The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Codeweb listing page.
Free & MIT-licensed. Runs entirely on your machine — no account, no server, no telemetry. Reads your code; never executes it.
Website · Gate every PR · See it in action · Install · Use · For agents (MCP: Model Context Protocol) · How it works · Free forever · Changelog
See what your AI edits affect.
Structural checks for AI code changes. codeweb's gate builds the call graph before and after a change, then fails the pull request on three regressions: a new dependency cycle, a new body-confirmed duplication, or an existing non-exported symbol that becomes an orphan with no mapped callers. Gate conditions and limits.
No LLM is in the checks. The gate uses zero model tokens for its static analysis. A passing check does not prove the program works. Analysis can miss dynamic relationships; inspect unresolved results and run the relevant tests. Pure removals pass the structural rules.
The verdict uses the mapped graph, not a model, and costs zero LLM tokens. Exported symbols are exempt
from the diff’s orphan check. Inspect analysis.checks: skipped
checks are not passes, and refresh drops the evidence needed to evaluate duplication.
A green result does not establish complete dependency coverage or behavioral correctness. Pure removals do not count as structural regressions. Put it on your PRs →
The gate needs a map to compare, and that map is worth reading on its own.
codeweb reads your code. It maps supported functions and the calls it can resolve between them. It maps 3,000 symbols in approximately 3 seconds. Static analysis produces the same map from the same code. No LLM is in the mapping loop.
Static extraction can omit unsupported layouts, ambiguous calls, and runtime dispatch; the map is not a completeness guarantee.
Your coding agents query the map instead of using grep. In measured tests, agents that used grep missed more than half of a function's real callers (see the measurements). An incomplete caller list can cause an agent to break code that it did not inspect.
codeweb_impact, codeweb_callers, and codeweb_find_similar.The map also shows relationships that are not visible in one file. These relationships include duplicated logic, dead code, hotspots, and tangled domains.
For a repository with 3,000 symbols, the first map takes approximately 3 seconds. Open
.codeweb/report.html to inspect the map.
912f0f5, captured 2026-07-29. The replay shortens the absolute local path to .codeweb; the displayed values are unchanged.
From a Codeweb source checkout, run the verdict locally; the GitHub Action can run it on every pull request:
The gate builds the graph from the pull request base and from its head, then diffs them. It posts a sticky structural review comment either way, so reviewers see the blast radius without installing anything.
Pin the Action to a release tag, not a moving branch: a floating ref can change your gate's
verdict semantics under you. Pin codeweb-ref to the same tag so the engine is fixed too. The
workflow YAML, the monorepo matrix form, and every input live in
docs/ci-gate.md.
Want the gate hosted — no workflow YAML, cached base graphs, and history across every repo in the org? That is the planned scope of codeweb Teams, the paid half of the boundary. Running it yourself stays free forever.
Each screenshot below shows a generated report for axios (278 symbols, 7 domains). The screenshots are not mockups.
codeweb found 3 real duplications in axios and rejected 12 false positives. Read the case study, or inspect the live map.
Select a function in the live map. The map highlights the function's blast radius and shows the symbols that the change can affect.
Your agents can get the same answer from the codeweb_impact MCP tool before they edit the code.
AxiosError in axios lights up its 31 callers across the domains that depend on it — try it yourself in the living map.
The force-directed map shows the extracted symbols. You can collapse symbols into domains. Search, drag, zoom, or select a node to trace its callers and dependencies.
The Findings tab ranks duplication, highly connected hotspots, and likely dead code. Select a row to inspect the symbol's callers and dependencies.
Treemap — The size of each block shows the file's lines of code. A brighter block contains more duplicated code. Use the bright blocks to identify possible consolidation targets. |
Matrix — The matrix shows coupling between domains. A large off-diagonal cell shows strong coupling. You can merge the domains or add a clear interface between them. |
codeweb works at symbol resolution. It maps functions, classes, methods, and the call and import edges between them. A file-level scanner can show that two modules are similar. codeweb can show that two functions do the same work, identify their callers, and calculate the effect of a merge.
Methodology, raw data, and per-claim receipts:
the evidence ledger. Benchmark your own
repo from a Codeweb source checkout: npm run bench -- <path>/.codeweb/graph.json. CI re-runs the performance budgets on
every PR; breaking a published number fails the build.
codeweb also keeps a local activity tally. From a Codeweb source checkout, run npm run stats to see it:
To evaluate a dependency, point codeweb at a repository that you do not own:
/codeweb https://github.com/owner/repo. codeweb makes a read-only clone, maps the clone, and
adds an adoption review. codeweb does not execute the target code.
