Skip to content
CAI
Software that uses CAICheck a score

w7corp/easywechat

63.9

Adequate · 26 September 2026

7.7k

lines of production code

PHP

with JavaScript, TypeScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

EasyWeChat is a PHP library that provides a unified interface for integrating with various WeChat platforms, including Official Accounts, Mini Programs, WeChat Work, and the Open Platform. It handles core infrastructure tasks such as access token management, message encryption and decryption, and HTTP request signing for both legacy and modern API versions. The system also includes a dedicated module for WeChat Pay v3, enabling merchants to process payments and validate callbacks. Structured around a modern kernel with PSR-7 support, it offers a standardized way to interact with WeChat's diverse ecosystem of services.

How it got here

2015–2017 — Kernel rewrite and rebranding

16 changes.

The project was rebranded to EasyWeChat and underwent a major architectural overhaul, replacing the legacy Pimple-based structure with a modern, modular Kernel built on Symfony components and PSR standards. This period focused on refactoring core modules like Official Account and Open Platform, introducing comprehensive contract interfaces, and establishing robust test coverage for the new infrastructure.

2018–2022 — Module expansion and contract standardization

15 changes.

This period focused on expanding the library with new providers for WeChat Work, MiniApp, and Open Platform, while introducing a modernized WeChat Pay module with API v3 support. The work heavily emphasized architectural stability by defining strict contract interfaces for account and application configurations across these modules. Concurrently, the core HttpClient was refactored for better reliability and PSR-7 compliance, accompanied by comprehensive test coverage for all new and modified components.

Features

Initial implementation of WeChat Work (OpenWork) provider

This change introduces the complete OpenWork module for the EasyWeChat library, enabling integration with WeChat Work (Enterprise WeChat) as a service provider. It adds the core Application class to manage configuration and access tokens (provider, suite, and authorizer), along with supporting classes for account management, encryption/decryption (Encryptor, SuiteEncryptor), and ticket handling (SuiteTicket, JsApiTicket). The Server component provides a robust event callback system with dedicated handlers for suite ticket refreshes, authorization lifecycle events (create, change, cancel), and contact directory changes (users, parties, tags).

src/OpenWork · high confidence

Introduce dedicated MiniApp application and utility components

This change adds a new \MiniApp\ namespace containing the core application entry point (\Application\), account management (\Account\), access token handling (\AccessToken\), server message handling (\Server\), and utility functions (\Utils\). The \Application\ class provides the main interface for interacting with the MiniApp API, including methods to retrieve the account, encryptor, server, and access token. The \Utils\ class offers helper methods for common operations like converting authorization codes to sessions (\codeToSession\), decrypting session data (\decryptSession\), and retrieving user phone numbers (\getPhoneNumber\). The \AccessToken\ class is specifically configured for MiniApps with a dedicated cache key prefix. These components work together to provide a structured and type-safe way to interact with the MiniApp platform.

src/MiniApp · high confidence

Introduce new WeWork (Enterprise WeChat) application components

This change adds the foundational classes for the WeWork module, including the Application entry point, Account and Config structures, AccessToken and JsApiTicket management, Server for handling callbacks, and Utils for JSSDK signature generation. These components provide the core infrastructure for interacting with the Enterprise WeChat API, including authentication, ticket caching, and message handling.

src/Work · high confidence

Introduces new Kernel components: Config, Encryptor, Message, and ServerResponse

The src/Kernel directory now includes a new Config class that manages configuration items with support for required key validation and ArrayAccess, a new Encryptor class handling AES-256-CBC encryption and decryption for WeChat XML and JSON message formats, a new abstract Message class providing JSON serialization and array access for message attributes, and a new ServerResponse class that wraps PSR-7 responses to handle HTTP header sending and output buffer management.

src/Kernel · high confidence

Introduces new OpenWork contract interfaces for account, application, and suite ticket management

Added three new interfaces to the OpenWork module: Account, Application, and SuiteTicket. The Account interface defines methods for retrieving core credentials such as CorpId, ProviderSecret, SuiteId, SuiteSecret, Token, and AesKey. The Application interface serves as the main entry point, providing access to the Account, Encryptor, Server, Request, Client, HttpClient, Config, ProviderAccessToken, and Cache. The SuiteTicket interface manages the retrieval and setting of the suite ticket. These contracts establish the structural foundation for the OpenWork integration.

