Skip to content
CAI
Software that uses CAICheck a score

zairakai/php-packages/laravel-twitch

71.5

Strong · 22 September 2026

13.9k

lines of production code

PHP

primary language

6

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This is a Laravel package that provides a comprehensive integration with the Twitch platform, handling OAuth 2.0 authentication and full access to the Twitch Helix API. It manages user token storage and validation while offering typed Data Transfer Objects and service traits for interacting with diverse Twitch features such as chat, channel management, bits, and ads. The system also includes robust support for real-time EventSub webhooks, automatically parsing and dispatching events through a typed, event-driven architecture.

Features

Add Twitch OAuth authentication and EventSub webhook handling

Introduces the TwitchAuthController to manage the full Twitch integration lifecycle. Users can now authenticate via OAuth, with the controller handling the authorization redirect, token exchange, and user profile synchronization. Additionally, the controller processes Twitch EventSub webhooks, including signature verification, challenge responses for subscription validation, and dispatching typed DTOs for notifications. It also explicitly handles revocation messages and implements robust error handling to prevent DTO construction failures from crashing the webhook endpoint.

src/Http · high confidence

Expanded Twitch API DTO coverage for Ads, Bits, Channel, and Chat features

This release adds a comprehensive set of new Data Transfer Objects (DTOs) to the \src/Dto\ directory, significantly expanding the library's support for the Twitch Helix API. The changes introduce structured models for managing ad schedules and snoozing (\AdSchedule\, \AdSnooze\, \CommercialResult\), detailed Bits analytics and leaderboards (\BitsLeaderboardEntry\, \Cheermote\, \CustomPowerUp\), and full channel management capabilities including stream schedules, channel information, and editor lists (\Channel\, \Schedule\, \ScheduleSegment\, \ChannelEditor\). It also adds support for Channel Points rewards and redemptions (\CustomReward\, \Redemption\), charity campaigns (\CharityCampaign\, \CharityDonation\), and extensive chat features such as settings, badges, emotes, pinned messages, and shared chat sessions (\ChatSettings\, \Badge\, \Emote\, \PinnedChatMessage\, \SharedChatSession\). Request DTOs are included for creating and updating channel schedules, rewards, and chat settings, ensuring type-safe interactions with these endpoints.

src/Dto · high confidence

Initial configuration for Twitch API, OAuth, and EventSub integration

This change introduces the core configuration files for the Twitch integration package. It adds \config/twitch.php\ to define application credentials, API endpoints, OAuth scopes (covering identity, chat, moderation, and channel management), and EventSub webhook settings. It also includes \config/dev-tools/insights.php\ to configure static analysis rules, specifically excluding certain service classes from cyclomatic complexity checks and adjusting fixers to resolve conflicts with PHPStan and Pint.

config · high confidence

Initial implementation of Twitch API service traits

This release introduces a comprehensive suite of new service traits in the \src/Services/Concerns\ directory, providing programmatic access to the Twitch Helix API. The new code covers Ads, Analytics, Bits, Channel management, Channel Points, Charity, Chat, Conduits, Content Labels, Drops, EventSub, Extensions, Games, Creator Goals, and Guest Star endpoints. Users can now interact with these features through dedicated methods such as \getAdSchedule\, \getExtensionAnalytics\, \getBitsLeaderboard\, \createCustomReward\, and \getEventSubSubscriptions\, enabling full integration with Twitch's broadcaster and extension ecosystems.

src/Services/Concerns · high confidence

Initial release of Laravel Twitch integration package

This change introduces the initial version of the Laravel Twitch package, providing a complete integration for Twitch OAuth authentication and API interaction. It includes a database migration to create the \twitch\_users\ table for storing user profiles and tokens, along with a \TwitchUser\ Eloquent model that handles token validation, scope checking, and secure storage of access/refresh tokens. The package registers a service provider that binds \TwitchApiService\ and \TwitchOAuthService\ into the container, loads configuration, and defines routes for OAuth redirects, callbacks, and webhook endpoints under the \/twitch\ prefix.

(repo-wide) · high confidence

Initial release of Twitch API and OAuth services

This change introduces the core service classes for interacting with the Twitch platform: \TwitchApiService\ and \TwitchOAuthService\. \TwitchApiService\ provides methods for accessing Twitch API endpoints (such as user, stream, and game data) with built-in caching and handles app-level access tokens via client credentials. \TwitchOAuthService\ manages the user authorization flow, including generating authorization URLs, exchanging codes for tokens, refreshing tokens, and revoking or validating existing tokens. These services form the foundation for all Twitch-related functionality in the application.

src/Services · high confidence

Initial release of zairakai/laravel-twitch with full Twitch API integration

This entry marks the initial release of the package, introducing a complete Twitch API integration for Laravel. It includes OAuth 2.0 authentication with token management, a Helix API wrapper for retrieving user, stream, and game data, and EventSub webhook support for real-time event notifications. The package features typed DTOs for all 76 EventSub subscription types with a generic fallback for future types, a badges system for emotes, and an event-driven architecture that dispatches Laravel events for received webhooks. The release also includes comprehensive documentation, CI/CD pipelines, and static analysis tooling.

