Skip to content
CAI
Software that uses CAICheck a score

WhiskeySockets/Baileys

55.2

Adequate · 2 October 2026

44.2k

lines of production code

TypeScript

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a TypeScript library for interacting with the WhatsApp Web API, providing a modular socket implementation for sending and receiving messages, managing groups, and handling user synchronization. It supports the latest multi-device protocol, including LID-based identity mapping, Signal encryption, and binary protocol encoding, while automating version updates and protobuf generation. The codebase includes comprehensive utilities for authentication, state management, and media handling, backed by extensive unit and end-to-end tests to ensure reliability.

How it got here

2020–2021 — V3 architecture migration

11 changes.

This period focused on migrating the codebase to the V3 architecture by removing legacy WhatsApp Web implementations and binary encoding modules. The work involved restructuring the socket layer into a modular design, introducing comprehensive TypeScript type definitions, and establishing new utilities for authentication and protocol handling.

2022–2026 — LID support and protocol expansion

13 changes.

This period focused on implementing core infrastructure for Link ID (LID) mapping and Signal protocol handling, alongside adding support for the USync and Web Activity Metrics protocols. The work included migrating Signal group cryptography to TypeScript and introducing automated tools for extracting and updating WhatsApp Web protobuf definitions. Comprehensive test suites were also developed to validate messaging, group operations, and connection stability.

Features

Add proto-extract script to generate WhatsApp Web protobuf definitions

A new \proto-extract\ tool has been added to automatically fetch and parse the latest WhatsApp Web JavaScript source to generate a predictable \WAProto.proto\ file. This script dynamically discovers protocol buffer modules from the web client without relying on hardcoded module lists, ensuring the generated definitions stay in sync with WhatsApp's current version (e.g., 2.3000.x).

proto-extract · high confidence

Automated WhatsApp Web version update script

A new \scripts/update-version.ts\ script has been added to automate the process of updating the WhatsApp Web protocol version across the codebase. When executed, the script fetches the latest version from web.whatsapp.com and updates the version definitions in \src/Defaults/baileys-version.json\, \src/Defaults/index.ts\, and \src/Utils/generics.ts\. It also supports CI integration by writing update status and version details to the \GITHUB\_OUTPUT\ environment file.

scripts · high confidence

Comprehensive type definitions for WhatsApp protocol features

This change introduces a complete set of TypeScript type definitions for the WhatsApp protocol, covering authentication, messaging, contacts, groups, labels, business profiles, calls, and state management. It includes types for LID (Line ID) mappings, signal key stores, message retries, and various sync actions, enabling better type safety and IDE support for developers using the library.

src/Types · high confidence

Initial USync protocol support for contacts, devices, status, disappearing mode, and usernames

This change introduces the foundational USync protocol implementations in the \src/WAUSync/Protocols\ directory, enabling the library to query and parse specific WhatsApp user data types. New protocol classes handle contact lookups (supporting phone, username, and LID identifiers), device list synchronization, status updates, disappearing message settings, and username retrieval. Additionally, a bot profile protocol is added to fetch bot metadata and commands, while a dedicated LID protocol supports Link ID-based queries. These components collectively allow the application to perform structured synchronization of user profile and chat settings via the new USync mechanism.

src/WAUSync/Protocols · high confidence

Initial support for WhatsApp USync protocol queries

The WAUSync module now provides the core infrastructure for querying WhatsApp's USync service. This includes the USyncQuery builder to construct requests with various protocols (device, contact, status, disappearing mode, bot profile, LID, and username) and the USyncUser model to define query targets. The implementation handles parsing binary response nodes into structured result lists, enabling the application to fetch and process user synchronization data.

src/WAUSync · high confidence

Introduction of modular utility functions for authentication, messaging, and state management

The library now exposes a comprehensive set of utility functions in the \src/Utils\ directory to handle core WhatsApp protocol operations. This includes \auth-utils\ for managing Signal key stores with caching and transaction capabilities, \chat-utils\ for encoding/decoding app state patches and managing LTHash states, and \business.ts\ for parsing and creating product catalog nodes. Additionally, \crypto.ts\ provides low-level encryption helpers, \decode-wa-message.ts\ handles message stanza decoding and LID mapping, and \event-buffer.ts\ implements a batching mechanism for efficient event processing.