src/OpenWork/Contracts · high confidence

Introduces new Pay module with WeChat Pay API v3 support

The \src/Pay\ directory now contains a complete, new implementation for WeChat Pay, introducing support for the API v3 protocol alongside legacy v2 compatibility. This includes a new \Application\ entry point, a \Client\ for handling HTTP requests with automatic v3 signature generation, and a \Server\ for processing payment callbacks. The module adds dedicated classes for merchant configuration (\Merchant\), signature validation (\Validator\, \Signature\), and utility functions for building payment configurations (\Utils\), effectively replacing the previous payment integration with a modern, v3-native architecture.

src/Pay · high confidence

Introduction of new kernel contract interfaces

The \src/Kernel/Contracts\ directory has been populated with a new set of interface definitions that formalize the kernel's core capabilities. These include \AccessToken\ and \RefreshableAccessToken\ for token management, \JsApiTicket\ and \RefreshableJsApiTicket\ for signature configuration, \AccessTokenAwareHttpClient\ for HTTP client integration, \Aes\ for encryption/decryption, \Config\ for configuration access, \Server\ for request handling, and utility interfaces \Arrayable\ and \Jsonable\ for data serialization. This establishes a standardized contract layer for these components.

src/Kernel/Contracts · high confidence

Introduction of specialized exception classes in the Kernel

The Kernel now provides a set of specific exception classes to improve error handling clarity. A base \Exception\ class has been introduced, extending the standard PHP exception. New specific exceptions include \HttpException\, which now carries an optional \ResponseInterface\ object to preserve HTTP response details, as well as dedicated classes for \BadMethodCall\, \BadRequest\, \BadResponse\, \Decrypt\, \InvalidArgumentException\, \InvalidConfig\, \RuntimeException\, and \ServiceNotFoundException\. This allows developers to catch and handle distinct error scenarios more precisely.

src/Kernel/Exceptions · high confidence

New Form and File classes for building multipart requests

Added \src/Kernel/Form/File.php\ and \src/Kernel/Form/Form.php\ to provide a structured way to build multipart form data. The \File\ class offers static methods (\from\, \fromContents\, and the deprecated \withContents\) to create file parts, automatically detecting MIME types and handling temporary files when necessary. The \Form\ class allows users to construct multipart forms from an array of fields and retrieve the resulting headers and body string via \toArray()\ or \toOptions()\, leveraging Symfony's \FormDataPart\.

src/Kernel/Form · high confidence

New contract interfaces for Official Account account and application configuration

Introduced the \Account\ and \Application\ interfaces in the \EasyWeChat\\OfficialAccount\\Contracts\ namespace to define the contract for official account credentials (AppId, Secret, Token, AesKey) and the core application services (Encryptor, Server, HTTP Client, Config, Access Token, Cache, and OAuth). These interfaces standardize how account data and application components are accessed within the Official Account module.

src/OfficialAccount/Contracts · high confidence

New contract interfaces for Open Platform components

Added three new interface definitions to the Open Platform contracts: \Account\ (defining getters for app credentials), \Application\ (defining the main application facade and accessors for services like encryptor, client, and mini-app/official-account factories), and \VerifyTicket\ (defining ticket retrieval and mutation). These interfaces establish the structural contracts for the Open Platform module.

src/OpenPlatform/Contracts · high confidence

New payment contract interfaces for merchant, application, and validation

The payment module now exposes four new interfaces in the \EasyWeChat\\Pay\\Contracts\ namespace to standardize how the application, merchant configuration, and response validation are accessed. \Application\ provides access to the merchant details, configuration, and HTTP client. \Merchant\ defines the contract for retrieving merchant credentials, including private keys, secret keys (V2 and V3), certificates, and platform certificates. \ResponseValidator\ and \Validator\ define contracts for validating HTTP responses and message interfaces respectively, enabling consistent validation logic across the payment integration.

