Skip to content
CAI
Software that uses CAICheck a score

Tyrrrz/YoutubeDownloader

47.1

Weak · 22 September 2026

4.2k

lines of production code

C#

primary language

6

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a cross-platform desktop application for downloading and managing YouTube videos, built on .NET 10 and the Avalonia UI framework. It provides core capabilities for resolving video queries, handling downloads with customizable quality and audio language options, and automatically tagging media files using MusicBrainz metadata. The application supports secure authentication via encrypted cookies, automatic updates, and a localized user interface across multiple languages.

How it got here

2018 — Avalonia UI migration and .NET modernization

13 changes.

The project underwent a comprehensive migration from the Windows-only WPF framework to the cross-platform Avalonia UI, enabling support for macOS and Linux. This effort included upgrading to .NET 10, adopting Centralized Package Management, and refactoring the entire MVVM architecture to use CommunityToolkit.Mvvm. Additionally, the codebase was hardened with encrypted authentication storage and modernized UI components.

2020–2026 — Avalonia migration and core refactoring

8 changes.

The project migrated its UI framework from WPF to Avalonia, introducing a centralized view management system and updated converters. Concurrently, the core downloading engine was rewritten to support automatic FFmpeg handling, language-specific audio selection, and improved query resolution. Additional enhancements included re-enabled MusicBrainz tagging, expanded localization support, and standardized HTTP client utilities.

Features

Add thumbnail format detection and standardized HTTP client

Users can now benefit from improved utility functions and network handling within the core downloader. A new ThumbnailExtensions utility allows the application to detect the image format of a thumbnail URL, supporting better media handling. Additionally, the HTTP client is now centralized in a dedicated Http utility class, which automatically attaches a specific User-Agent header (identifying the application as 'YoutubeDownloader') to all outgoing requests, ensuring compatibility with services that require this identification.

YoutubeDownloader.Core/Utils · high confidence

New language support and localization infrastructure

The application now supports Hungarian and Simplified Chinese in addition to the existing English, Ukrainian, German, French, and Spanish options. This change introduces a new \Language\ enum and a centralized \LocalizationManager\ that dynamically switches UI strings based on the user's selected language or system default. The localization files cover all dashboard, settings, authentication, and download dialog text, ensuring a consistent experience across all supported languages.

YoutubeDownloader/Localization · high confidence

Security

Encrypt authentication cookies in settings and refactor service architecture

Authentication cookies are now encrypted at rest in the settings file using AES-GCM and a machine-bound key, preventing plain-text exposure of session data. The application's service layer has been restructured: the previous DownloadService and QueryService models have been removed in favor of a new SettingsService that manages configuration persistence via Cogwheel, and an UpdateService that handles automatic updates using the Onova library.

YoutubeDownloader/Services · high confidence

Behavioural changes

Dialogs migrated to Avalonia UI

The dialog views (AuthSetup, DownloadSingleSetup, DownloadMultipleSetup, MessageBox, and Settings) have been rewritten from WPF XAML to Avalonia AXAML. This migration updates the authentication dialog to use a platform-native WebView for login, replaces the multi-download list with a multi-select ListBox, and modernizes the single-download and settings interfaces with Avalonia-specific controls and styling.

YoutubeDownloader/Views/Dialogs · high confidence

Migrate main window UI from WPF to Avalonia

The main application window has been ported from WPF to Avalonia, replacing the previous RootView with a new MainView. This change updates the UI framework, switching from MaterialDesignInXAML to Material.Styles for styling, and adjusts the layout to use a DialogHostAvalonia with disabled opening animations to prevent WebView positioning issues. The window dimensions and minimum size constraints have been updated to fit the new framework's requirements.

YoutubeDownloader/Views · high confidence

Migrate view models to Avalonia and CommunityToolkit.Mvvm

The Dashboard and Download view models have been rewritten to support the new Avalonia UI framework, replacing the previous Stylet-based implementation with CommunityToolkit.Mvvm. This change introduces a structured DownloadStatus enum (Enqueued, Started, Completed, Failed, Canceled) to track download states, adds a copy-to-clipboard command for error messages on failed downloads, and implements platform-specific file handling (e.g., Windows Explorer navigation) with proper error dialogs. The migration also includes improved resource disposal for cancellation tokens and progress observers to prevent memory leaks.