(repo-wide) · high confidence

Test coverage

Added tests for TwitchUser model and EventSub webhook fixtures

Added a new feature test class for the TwitchUser model, covering scope checking, token validity, user creation, lookup by login or ID, and token updates. Additionally, added a fixture file containing JSON payloads for numerous Twitch EventSub webhook events (such as automod, channel points, chat, and subscriptions) to support testing of webhook parsing and DTO mapping.

tests · high confidence

Dependencies

Update PHP and Laravel version requirements

The package now requires PHP 8.4 and supports Laravel 12 or 13, dropping support for older versions. This change updates the \composer.json\ manifest to reflect the new minimum runtime environment and framework compatibility.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 66 → 71 (+5.9)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 99 (+0.1)
  • Architecture 100 → 97 (-2.6)
  • Maturity 59 → 59 (+0.0)
  • Readiness 50 → 67 (+16.8)
  • Security 98 → 97 (-1.1)

Resolved (14)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (src/Services/Concerns/HasChannelPointsMethods.php)
  • Duplicated block (15 lines × 2) (src/Services/Concerns/HasChannelPointsMethods.php)
  • Duplicated block (15 lines × 2) (src/Services/Concerns/HasDropsMethods.php)
  • Duplicated block (17 lines × 3) (src/Services/Concerns/HasBitsMethods.php)
  • Duplicated block (19 lines × 4) (src/Services/Concerns/HasAnalyticsMethods.php)
  • Duplicated block (9 lines × 2) (src/Services/TwitchApiService.php)
  • High CVE: [GHSA redacted] (composer.lock)
  • No exposed public API
  • Test reliability not included
  • The BATS test suite is documented but does not mention how to run tests or what CI tools are supported. (tests/bats/README.md)
  • early-stage repository — too little history to judge knowledge freshness
  • single-maintainer — knowledge-concentration (bus factor) risk

New (23)

  • Ambiguous naming for distinct data formats. 'getSchedule' returns a structured DTO (Schedule) while 'getScheduleCalendar' returns a raw string (likely an iCal feed or similar). The suffix 'Calendar' implies a specific format, but 'getSchedule' is generic. If 'getSchedule' is the primary method, the calendar variant should perhaps be named 'getScheduleAsCalendar' or similar to explicitly denote the format difference, or the return type should be a specific CalendarDto.
  • Documentation: no architecture or design documentation (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (10 lines × 2) (src/Services/Concerns/HasChatMethods.php)
  • Duplicated block (10 lines × 2) (src/Services/TwitchApiService.php)
  • Duplicated block (10–11 lines × 2) (src/Services/Concerns/HasChannelPointsMethods.php)
  • Duplicated block (11 lines × 3) (src/Services/Concerns/HasChannelMethods.php)
  • Duplicated block (13 lines × 8) (src/Services/Concerns/HasAnalyticsMethods.php)
  • Duplicated block (14 lines × 3) (src/Services/Concerns/HasBitsMethods.php)
  • Duplicated block (17–21 lines × 6) (src/Services/Concerns/HasAnalyticsMethods.php)
  • Duplicated block (18 lines × 2) (src/Services/TwitchApiService.php)
  • Duplicated block (24 lines × 3) (src/Services/TwitchApiService.php)
  • Duplicated block (7 lines × 2) (src/Services/TwitchApiService.php)
  • Duplicated block (7 lines × 3) (src/Services/Concerns/HasExtensionsMethods.php)
  • Duplicated block (8 lines × 3) (src/Services/Concerns/HasAdsMethods.php)
  • High: security finding (details withheld)
  • Members sharing a duplicated core (8 members, 50+ identical tokens) (src/Services/Concerns/HasAnalyticsMethods.php)
  • No dependency advisory monitoring
  • Outdated: laravel/framework
  • …and 3 more

Changes since last survey

  • 56 commits — 32 feature/other, 24 fixes

By area

  • (repo) — 29 commits
  • src/Dto — 14 commits
  • (root) — 4 commits
  • src/Services — 4 commits
  • src/Http — 2 commits
  • tests/Unit — 2 commits
  • config/twitch.php — 1 commit

Notable commits

  • fix: Merge branch 'fix/#3-vendor-patches-from-daemon-validation' into 'main'
  • fix: Merge branch 'fix/#7-nullable-chat-color' into 'develop'
  • fix: Merge branch 'fix/eventsub-notification-resilience' into 'develop'
  • fix: Merge branch 'fix/eventsub-real-payload-crashes' into 'develop'
  • fix: Merge branch 'fix/eventsub-revocation-handling' into 'develop'
  • fix: Merge branch 'fix/eventsub-subscriptions-by-type-double-filter' into 'main'
  • fix: Merge branch 'fix/nullable-reward-prompt' into 'develop'
  • fix: Merge branch 'fix/oauth-service-auth-url-base-uri' into 'main'
  • fix: Merge branch 'fix/twitch-endpoint-audit' into 'develop'
  • fix: chore(laravel-twitch): revert CHANGELOG.md edits
  • fix: fix(laravel-twitch): cast EventSub timestamps to Carbon via a local cast
  • fix: fix(laravel-twitch): correct channel.chat.message fields against official docs
  • fix: fix(laravel-twitch): tighten remaining loosely-typed EventSub fields
  • fix: fix(twitch): #3 report vendor patches found during daemon live validation
  • fix: fix(twitch): #4 fix TwitchOAuthService base_uri dropping /oauth2
  • fix: fix(twitch): #5 fix getEventSubSubscriptionsByType double-filter 400
  • fix: fix(twitch): #7 make chat color nullable on chat events
  • fix: fix(twitch): correct 7 wrong endpoint paths/shapes found via full API audit
  • fix: fix(twitch): don't let a DTO construction failure crash the webhook #18
  • fix: fix(twitch): fix 3 real EventSub payload crashes found via 2026-08-27 stream replay
  • …and 36 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

zairakai/php-packages/laravel-twitch was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit e5006870629638f188e09aed0c82b1f87c3a87cf — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.