Handlebars (.hbs) templates that utilize HTMX for dynamic interactions. This change introduces a new layout structure (layout.hbs) and dedicated views for core user flows, including URL shortening, statistics (stats.hbs), account management (settings.hbs, login.hbs, reset\_password.hbs), and administrative functions (admin.hbs). Key behavioral updates include the use of HTMX for asynchronous data loading (e.g., stats), automatic redirections after logout or verification, and conditional rendering for features like email reporting and password resets. This migration removes the previous Next.js dependency for these views, resulting in a lighter, server-rendered experience with client-side enhancements driven by HTMX.
server/views · high confidence
Redesigned UI with CSS variables and responsive styles
The application's visual appearance has been updated to use CSS variables for colors and gradients, replacing hardcoded values to allow for easier theming and consistency. The new styles include responsive design adjustments and specific fixes for UI elements such as button spinners and Safari rendering issues, ensuring a more polished and consistent user experience across different browsers and screen sizes.
static/css · high confidence
Redesigned UI with HTMX-powered interactions and new admin/reporting features
The interface has been rebuilt using Handlebars partials and HTMX to replace the previous Next.js implementation, enabling dynamic, server-rendered updates without full page reloads. Key changes include a new header and footer layout with a PNG logo, a redesigned shortener form with advanced options (domain, custom URL, password, expiration), and a new stats page displaying visit analytics via charts and a world map. Additionally, the application now supports an admin panel for administrators, a report abuse page (conditionally shown if a report email is configured), and a contact us feature that reveals the support email via an HTMX request.
server/views/partials · high confidence
Redesigned authentication UI with OIDC support and admin onboarding
The authentication interface has been updated to support OpenID Connect (OIDC) login, displaying a configurable button for OIDC providers when enabled. A new admin onboarding flow allows users to create an initial admin account via a dedicated form, while the standard login and signup forms now utilize HTMX for asynchronous submission and error handling. Additionally, specific states for disabled login, email verification, and post-login redirection are now handled by distinct partials to improve user feedback.
server/views/partials/auth · high confidence
Redesigned links management interface with inline editing and admin controls
The links management view has been rebuilt using HTMX to provide a more interactive experience. Users can now search, paginate, and sort links directly within the table without full page reloads. A new inline editing mode allows users to modify a link's target, address, password, description, and expiration time in-place. Additionally, an admin section has been added, enabling administrators to ban links and associated users, hosts, or domains via a dedicated confirmation dialog.
server/views/partials/links · high confidence
Redesigned settings page with new API key management and account controls
The settings interface has been rewritten to use HTMX for dynamic, partial-page updates. This update introduces a new API key management section where users can generate, view, and copy their API keys directly from the settings page. Additionally, the account management capabilities have been expanded to include dedicated, standalone forms for changing the email address, changing the password (with correct autocomplete attributes to prevent browser autofill issues), and deleting the account, all featuring improved error handling and success feedback.
server/views/partials/settings · high confidence
Removal of Redux action creators and type constants
The Redux action layer in the client has been removed, eliminating the \client/actions\ directory and its associated \actionTypes.js\ constants. This deletes all legacy action creators for URL management (shortening, listing, deleting), user authentication (login, signup, logout, token renewal), and settings (custom domains, API keys), indicating a migration away from the Redux state management pattern for these features.
client/actions · high confidence
Removal of centralized Redux reducer file
The single file containing all Redux reducers (url, error, loading, auth, settings) and the root reducer combination has been deleted from the client/reducers directory. This change removes the monolithic reducer structure, implying that the application's state management logic has been split or moved to other files or locations within the codebase.
client/reducers · high confidence
Removal of legacy Next.js client pages and document structure
The client-side page definitions and the global document template have been removed from the \client/pages\ directory. This includes the deletion of \\_document.js\ (which previously handled server-side styling and meta tags), \index.js\ (the homepage), \login.js\, \logout.js\, \reset-password.js\, \settings.js\, \stats.js\, \terms.js\, \url-password.js\, and \verify.js\. These files, which previously relied on \next-redux-wrapper\ and \styled-components\ for rendering and state management, are no longer present, indicating a significant restructuring or migration of the client application's routing and rendering architecture.
client/pages · high confidence
Removal of legacy Settings UI components
The previous Settings page implementation, including the main container and sub-components for custom domains, API keys, password changes, and user welcome messages, has been removed from the client. This deletion clears the way for the new Settings interface introduced in the v2-beta refactor.