YoutubeDownloader/ViewModels/Components · high confidence

New query resolution logic with channel handle/slug support and search prefix handling

The core query resolver has been rewritten to support resolving channels by handle or slug in addition to channel IDs, and queries starting with '?' are now explicitly treated as search queries. Additionally, personal system playlists (WL, LL, LM) are skipped for unauthenticated users, and multiple queries are aggregated into a single result with deduplicated videos.

YoutubeDownloader.Core/Resolving · high confidence

New utility extensions and native method bindings for Avalonia migration and security

This change introduces several new utility classes in the Utils/Extensions namespace to support the migration to Avalonia and enhance security. AvaloniaExtensions provide helper methods to retrieve the main application view and handle graceful shutdown across different application lifetimes. CookieExtensions add logic to correctly determine if a cookie applies to a specific URI, handling subdomain scoping. EnvironmentExtensions introduce a new method to retrieve a stable machine ID by reading the Windows registry or Linux machine-id files, which is required for machine-bound encryption of auth cookies. PathExtensions add a method to generate unique file paths to prevent overwrites. Additionally, NativeMethods.cs adds a P/Invoke binding to the Windows user32.dll MessageBox function.

YoutubeDownloader/Utils · high confidence

Port converters to Avalonia and add new value converters

The converter components in the application have been migrated from WPF to Avalonia, updating all existing converters to implement Avalonia's IValueConverter interface and use Avalonia-specific UI types (such as Avalonia.Controls.Documents.InlineCollection). Additionally, several new converters have been introduced to support the new framework: EqualityConverter for boolean equality checks, LanguageToStringConverter for displaying localized language names, VideoQualityPreferenceToStringConverter for formatting quality settings, and two new thumbnail URL converters (VideoToHighestQualityThumbnailUrlStringConverter and VideoToLowestQualityThumbnailUrlStringConverter) that extract the highest and lowest resolution thumbnail URLs from video metadata using YoutubeExplode.

YoutubeDownloader/Converters · high confidence

Port from WPF to Avalonia UI

The application has been migrated from the Windows-only WPF framework to the cross-platform Avalonia UI framework, enabling it to run on macOS and Linux in addition to Windows. This change replaces the previous XAML-based UI and Stylet bootstrapper with Avalonia's XAML (App.axaml) and a new dependency injection setup, while also updating the application entry point and removing legacy WPF-specific configuration files.

YoutubeDownloader · high confidence

Redesigned dashboard and download list UI

The dashboard view has been completely rewritten to use a modern Material Design theme with a new layout. The previous individual download cards have been replaced by a DataGrid that displays thumbnails, file names, and status for all active downloads, including context menu actions to remove, restart, or cancel downloads. The query input area now features a dedicated search button and authentication controls, and the interface supports localization and improved visual styling.

YoutubeDownloader/Views/Components · high confidence

Redesigned download engine with FFmpeg auto-download and language-specific audio support

The core downloading logic has been rewritten to improve reliability and flexibility. FFmpeg is now automatically downloaded at runtime if missing, with support for locating the executable in user and system PATH locations. The download options engine now supports selecting audio tracks by language, allowing users to download videos with specific audio languages. Additionally, a new '≤ 360p' quality preference has been added, and the 'Lowest Quality' option now correctly selects the lowest available resolution (e.g., 144p) instead of the highest. File naming templates now support the '$numc' token for cleaner numbering.

YoutubeDownloader.Core/Downloading · high confidence

Refactor download dialogs and settings with Avalonia MVVM patterns

The dialog view models in the YoutubeDownloader application have been rewritten to use the CommunityToolkit.Mvvm framework and Avalonia UI primitives, replacing the previous custom base classes and manual property notification. This change introduces user-configurable settings for file naming templates, FFmpeg paths, and download preferences (such as container format and quality) directly into the Settings dialog, while the single and multiple download setup dialogs now support custom file naming, unique file path generation to prevent overwrites, and context menu actions to copy titles. The authentication setup dialog has been added to manage cookie-based login state, and the message box view model now supports configurable button text and visibility, allowing for more flexible user prompts.