src/Utils · high confidence

New LID mapping store and Signal repository implementation

This change introduces the core Signal protocol handling and Phone Number-to-LID (LID) mapping infrastructure. The new \libsignal.ts\ file implements the \SignalRepositoryWithLIDStore\, providing methods for encrypting and decrypting both individual and group messages, handling session creation, and detecting identity key changes. It integrates with the new \lid-mapping.ts\ module, which manages the bidirectional mapping between phone numbers and LIDs using a transactional key store and an LRU cache with a 7-day TTL. This foundation enables the system to correctly route and process messages for users identified by LIDs, including support for hosted devices.

src/Signal · high confidence

New WABinary module for WhatsApp protocol encoding and decoding

A new WABinary module has been introduced to handle the encoding and decoding of WhatsApp's binary XML protocol. This includes dedicated files for constants (defining tags like INTEROP\_JID, FB\_JID, and AD\_JID), encoding (encode.ts), and decoding (decode.ts) logic. The module also provides JID utilities (jid-utils.ts) supporting various server types such as 'lid', 'hosted', and 'hosted.lid', along with generic utilities (generic-utils.ts) for navigating binary nodes. This change establishes the foundational binary communication layer for the application.

src/WABinary · high confidence

New Web Activity Metrics (WAM) binary encoding module

The \src/WAM\ directory now contains a new implementation for encoding Web Activity Metrics into a binary format. This includes a \BinaryInfo\ class to hold protocol state, a comprehensive \constants.ts\ file defining event schemas (such as Meta Verified interactions and catalog requests), and an \encode.ts\ module that serializes these events and global attributes into a binary buffer. The module is exported via \index.ts\, providing the core logic for WAM data serialization.

src/WAM · high confidence

New WhatsApp Web example with multi-file auth and retry caching

The repository now includes a new example client (Example/example.ts) that demonstrates the updated API. This example uses multi-file authentication state via useMultiFileAuthState and integrates a NodeCache instance for message retry counters to prevent decryption loops across restarts. It connects to the latest WhatsApp Web version, handles connection updates including automatic reconnection and pairing codes, and processes events such as message upserts, history sync, and label associations.

Example · high confidence

Removals

Removal of legacy WhatsApp Web (WAClient) implementation

The legacy WhatsApp Web client implementation (WAClient) has been removed from the repository. This includes the deletion of the core \WhatsAppWeb.js\ module and its associated components (\WhatsAppWeb.Recv.js\, \WhatsAppWeb.Send.js\, \WhatsAppWeb.Session.js\, and \WhatsAppWeb.Utils.js\), as well as the legacy \test.js\ example. This cleanup prepares the codebase for the V3 architecture, which relies on the new multi-device protocol.

(repo-wide) · high confidence

WhatsApp binary encoding module removed

The \binary\_coding\ module, which provided JavaScript-based encoding and decoding for WhatsApp binary protocols (including message structures, token dictionaries, and protobuf definitions), has been deleted. This removes the capability to serialize and deserialize WhatsApp chat messages and metadata within this specific component.

_binary\coding · high confidence

API

Standardized public API entry point with named and default exports

The library now exposes a unified entry point in src/index.ts that re-exports core components (Utils, Types, Defaults, WABinary, WAM, WAUSync) and the protocol definitions. Users can import makeWASocket as a named export or as the default export, and the WASocket type is now explicitly available for type checking, simplifying integration and ensuring consistent access to the socket factory and related utilities.

src · high confidence

Architecture

Refactored socket architecture with modular layers and dedicated WebSocket client

The socket implementation has been restructured into a modular, layered architecture to improve maintainability and separation of concerns. A new \Socket/Client\ module introduces an \AbstractSocketClient\ interface and a concrete \WebSocketClient\ implementation, decoupling the raw transport layer from the application logic. The main socket entry point (\makeWASocket\) now chains through specialized modules—\newsletter\, \groups\, \communities\, \business\, \chats\, and \messages\—each adding specific capabilities (e.g., business profile updates, community management, newsletter interactions) on top of the core messaging layer. This refactoring replaces the previous monolithic structure with a clear dependency chain, enhancing code organization without changing the external API.

src/Socket · high confidence

Behavioural changes

Initialize default configuration and version constants

The library now defines its core defaults in a new \src/Defaults\ module, establishing the WhatsApp protocol version as 2.3000.1043857760. This update sets the default browser identity to macOS Chrome, configures the WebSocket connection timeout to 20 seconds and keep-alive interval to 30 seconds, and enables full history synchronization by default. It also introduces specific constants for media path mapping, cache TTLs, and pre-key counts to standardize connection and messaging behavior.

src/Defaults · high confidence

Optimized WAProto generation with ESM and BigInt-based Long handling

The WAProto module has been updated to generate optimized static JavaScript and TypeScript definitions using ESM modules. This change significantly reduces bundle size and improves performance by replacing the previous Long library implementation with native BigInt conversions for handling large integer fields, resulting in faster serialization and deserialization of protocol buffer messages.