src/Pay/Contracts · high confidence

New support utilities for encryption, data handling, and identity

The \src/Kernel/Support\ directory now includes a suite of new helper classes: \AesCbc\, \AesEcb\, and \AesGcm\ provide standardized AES encryption and decryption capabilities; \Arr\ and \Str\ offer array and string manipulation utilities; \MessageParser\ enables automatic parsing of XML or JSON message content; \Pkcs7\ handles padding and unpadding; \PrivateKey\ and \PublicKey\ manage cryptographic key and certificate loading; \UserAgent\ constructs detailed user-agent strings; and \Xml\ wraps the \TheNorthMemory/xml\ library for XML transformation.

src/Kernel/Support · high confidence

Removals

Removal of legacy Application and Config classes

The legacy \Application\ and \Config\ classes in the \src\ directory have been removed. This eliminates the previous implementation that relied on Pimple for dependency injection and managed service providers, cache, and access tokens, indicating a structural shift in how the library initializes and manages its core services.

src · high confidence

Removal of legacy Server and User service providers

The \ServerServiceProvider\ and \UserServiceProvider\ classes have been removed from the \src/ServiceProviders\ directory. This eliminates the automatic registration of the \encryptor\, \server\, and \user\ services via the Pimple container, meaning users can no longer rely on these specific service definitions being available in the container without manual configuration.

src/ServiceProviders · high confidence

Behavioural changes

HttpClient component refactored with retry, scoping, and PSR-7 support

The HttpClient module has been restructured into a modular system of traits and classes to improve reliability and interoperability. A new RetryableClient trait and AccessTokenExpiredRetryStrategy enable automatic request retries, including intelligent handling of expired access tokens. The ScopingHttpClient allows applying default options to specific URL patterns, while the Response class now supports PSR-7 conversion via toPsr7Response() and provides explicit failure judgment methods (isSuccessful, isFailed). Request building is streamlined through the RequestWithPresets trait, which supports fluent configuration of headers, body parts, and file uploads, and the RequestUtil class standardizes option formatting for JSON, XML, and query parameters.

src/Kernel/HttpClient · high confidence

Official Account module refactored with stable access token support

The Official Account component has been rewritten to support the WeChat stable access token API via a new \use\_stable\_access\_token\ configuration option, which switches the token endpoint from the legacy \cgi-bin/token\ to \cgi-bin/stable\_token\. The module now uses a dedicated \AccessToken\ class that integrates with Symfony's HTTP client and cache components, and introduces a new \Account\ class to manage app credentials. The server-side message handling has been restructured into a new \Server\ class with explicit encryption and signature validation logic, and the \JsApiTicket\ class now extends \AccessToken\ to share caching and HTTP infrastructure.

src/OfficialAccount · high confidence

Project rebrand to EasyWeChat and PHP 8.0+ requirement

The library has been rebranded from 'Wechat' to 'EasyWeChat' (namespace and Composer package changed to w7corp/easywechat), and the minimum supported PHP version has been raised to 8.0.2. The README has been updated to reflect the new branding, installation command (composer require w7corp/easywechat), and usage examples using the new namespace. The project also introduces a formal security policy (SECURITY.md) and a contribution guide (CONTRIBUTING.md).

(repo-wide) · high confidence

Refactored Open Platform core architecture with new service classes

The Open Platform module has been significantly restructured to improve code organization and maintainability. The central \Application\ class now delegates responsibilities to dedicated, single-purpose classes: \Account\ for managing credentials, \ComponentAccessToken\ for handling component token retrieval and caching, \AuthorizerAccessToken\ for authorizer tokens, \VerifyTicket\ for ticket management, \Authorization\ for parsing authorization data, and \Server\ for handling incoming webhook messages and signature validation. This change introduces a more modular design where the main application object acts as a coordinator for these specific services.

src/OpenPlatform · high confidence

Refactored message decryption and response handling traits

The \src/Kernel/Traits\ directory has been restructured to consolidate and improve message handling. A new \DecryptMessage\ trait now provides a unified decryption method that automatically detects and handles both XML and JSON message formats, replacing the previous separate \DecryptXmlMessage\ and \DecryptJsonMessage\ traits (which are now deprecated aliases). Response generation has also been refined: \RespondXmlMessage\ and \RespondJsonMessage\ now enforce stricter validation on message types (e.g., requiring \MsgType\ or \msgtype\) and handle encryption consistently. Additionally, the \HasAttributes\ trait was rewritten to provide a more robust, array-backed attribute storage system with full array-access interface support, and \InteractWithHttpClient\ was updated to support scoped HTTP clients via configuration.