YoutubeDownloader/ViewModels/Dialogs · high confidence

Refactored UI framework with Avalonia integration and centralized view management

The application has been migrated to the Avalonia UI framework, introducing a new \ViewManager\ that automates view initialization via the Loaded event and binds ViewModels to Views. This change includes a new \DialogManager\ that fixes issues with sequential dialog display and provides standardized file/folder pickers, a \SnackbarManager\ for user notifications, and a \ThemeVariant\ enum supporting System, Light, and Dark modes. Additionally, a \ViewModelManager\ centralizes the creation and configuration of ViewModels using dependency injection, while new generic \Window\ and \UserControl\ base classes enforce type-safe DataContext assignment.

YoutubeDownloader/Framework · high confidence

Reintroduce automatic media tagging with MusicBrainz integration

Media tagging has been re-enabled as an option in settings, restoring the ability to automatically embed metadata into downloaded audio files. The new implementation uses the MusicBrainz API to look up and inject artist, title, album, and sort-name information, while also attaching the video's thumbnail image and adding a comment with download source details. This replaces the previous tagging logic with a dedicated service that handles metadata injection and file saving.

YoutubeDownloader.Core/Tagging · high confidence

Removal of WPF-specific video selection behavior

The WPF-specific behavior class VideoMultiSelectionListBoxBehavior has been removed from the codebase. This component previously handled the synchronization of selected video items between the view and the model for ListBox controls using WPF-specific dependencies like System.Windows.Interactivity and DependencyProperties. Its removal is part of the broader migration from WPF to Avalonia, as this WPF-specific implementation is no longer applicable to the new UI framework.

YoutubeDownloader/Behaviors · high confidence

Removal of legacy .NET Framework Properties files

The AssemblyInfo.cs, Resources.Designer.cs, and Resources.resx files in the Properties folder have been deleted. These files contained assembly metadata, versioning, and strongly-typed resource definitions specific to the legacy .NET Framework project structure. Their removal aligns with the migration to .NET Core 3, where such metadata is typically managed via the project file (csproj) and resource handling is simplified or removed if not needed.

YoutubeDownloader/Properties · high confidence

Removal of legacy WPF dialog and view-model infrastructure

The WPF-specific dialog management layer has been removed from the application. This includes the deletion of \DialogManager.cs\, which previously handled WPF \DialogHost\ integration and native Vista file/folder dialogs, as well as \DialogScreen.cs\, the base classes for WPF dialog screens, and \IViewModelFactory.cs\, the interface used to instantiate specific view models like \DownloadSingleSetupViewModel\ and \DownloadMultipleSetupViewModel\. These changes reflect the migration away from the WPF framework and its associated Stylet/MaterialDesignInXAML dependencies.

YoutubeDownloader/ViewModels/Framework · high confidence

Replace RootViewModel with MainViewModel for initialization and update logic

The application's primary view model has been refactored from RootViewModel to MainViewModel. This change removes the legacy view model that handled query processing and download list management directly, replacing it with a new MainViewModel that focuses on application lifecycle tasks: displaying the Ukraine support message, warning about development builds, and managing automatic updates. The actual download logic and UI state management have been moved to other components (such as DashboardViewModel), while MainViewModel now serves as the entry point for these background services and notifications.

YoutubeDownloader/ViewModels · high confidence

Upgrade to .NET 10 and modernize project structure

The application has been upgraded to target .NET 10.0, requiring users to have the .NET 10 runtime installed to run the software. The project structure has been modernized by migrating from the legacy .sln format to the new .slnx solution format and adopting Centralized Package Management (CPM) via Directory.Packages.props. Additionally, the build process now enforces treating all warnings as errors to improve code quality, and the license has been switched to MIT.

