Skip to content
CAI
Software that uses CAICheck a score

webmozarts/assert

69.4

Adequate · 26 September 2026

7.6k

lines of production code

PHP

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Added code generators for mixin and static analysis test files

The \bin\ directory now includes PHP scripts (\generate.php\, \MixinGenerator.php\, \StaticAnalysisNonReturnGenerator.php\) that automatically generate the \Mixin\ trait, the \HasAssert\ class, and static analysis test files. These generators reflect the current state of the \Assert\ class, ensuring that the generated code stays in sync with the library's assertion methods, including support for \allNullOr\ variants and handling of Psalm-specific type annotations.

bin · high confidence

Added project infrastructure and tooling configuration files

The repository now includes essential project configuration files to standardize development and tooling. An \.editorconfig\ file enforces consistent coding styles (UTF-8, LF line endings, 4-space indentation). A \.gitattributes\ file is added to exclude development artifacts (like /tests, /tools, /ci) from distribution exports. A \.php-cs-fixer.php\ file configures PHP-CS-Fixer with PSR-2 and Symfony rules. Additionally, \phpunit.xml.dist\ and \psalm.xml\ are introduced to configure the PHPUnit test runner and Psalm static analysis tool respectively.

(repo-wide) · high confidence

Introduced static assertion methods and Psalm plugin for improved type safety

The library now provides static assertion methods that return the validated value, enabling direct usage in expressions and assignments. A new \HasAssert\ class and \PsalmPlugin\ have been added to provide comprehensive Psalm type assertions for all assertion methods, significantly improving static analysis and type inference for users of the library.

src · high confidence

Test coverage

Added automated tests for project code consistency and static analysis; Expanded static analysis test coverage for Assert methods.

Dependencies

Locks tool dependencies for PHP 8.2+

The project's development tooling (php-cs-fixer, phpunit, psalm, and roave/backward-compatibility-check) has been restructured into separate subdirectories under /tools, each with its own composer.json and composer.lock. All tool environments now require PHP 8.2 or higher, and their respective dev dependencies (such as friendsofphp/php-cs-fixer, phpunit/phpunit, vimeo/psalm, and roave/backward-compatibility-check) are locked to specific versions in their local lock files.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 48 → 69 (+21.1)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 97 → 98 (+1.5)
  • Architecture 94 → 100 (+5.9)
  • Maturity 57 → 57 (+0.0)
  • Readiness 25 → 62 (+36.3)
  • Security 68 → 98 (+30.3)

Resolved (11)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No exposed public API
  • No tests found
  • Test reliability not included

New (31)

  • ClassTooLong: Assert (src/Assert.php)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (9 lines × 2) (src/Assert.php)
  • FileTooLong: src/Assert.php (src/Assert.php)
  • FileTooLong: src/Mixin.php (src/Mixin.php)
  • High CVE: [GHSA redacted] (tools/roave-bc-check/composer.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium CVE: [GHSA redacted] (tools/php-cs-fixer/composer.lock)
  • No assertions: testIsInReadme (tests/ProjectCodeTest.php)
  • No dependency advisory monitoring
  • Skipped (documented): testAllArray (tests/AssertTest.php)
  • Skipped (documented): testAllNullOrArray (tests/AssertTest.php)
  • Skipped (documented): testAllTraversable (tests/AssertTest.php)
  • Skipped (documented): testAssert (tests/AssertTest.php)
  • …and 11 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

webmozarts/assert was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 2ccb7c2e821038c03a3e6e1700c570c158c55f70 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-a15879f6f801.