ug-libraries/clean-architecture-core-php
70.6
Strong · 21 September 2026
984
lines of production code
PHP
primary language
4
measurements over time
What this system is
This system is a PHP-based application framework that manages HTTP requests and business use cases through immutable, dependency-injected components. It enforces structured error handling via a standardized exception formatting contract and provides a streamlined API for creating and accessing request data. The architecture emphasizes immutability and explicit field access, ensuring consistent data flow from request to response presentation.
Behavioural changes
Exception formatting interface expanded with status code and message accessors
The ExceptionFormatter trait now requires implementers to provide status code and message accessors (getCode and getMessage), changing the contract for exception formatting. This ensures that all exceptions processed by the formatter expose their HTTP status code and message, allowing for more structured error responses.
src/Exception · medium confidence
Refactor Usecase to use immutable request handling and add field accessors
The Usecase class now requires non-null RequestInterface and PresenterInterface dependencies, replacing the previous nullable builder pattern with immutable setter methods (withRequest/withPresenter). A new getField method allows retrieving individual request fields with an optional default, and a getRequestId accessor is added. The Response class now accepts a default value for the get method, and the Presenter's getResponse/getFormattedResponse methods are removed.
src/Usecase · medium confidence
Simplified request handling with direct property access
The request handling mechanism has been refactored to remove the intermediate \RequestBuilder\ and \RequestParam\ classes, replacing them with a direct payload-to-object transformation. The \Request\ class now uses a \PropertyAccessor\ trait to allow individual field access via magic methods (\\_\get\/\\\_set\) and a \get\ method, while \createFromPayload\ returns the request instance itself rather than a builder. This change streamlines the API for creating and accessing application request data.
(repo-wide), src/Request · high confidence
Test coverage
Updated test suite for request and usecase components
Added a new test file for the CustomPresenter and updated existing tests for CustomRequest and Usecase. The request tests now verify that request creation returns the RequestInterface rather than RequestBuilderInterface, and validate that field constraints are properly wrapped in BadRequestContentException. The usecase tests were updated to use the new withRequest/withPresenter fluent API methods and assert that the presenter's getResponse() method returns the correct data structure.
tests · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 71 → 71 (-0.6)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 100 (+0.0)
- Architecture 69 → 69 (+0.0)
- Maturity 69 → 69 (+0.0)
- Readiness 68 → 65 (-2.6)
- Security 88 → 96 (+8.3)
Resolved (12)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High CVE: [GHSA redacted] (composer.lock)
- High: security finding (details withheld)
- High: security finding (details withheld)
- No exposed public API
- Test reliability not included
- The visible Core Overview section shows only Application Request code (Request class, requestPossibleFields) with a partial applyConstraintsOnRequestFields method before any of the outlined Presenter, Response, Use Case, or Exception sections appear. (README.md)
- early-stage repository — too little history to judge knowledge freshness
- git history depth insufficient
- git history depth insufficient
- single-maintainer — knowledge-concentration (bus factor) risk
New (17)
- Ambiguous overlap between Interface and Trait. ExceptionInterface defines format(), and ExceptionFormatter trait also implements format(). It is unclear if the trait is the intended implementation of the interface method, or if they serve different purposes (e.g., one for API output, one for internal formatting). If they are the same, the interface should not be redundant with the trait's public method unless the trait is the sole implementation strategy.
- Documentation: no usage examples (README.md)
- High CVE: [GHSA redacted] (composer.lock)
- High CVE: [GHSA redacted] (composer.lock)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Inconsistent method signature for property access. RequestInterface.get accepts a default value argument, while ResponseInterface.get does not. This forces consumers to handle null checks differently depending on whether they are accessing request data or response data.
- Medium: security finding (details withheld)
- No assertions: testCanNotBuildNewRequestWithMissingMoreNestedParameters (tests/Request/CustomRequestTest.php)
- No assertions: testCanNotBuildNewRequestWithMissingParameters (tests/Request/CustomRequestTest.php)
- No assertions: testCanNotBuildNewRequestWithUnrequiredNestedParameters (tests/Request/CustomRequestTest.php)
- No assertions: testCanNotBuildNewRequestWithUnrequiredParameters (tests/Request/CustomRequestTest.php)
- No assertions: testCanNotBuildNewRequestWithWrongNestedMissingParameters (tests/Request/CustomRequestTest.php)
- No dependency advisory monitoring
- Outdated: ramsey/uuid
- Redundant method names with potentially different semantics. Both interfaces/traits expose getErrors(), but it is unclear if they return the same structure. Given Exception also has getErrors() and getDetails(), while ExceptionFormatter has getCode() and getMessage(), the naming suggests getErrors might be a raw data dump in one context and a formatted list in another, or vice versa. This creates ambiguity for implementers.
- Workflow token permissions not restricted
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
ug-libraries/clean-architecture-core-php was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit cbb28b2bfbab67da4402b42554043e6486589409 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.