client/components/Settings · high confidence
Removed reCAPTCHA and analytics configuration
The client configuration file (config.example.js) has been deleted, removing the previously available settings for the reCAPTCHA site key and the Google Analytics tracking ID. Users will no longer be able to configure these specific third-party integrations through this example configuration file.
client · high confidence
Server migration to Express/HTMX, Postgres/SQLite, and OIDC support
The server backend has been rewritten from a Next.js application to a standalone Express server using Handlebars (HTMX) for rendering, replacing the previous client-side framework. Database support has shifted from Neo4j to relational databases (PostgreSQL, MySQL, or SQLite) via Knex, with configuration now managed through environment variables in a new \env.js\ module. Authentication has been updated to use JWTs stored in cookies instead of headers, and a new OIDC (OpenID Connect) login strategy has been added, configurable via environment variables. Additionally, Redis is now an optional caching layer, and the previous \config.js\ file has been removed in favor of the new environment-based configuration.
server · high confidence
Server routes restructured into modular files with OIDC and admin setup support
The server routing logic has been refactored from a single file into distinct modules (auth, domain, health, link, renders, user) to improve organization. This change introduces new authentication capabilities, including OpenID Connect (OIDC) login support and a dedicated endpoint for creating the initial admin user during first-time setup. It also adds specific routes for password and email changes, account deletion, and API key generation, while maintaining existing functionality for link management, domain administration, and user oversight.
server/routes · high confidence
Server utility library restructured for multi-database support and custom link generation
The server utility module has been reorganized into a modular structure (asyncHandler, knex, utils, map) to support a migration to multiple database backends (SQLite, MySQL, PostgreSQL, MSSQL, Oracle) and TypeScript. Key changes include the introduction of a custom alphabet configuration for link address generation via nanoid, database-agnostic timestamp truncation logic for stats aggregation, and the addition of a low-resolution world map dataset for geographic visualization. The utils module also centralizes token signing, cookie management (with SameSite: Lax), and URL parsing logic.
server/utils · high confidence
Visit tracking now supports offline mode and enhanced analytics
The visit tracking system in server/queues now functions without Redis; if Redis is disabled, visits are processed synchronously instead of being queued. Additionally, visit records now include the user ID associated with the link, and country detection prioritizes the CF-IPCountry header with geoip-lite as a fallback, while user agent parsing has been updated to use the express-useragent library for more accurate browser and OS identification.
server/queues · high confidence
Dependencies
Kutt upgraded to v3.2.6 with a complete dependency overhaul and lockfile migration
The application has been updated to version 3.2.6, migrating the \package-lock.json\ from version 1 to version 3. This change replaces the legacy dependency tree with a modern set of packages, introducing significant upgrades such as Express 4.22.2, Knex 3.1.0, and Nodemailer 9.0.3, while adding new capabilities like Bull 4.16.5 for job queues, ioredis 5.4.2 for Redis connectivity, and OpenID Connect support via openid-client 5.7.0. The update also removes the previous Next.js and React frontend dependencies in favor of server-side rendering with HBS, and drops legacy tools like Husky and ESLint in favor of TypeScript type definitions and Redoc for API documentation.
(dependencies) · high confidence
Updated Chart.js to v4.4.4
The static library \static/libs/chart.min.js\ has been updated to version 4.4.4. This upgrade brings the latest features and bug fixes from the Chart.js library to the client-side charts used in the application.
static/libs · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 34 → 33 (-0.9)
- Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 54 → 54 (+0.0)
- Architecture 93 → 85 (-7.8)
- Maturity 56 → 56 (+0.0)
- Readiness 15 → 13 (-1.9)
- Security 58 → 50 (-7.6)
- Accessibility 41 → 41 (+0.0)
- Performance 100 (new)
Resolved (3)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
New (25)
- Outdated (npm): bcryptjs
- Outdated (npm): better-sqlite3
- Outdated (npm): cors
- Outdated (npm): date-fns
- Outdated (npm): dotenv
- Outdated (npm): envalid
- Outdated (npm): express
- Outdated (npm): express-rate-limit
- Outdated (npm): express-useragent
- Outdated (npm): express-validator
- Outdated (npm): geoip-lite
- Outdated (npm): hbs
- Outdated (npm): helmet
- Outdated (npm): ioredis
- Outdated (npm): isbot
- Outdated (npm): jsonwebtoken
- Outdated (npm): knex
- Outdated (npm): mysql2
- Outdated (npm): nanoid
- Outdated (npm): nodemailer
- …and 5 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
thedevs-network/kutt was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 2 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 279b491b53bbd01fbae70f603222526962772061 — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.