Skip to content
CAI
Software that uses CAICheck a score

zotonic/z_stdlib

58.3

Adequate · 2 October 2026

13.5k

lines of production code

Erlang

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

zotonic\_stdlib is a standalone Erlang utility library providing core data processing and web asset management functions. It offers capabilities for sanitizing HTML and CSS, minifying JavaScript and CSS, and handling URL metadata extraction and IP reputation checks. The system also includes utilities for string normalization, date formatting, and email validation, with a strong emphasis on security and robustness through comprehensive testing.

Features

Initial release of zotonic\_stdlib as a standalone Erlang library

The Zotonic standard library is now available as a standalone project (\zotonic\_stdlib\) for use in any Erlang application. It includes modules for data conversion (\z\_convert\), CSS parsing and minification (\z\_css\, \z\_cssmin\), date formatting (\z\_dateformat\), email validation (\z\_email\_utils\), HTML sanitization (\z\_html\), IP address handling (\z\_ip\_address\), JavaScript minification (\z\_jsmin\), string manipulation (\z\_string\), SVG sanitization (\z\_svg\), temporary files (\z\_tempfile\), UBF encoding (\z\_ubf\), and URL operations (\z\_url\, \z\_url\_fetch\, \z\_url\_metadata\). The library requires Erlang/OTP 22 or later and is distributed via Hex and GitHub.

(repo-wide) · high confidence

New URL metadata record definition

Added the \url\_metadata\ record definition in \include/z\_url\_metadata.hrl\, specifying the structure for data returned by the \z\_url\_metadata:fetch/1\ function. This record includes fields for the final URL, content type and length, metadata lists, HTTP headers, parsed link headers, JSON-LD data, and partial response data.

include · high confidence

Behavioural changes

Added word normalization mappings for Ukrainian city names

A new CSV mapping file has been added to the private resources to support the \z\_string:normalize/1\ function. This file defines canonical forms for several Ukrainian cities (Kyiv, Odesa, Kharkiv, and Lviv), allowing the system to normalize various historical, transliterated, and Cyrillic spellings into their current official English names.

priv · high confidence

Major overhaul of HTML, CSS, and URL sanitization and metadata extraction

This release significantly strengthens security and robustness across the core utility modules. The HTML sanitizer (z\_html) now supports SVG sanitization, recursive sanitization of maps and lists, and stricter handling of URI properties and link protocols (defaulting to https). A new strict CSS parser and sanitizer (z\_css) replaces the previous logic, rejecting invalid CSS constructs and stripping external URI references. URL handling (z\_url, z\_url\_fetch, z\_url\_metadata) has been hardened with stricter filtering, normalization, and improved metadata extraction (including support for YouTube and Slack metadata). Additionally, new modules z\_email\_dnsbl for IP reputation checking and z\_cssmin/z\_jsmin for asset minification have been added, while various fixes address crashes in escaping, UTF-8 handling, and date formatting.

src · high confidence

Test coverage

Added comprehensive test suites for core utility modules

Added EUnit and PropEr test coverage for the \z\_convert\, \z\_css\, \z\_cssmin\, \z\_dateformat\, \z\_email\_utils\, \z\_filelib\, \z\_html\_charref\, \z\_html\_parse\, \z\_html\, \z\_ip\_address\, \z\_jsmin\, \z\_string\, and \z\_string\_sanitize\_utf8\ modules. These tests validate data conversion, CSS sanitization and minification, date formatting, email extraction, OS-specific filename escaping, HTML parsing and sanitization, IP address classification, JavaScript minification, and string normalization/UTF-8 handling.

test · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 58 → 58 (+0.1)
  • Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 91 → 91 (+0.0)
  • Architecture 100 → 100 (+0.0)
  • Maturity 34 → 34 (+0.5)
  • Readiness 64 → 62 (-2.4)
  • Security 90 → 96 (+5.7)
  • Event Sourcing 100 → 100 (+0.0)

Resolved (8)

  • Coverage not measured — no coverage collector is wired up
  • Documentation: no usage examples (README.md)
  • Hotspot: src/z_convert.erl (src/z_convert.erl)
  • Hotspot: src/z_css.erl (src/z_css.erl)
  • Hotspot: src/z_html.erl (src/z_html.erl)
  • Hotspot: src/z_html_parse.erl (src/z_html_parse.erl)
  • Medium: security finding (details withheld)
  • Off-boarding risk: anonymized user #1

New (3)

  • Documentation: no project overview (README.md)
  • Medium CVE: EEF-[CVE redacted] (rebar.lock)
  • Off-boarding risk: anonymized user #1

Changes since last survey

  • 4 commits — 4 feature/other, 0 fixes

By area

  • (root) — 2 commits
  • src/z_ip_address.erl — 1 commit
  • src/z_url_fetch.erl — 1 commit

Notable commits

  • change: Add z_ip_address:is_public check function (#131)
  • change: OTP29 compat (#128)
  • change: Upgrade deps (#129)
  • change: z_url_fetch: add option to not autoredirect (#130)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

zotonic/z_stdlib was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 2 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 3b72839140ffc5342b333ecbf488879872651cab — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.