src/Kernel/Traits · high confidence

Test coverage

Added test fixtures for certificate and payment validation; Added test infrastructure and base test case; Added tests for HttpClient components; Added unit tests for Kernel Support utilities; Added unit tests for Kernel Traits; Added unit tests for Kernel components; Added unit tests for MiniApp core components; Added unit tests for Open Platform core components; Added unit tests for the Pay module components; Added unit tests for the Work module core components.

Dependencies

Major dependency overhaul and documentation site initialization

The core library has been significantly upgraded, raising the minimum PHP version to 8.0.2 and replacing legacy extensions (mcrypt) with modern requirements (openssl, fileinfo, simplexml). The dependency stack now relies on Symfony components (versions 5.4 through 8.0) and PSR-7/PSR-18 implementations, while dropping older packages like Pimple and Monolog. Concurrently, a new documentation site has been added under the \docs/\ directory, utilizing VitePress 1.6.3, Tailwind CSS, and pnpm for package management.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 45 → 64 (+18.9)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 97 (-2.7)
  • Architecture 96 → 97 (+1.5)
  • Maturity 47 → 48 (+0.9)
  • Readiness 25 → 67 (+42.0)
  • Security 64 → 83 (+19.9)

Resolved (16)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • LLM evaluation failed
  • No exposed public API
  • No tests found
  • Secret: generic-api-key (docs/.vitepress/config.ts)
  • Secret: generic-api-key (docs/.vitepress/config.ts)
  • Test reliability not included

New (44)

  • Client.request (cognitive 28) (src/Pay/Client.php)
  • Client.request (cyclomatic 21) (src/Pay/Client.php)
  • Dependency hygiene PARTLY measured — Composer dependencies read, no committed lock to grade for currency
  • Duplicated block (10 lines × 2) (src/MiniApp/Application.php)
  • Duplicated block (10 lines × 3) (src/MiniApp/Application.php)
  • Duplicated block (10–12 lines × 2) (src/MiniApp/Application.php)
  • Duplicated block (10–22 lines × 6) (src/OfficialAccount/AccessToken.php)
  • Duplicated block (11 lines × 2) (src/OpenPlatform/Server.php)
  • Duplicated block (11 lines × 2) (src/OpenPlatform/Server.php)
  • Duplicated block (13 lines × 2) (src/OpenWork/Server.php)
  • Duplicated block (14 lines × 2) (src/OpenWork/JsApiTicket.php)
  • Duplicated block (14–15 lines × 2) (src/OpenWork/JsApiTicket.php)
  • Duplicated block (16–25 lines × 2) (src/OpenPlatform/ComponentAccessToken.php)
  • Duplicated block (17 lines × 2) (src/MiniApp/Application.php)
  • Duplicated block (5 lines × 2) (src/Kernel/HttpClient/AccessTokenAwareClient.php)
  • Duplicated block (5 lines × 8) (src/OpenPlatform/Server.php)
  • Duplicated block (6–7 lines × 2) (src/MiniApp/Application.php)
  • Duplicated block (7 lines × 2) (src/OfficialAccount/AccessToken.php)
  • Duplicated block (7 lines × 2) (src/OpenPlatform/VerifyTicket.php)
  • Duplicated block (7 lines × 3) (src/OpenPlatform/ComponentAccessToken.php)
  • …and 24 more

Changes since last survey

  • 4 commits — 3 feature/other, 1 fixes

By area

  • docs/src — 2 commits
  • docs/package.json — 1 commit
  • docs/pnpm-lock.yaml — 1 commit

Notable commits

  • fix: fix: 统一服务端回调消息的签名校验逻辑 (#2990)
  • change: build(deps): bump follow-redirects (#2985)
  • change: build(deps): bump the npm_and_yarn group across 1 directory with 2 updates (#2992)
  • change: 更新官方文档网址,原来网址无法访问 (#2994)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

w7corp/easywechat was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit ba8022698a613e37b10ed1e4db604c5a96af0a63 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-a15879f6f801.