(repo-wide) · high confidence

Dependencies

Migrate to Centralized NuGet Package Management (CPM)

The project now uses Centralized NuGet Package Management to streamline dependency handling. A new Directory.Packages.props file defines the versions for all packages, including major updates like Avalonia 12.1.1 and YoutubeExplode 6.6.2, while the individual project files (such as YoutubeDownloader.Core and YoutubeDownloader) have been refactored to reference these packages without specifying versions directly. This change simplifies version management and ensures consistency across the solution.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 45 → 47 (+2.0)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 70 → 69 (-0.7)
  • Architecture 81 → 81 (+0.0)
  • Maturity 54 → 54 (+0.2)
  • Readiness 29 → 29 (+0.0)
  • Security 58 → 75 (+16.7)

Resolved (8)

  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • LLM evaluation failed
  • No exposed public API
  • Off-boarding risk: anonymized user #1
  • Outdated: DialogHost.Avalonia
  • Outdated: PowerKit

New (13)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (6 lines × 2) (YoutubeDownloader/Framework/UserControl.cs)
  • HackComment (YoutubeDownloader/Views/MainView.axaml)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Hotspot: YoutubeDownloader/Localization/LocalizationManager.cs (YoutubeDownloader/Localization/LocalizationManager.cs)
  • Inconsistent naming convention for injection methods. 'InjectMiscMetadata' is a synchronous method (implied by lack of 'Async' suffix and no CancellationToken parameter), while 'InjectThumbnailAsync' is asynchronous. If both operations are I/O bound or potentially long-running, they should both be async. If 'InjectMiscMetadata' is truly synchronous and fast, the naming is consistent with its behavior, but the inconsistency lies in the fact that 'InjectThumbnail' is async while 'InjectMiscMetadata' is not, suggesting a potential oversight in making the metadata injection async as well, or a lack of uniformity in the API design for tag injection.
  • No checksums published for release artifacts
  • Outdated: Markdig
  • The MediaFile class implements IDisposable (via Dispose) but also exposes a static factory method named Open. While 'Open' is a common pattern for file-like objects, it conflicts with the standard .NET pattern where such objects are typically created via a constructor or a static 'Create'/'From' method, and 'Open' is often reserved for instance methods that return a stream or handle. More critically, if MediaFile is intended to be a wrapper around a file handle, having both Dispose and Open on the same type can be confusing regarding ownership and lifecycle. However, the primary inconsistency here is subtle: 'Open' usually implies returning a new instance or a stream, whereas 'Dispose' cleans up. If 'Open' returns a new MediaFile, it's a factory. If it opens an existing one, it's a lifecycle method. Given 'MediaFile' is likely a value-object or a simple wrapper, 'Open' is a verb implying an action on the instance, which is inconsistent with the noun-like nature of the type name unless it's a stream-like object. A more standard naming for a factory would be 'FromPath' or 'Load'.
  • redundant comment (YoutubeDownloader.Core/Downloading/VideoDownloadOption.cs)

Changes since last survey

  • 10 commits — 7 feature/other, 3 fixes

By area

  • (root) — 5 commits
  • YoutubeDownloader/Localization — 2 commits
  • YoutubeDownloader/Views — 2 commits
  • YoutubeDownloader/YoutubeDownloader.csproj — 1 commit

Notable commits

  • fix: Fix Authentication crash by migrating to Avalonia.Controls.WebView (#887)
  • fix: Fix Avalonia version mismatch (#879)
  • fix: Fix security issues
  • change: Add Hungarian localization (#869)
  • change: Add dependency instructions for web view (#888)
  • change: Allow authentication on all platforms
  • change: Bump the nuget group with 1 update (#884)
  • change: Publish macOS bundle via MacBundle
  • change: Remove redundant build task
  • change: Update YoutubeExplode

Architecture

  • Unchanged — 1 containers · 1 contexts · 0 edges

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

Tyrrrz/YoutubeDownloader was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 5d60ffab1d93aae4a28892beb8d59a58d749be91 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.