Skip to content
CAI
Software that uses CAICheck a score

websockets/ws

47.7

Weak · 1 October 2026

4.8k

lines of production code

JavaScript

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Node.js WebSocket library that provides client and server implementations for real-time, bidirectional communication over TCP. It supports secure connections via SSL/TLS, integrates with Express sessions for authentication, and exposes internal components like parsers and senders for performance benchmarking. The library also offers utilities for streaming data and monitoring server metrics, with a focus on modern ES module compatibility and strict protocol compliance.

Features

Add Express session parsing example

Added a new example demonstrating how to parse Express sessions within WebSocket upgrade requests. The example includes a Node.js server that uses the \express-session\ middleware to validate user sessions before establishing a WebSocket connection, along with a client-side HTML and JavaScript interface for simulating login, logout, and messaging.

examples/express-session-parse · high confidence

Add server-stats example demonstrating memory usage monitoring

A new example named 'server-stats' has been added to the examples directory. It provides a complete demonstration of using the WebSocket library to stream Node.js process memory usage (RSS, Heap total, Heap used, External) from a server to a browser client in real-time.

examples/server-stats · high confidence

Added SSL WebSocket example

A new example file (examples/ssl.js) demonstrates how to run WebSocket connections over SSL/TLS using Node.js's https module. It shows creating an HTTPS server with self-signed certificates, initializing a WebSocketServer on that HTTPS server, and configuring the client to connect via wss:// with rejectUnauthorized set to false to handle the self-signed certificate.

examples · high confidence

Behavioural changes

Library restructured with ES module wrapper and browser shim

The library now provides an ES module wrapper (wrapper.mjs) for modern import syntax and a browser shim (browser.js) that throws an error to prevent usage in browsers, directing users to the native WebSocket object. The main entry point (index.js) has been updated to expose internal classes like Receiver, Sender, and PerMessageDeflate as static properties on the WebSocket object, and the legacy Makefile has been removed in favor of npm scripts.

(repo-wide) · high confidence

Major overhaul of WebSocket internals and API

The library has been significantly refactored to modernize its architecture and improve performance. Key changes include the introduction of a \createWebSocketStream\ utility to wrap WebSockets in Node.js Duplex streams, the addition of \autoPong\ and \closeTimeout\ options for server configuration, and the implementation of a custom \EventTarget\ interface with \addEventListener\ support. Performance is enhanced through optimized buffer handling in \buffer-util\, stricter validation of subprotocols and extensions, and the use of \FastBuffer\ to reduce allocations. Additionally, the library now supports \Blob\ objects for binary data, allows \URL\ instances in the constructor, and drops support for older Node.js versions.

lib · high confidence

Test coverage

Added SSL/TLS test fixtures; Added WebSocket performance benchmarks for parser, sender, and throughput; Initial test suite for the ws library.

Dependencies

Major version 8.22.0 release with ES module support and modernized tooling

The library has been updated to version 8.22.0, introducing an ES module wrapper (\wrapper.mjs\) and explicit package exports to support modern bundlers and import systems. Node.js support is now restricted to version 10.0.0 and above, dropping older runtime compatibility. The development environment has been significantly upgraded, moving to ESLint 10, Prettier 3, Mocha 8, and NYC 15 for testing and linting. Additionally, \bufferutil\ and \utf-8-validate\ are now declared as optional peer dependencies with explicit \allowScripts\ permissions, and example projects for Express session parsing and server stats have been added.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 50 → 48 (-2.3)
  • Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 37 → 37 (+0.0)
  • Architecture 100 → 100 (+0.0)
  • Maturity 54 → 57 (+2.9)
  • Readiness 54 → 41 (-13.4)
  • Security 82 → 85 (+2.2)
  • Performance 85 (new)

Resolved (4)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no licence statement (README.md)
  • Documentation: no usage examples (README.md)
  • Off-boarding risk: anonymized user #1

New (3)

  • Off-boarding risk: anonymized user #1
  • Scanner failed to run — not a clean result
  • WebSocket.constructor (cognitive 22) (lib/websocket.js)

Changes since last survey

  • 2 commits — 2 feature/other, 0 fixes

By area

  • (root) — 1 commit
  • doc/ws.md — 1 commit

Notable commits

  • change: [dist] 8.22.0
  • change: [feature] Introduce the protocols option

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

websockets/ws was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 297202cdae9b0590629821373b3b679c407f3431 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.