Skip to content
CAI
Software that uses CAICheck a score

manonworld/manon

42.4

Weak · 22 September 2026

1.8k

lines of production code

PHP

with JavaScript

6

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a PHP-based backend application built on the Symfony framework, utilizing Domain-Driven Design principles for its core architecture. It provides a RESTful API with HATEOAS-compliant serialization, supports automated testing, and manages infrastructure via Docker containers for MySQL, Redis, and the application itself. The codebase also includes a React front-end with offline capabilities and integrates static analysis tools for code quality.

Features

Added API documentation, testing, and infrastructure services

The backend app now includes configuration for Nelmio API Doc to generate OpenAPI/Swagger documentation for the API, alongside a new .env.test file and phpunit configuration to support automated testing. Additionally, the application registers services for Redis client access, Hateoas serialization, and JMS serialization, while also introducing PHP CodeSniffer for code quality checks and data fixtures for database seeding.

back-end/app · high confidence

Added DDD scaffold and delete commands

Introduced a new \app:create:ddd\ command that generates a Domain-Driven Design directory structure (including Bus, Entity, Controller, Service, and Repository directories) with interactive confirmation prompts, alongside an \app:delete:ddd\ command to remove a domain's directory structure. The implementation includes supporting classes for validation, directory creation/deletion, and user interaction.

back-end/app/src/Command · high confidence

Added DirectoryManager for creating and removing directories

A new DirectoryManager class was added to the Infrastructure/Command layer, providing a wrapper around Symfony's Filesystem component to create and remove directories and files. This introduces a dedicated service for managing directory operations within the application's infrastructure.

back-end/app/src/Infrastructure/Command · high confidence

Added Redis client and custom command implementations

The application now includes a new Redis infrastructure layer, introducing a custom \Client\ class that wraps the Predis library to handle connection, authentication, and command execution. This change adds specific command implementations for \AUTH\ and \XADD\ (stream creation), enabling the system to connect to and interact with a Redis instance using environment variables for configuration.

back-end/app/src/Infrastructure/Redis · medium confidence

Added automated Coverity build capture and analysis artifacts

Added the \cov-int\ directory containing the output of an automated Coverity static analysis run. This includes build logs, timing data, and configuration files generated by the \cov-build\ tool, capturing the state of the \back-end/app/src/\ directory for security and quality analysis.

cov-int · high confidence

Added exception-to-array conversion utility

A new static utility class, ExceptionToArray, was added to the Shared layer. It provides a method to convert PHP Exception objects into structured associative arrays containing status, type, message, file, line, and previous exception details, enabling consistent error serialization.

back-end/app/src/Shared · high confidence

Introduced HATEOAS serialization support

Added a new HATEOAS-based serializer (HateoasSerializer) alongside an updated JMS serializer that now implements a common SerializerInterface. This allows the application to serialize objects into HATEOAS-compliant formats, providing hypermedia links in REST responses.

back-end/app/src/Infrastructure/Serializer · high confidence

Updated Docker infrastructure and build tooling

The project's Docker Compose configuration has been updated to use version 3.3 and switched the database service from MariaDB to MySQL, while also removing the RabbitMQ messaging services. Additionally, new configuration files for Coveralls (.coveralls.yml) and release management (.rmt.yml) have been added, and the Makefile has been expanded with commands for application lifecycle management (install, start, stop, test, domain scaffolding) and release generation.

(repo-wide) · high confidence

Behavioural changes

Added placeholder for Validator infrastructure

A new .gitkeep file was added to the back-end/app/src/Infrastructure/Validator directory, ensuring the directory structure is tracked by version control.

back-end/app/src/Infrastructure/Validator · high confidence

BaseController now supports HATEOAS serialization

The base controller has been updated to include a new \HateoasSerializer\ dependency. This adds support for HATEOAS (Hypermedia as the Engine of Application State) in REST responses, allowing API clients to navigate resources via links embedded in the serialized output.

back-end/app/src/Infrastructure/Controller · medium confidence

Database and cache configuration updates

The environment configuration for the PHP application has been updated to use MySQL instead of MariaDB, with new connection strings defined in env/php/php.mysql.env. Additionally, the previous MariaDB-specific environment file (env/php/php.mariadb.env) has been removed. Several RabbitMQ and Redis environment files have been deleted, and various environment files have had their permissions updated to be executable.

env · medium confidence

Enable service worker for offline support

The front-end application now registers its service worker by default, enabling offline support and faster loading via caching. Previously, the service worker was explicitly unregistered; this change activates the PWA capabilities provided by the React app template.

front-end · high confidence

PHP container updated with new extensions and Redis session support

The PHP Dockerfile was updated to switch from the standard PHP image to the ZTS variant and added the parallel and xdebug extensions. The php.ini was modified to enable the protobuf and parallel extensions, switch session storage to Redis with locking enabled, and configure Xdebug for coverage. Additionally, the container now exposes port 443 for TLS, includes a health check, and changes the default command to start the Symfony server and logger.

back-end/.docker · medium confidence

Refactored TestDomainController to remove dependency on external serializer

The TestDomainController was updated to stop using the external serializer for JSON responses. Instead of passing an array to the serializer, the controller now returns the array directly, simplifying the response handling in the TestDomain area.

back-end/app/src/TestDomain · high confidence

Updated Redis Dockerfile to use official bitnami image

The Redis Dockerfile was replaced to use the official bitnami/redis base image instead of building from source on Alpine Linux. The new Dockerfile copies a custom redis.conf and runs redis-server with that configuration, simplifying the build process and removing the need for the previous docker-entrypoint.sh script.

Redis · high confidence

Test coverage

Added test coverage for the DDD scaffold command; Added test infrastructure and unit tests for core services.

Dependencies

Updated PHP and JavaScript dependencies

The project's PHP dependencies have been updated, including upgrading doctrine/annotations from 1.10.2 to 1.13.1 and doctrine/instantiator from 1.3.0 to 1.4.0, alongside adding new packages such as myclabs/php-enum, predis/predis, and nelmio/api-doc-bundle. The front-end dependencies have also been updated via package-lock.json.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 44 → 42 (-1.3)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 54 → 57 (+3.0)
  • Architecture 100 → 87 (-12.8)
  • Maturity 46 → 42 (-3.5)
  • Readiness 30 → 30 (+0.3)
  • Security 68 → 63 (-4.9)

Resolved (59)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • Critical vulnerability: [GHSA redacted] (front-end/app/package-lock.json)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • High CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • …and 39 more

New (135)

  • Coverage read from a committed report
  • Critical CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • Critical CVE: [GHSA redacted] (front-end/app/package-lock.json)
  • Critical vulnerability: [GHSA redacted] (front-end/app/package-lock.json)
  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (the committed lockfile is in a format this engine cannot resolve)
  • Documentation: no contributor guidance (README.md)
  • Documentation: no usage examples (README.md)
  • …and 115 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

manonworld/manon was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 887732f82ddab53d6c9cb43cc46dc4ef47de77dd — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.