WAProto · high confidence

Fixes

Migrate Signal Group cryptography to TypeScript

The Signal Group module has been rewritten in TypeScript, replacing the previous implementation with new files for sender-key state management, group session building, and message encryption/decryption. This migration includes updated Protobuf deserialization logic to handle string and Uint8Array formats for signing keys, improved type safety for key handling, and hardened deserialization to prevent errors when processing invalid or null values in group messages.

src/Signal/Group · high confidence

Test coverage

Added test coverage for Socket chat, group, and identity change handling; Added tests for BigInt-based Long field serialization and validation; Added tests for connection deadlock and reconnection sync behavior; Added unit tests for LIDMappingStore and SenderKeyState regression; Added unit tests for app-state sync resilience and utility functions; New end-to-end test suite for messaging, groups, and media.

Dependencies

Add proto-extract utility and update project dependencies

This change introduces a new \proto-extract\ sub-project (a WhatsApp Web protobuf extractor) with its own \package.json\ and lockfiles, adding dependencies like \acorn\, \request\, and \ajv\. It also updates the main project's \yarn.lock\ to resolve newer versions of build tools (e.g., \@babel/core\ 7.28.0) and removes several legacy or unused \node\_modules\ packages, including \protobufjs\ (v6.8.9), \curve25519-js\, \futoin-hkdf\, and \qrcode-terminal\, reflecting a cleanup of the dependency tree.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 54 → 55 (+1.6)
  • Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 69 → 61 (-7.9)
  • Architecture 52 → 52 (+0.5)
  • Maturity 58 → 58 (-0.1)
  • Readiness 52 → 56 (+3.2)
  • Security 54 → 60 (+6.3)
  • Performance 60 (new)

Resolved (6)

  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
  • Documentation: no installation or build instructions (README.md)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • Medium CVE: [GHSA redacted] (yarn.lock)
  • Off-boarding risk: anonymized user #1

New (120)

  • (anonymous) (cognitive 147) (proto-extract/index.js)
  • (anonymous) (cyclomatic 77) (proto-extract/index.js)
  • Banned license: libsignal
  • FileTooLong: Socket/chats.ts (src/Socket/chats.ts)
  • FileTooLong: Socket/messages-recv.ts (src/Socket/messages-recv.ts)
  • FileTooLong: Socket/messages-send.ts (src/Socket/messages-send.ts)
  • FileTooLong: Socket/socket.ts (src/Socket/socket.ts)
  • FileTooLong: Utils/chat-utils.ts (src/Utils/chat-utils.ts)
  • FileTooLong: Utils/messages-media.ts (src/Utils/messages-media.ts)
  • FileTooLong: Utils/messages.ts (src/Utils/messages.ts)
  • FileTooLong: Utils/process-message.ts (src/Utils/process-message.ts)
  • FunctionTooLong: business.makeBusinessSocket (src/Socket/business.ts)
  • FunctionTooLong: chat-utils.chatModificationToAppPatch (src/Utils/chat-utils.ts)
  • FunctionTooLong: chat-utils.processSyncAction (src/Utils/chat-utils.ts)
  • FunctionTooLong: chats.makeChatsSocket (src/Socket/chats.ts)
  • FunctionTooLong: communities.makeCommunitiesSocket (src/Socket/communities.ts)
  • FunctionTooLong: event-buffer.append (src/Utils/event-buffer.ts)
  • FunctionTooLong: event-buffer.makeEventBuffer (src/Utils/event-buffer.ts)
  • FunctionTooLong: groups.makeGroupsSocket (src/Socket/groups.ts)
  • FunctionTooLong: libsignal.makeLibSignalRepository (src/Signal/libsignal.ts)
  • …and 100 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

WhiskeySockets/Baileys was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 2 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 0af2386292907f7d9742d8d41f830d8c48208fa1 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.