Free & MIT-licensed. Runs entirely on your machine — no account, no server, no telemetry. Reads your code; never executes it.
node_modules
directory.web-tree-sitter wasm grammar improves extraction. codeweb does not require it.npm audit signatures to verify a release.Using Claude Code? Install the plugin to add the /codeweb command, automatic pre-edit
impact cards, and all 28 tools:
Restart Claude Code to register the /codeweb command, agents, and skill.
Choose your MCP client: The setup page provides one recipe for Claude Code, Cursor, Windsurf, Gemini CLI, or Codex. Print a recipe and check local setup from your project:
Setup prints configuration without replacing files. Doctor checks the local server and graph;
a successful local check does not prove an editor connection. Restart your client, ask your
agents to run codeweb_callers, and check a returned source location.
Map a repository without an AI agent: Run one command from your project directory:
For a temporary evaluation, use the npx command. It creates the map without a permanent
installation.
Run the engine from a clone:
docs/cli.md lists each executable, flag, and exit code.
VS Code: editor/vscode-codeweb shows an
N callers · blast M lens above each mapped symbol. Select the lens to open the report.
Each link lands on full docs, flags, and examples in the reference.
diff verdict ·
the PR gate ·
the capability suiteoptimize ·
hotspots ·
campaign ·
trendAvailable flags include --depth module|symbol|auto, --engine hybrid|read|tools,
--focus <glob>, --mode internal|external, and --open. See commands/codeweb.md for details.
codeweb writes all outputs to <target>/.codeweb/. Agents and other tools can read graph.json.
You can open report.html. codeweb also creates Markdown versions.
See the description of each output file.
scripts/mcp-server.mjs is a zero-dependency Model Context Protocol (MCP) stdio server. It gives
MCP clients access to 28 tools. The tools help the client orient, read the structure,
check before writing, gate an edit, and plan cleanup.
The September 14 packaged assessment exercised the baseline loop with Codex CLI 0.154.0; it did not certify every tool in every client. Claude runtime compatibility and other clients were not tested in that assessment. See the recorded scope.
The plugin registers the server automatically. To register the standalone server, run:
Requires Codeweb 0.15.0 or later. Use the installed MCP server, or register a source checkout using its absolute path as shown in the reference.
The loop an agent runs:
codeweb_brief (or codeweb_find when no symbol name is known).codeweb_refresh {baseline:true} once to capture fresh source.
Ask codeweb_explain, then codeweb_context, codeweb_impact, or codeweb_dependents
about the symbol before changing it.codeweb_diff {before:"baseline",refresh:true}.baseline:true replaces the original.
Ordinary and automatic refreshes preserve it. Start a new baseline for the next task.Known unsupported same-line JS/TS declarations produce status: "inconclusive" and
ok:false instead of a clean gate. Inspect the diagnostic locations and callers in source.
The detector covers known layouts; no diagnostic does not prove complete extraction.
Read analysis.checks: a skipped check is not a pass. Refresh drops overlap evidence, so
this loop does not evaluate duplication; structural green does not prove behavioral
correctness. Run the project's tests too. If the baseline is missing, edited source cannot
reconstruct it — recover the pre-edit source before beginning again.
For npm v0.14.0, use the snapshot quickstart. For the unreleased checkout, try the tiny cycle → repair → green walkthrough. Clients that hide the server's built-in instructions can paste the rules snippet instead.
The server includes these agent-specific features:
graph argument: The server finds the nearest map when you omit graph. If no map
exists, the error directs the agent to codeweb_map.codeweb_refresh — on the orient tools and on every spawned advisor answer.All 28 tools, grouped and explained →
For JavaScript, TypeScript, Python, Rust, Go, Java, C#, Ruby, PHP, Kotlin, Swift, C, and C++, codeweb uses a deterministic Node pipeline by default. One command creates the map. No LLM is in the pipeline, and the same input produces the same bytes.
The map pipeline has the four stages in the following diagram. scripts/run.mjs also creates
optimize.md after overlap analysis and before report rendering.
extract-symbols.mjs) parses each source file into atomic nodes such as functions,
classes, and methods. It also records call and import edges. If a bare call can refer to more
than one definition, codeweb omits the edge instead of guessing. Per-file caching makes
extraction incremental and byte-identical to a full rebuild. An imported .json file enters
the map as a file-level node without being parsed. An unreferenced .json file stays out of the
map, which prevents lock-file noise.cluster3.mjs) removes genuine utility hubs and groups the remaining nodes into
directory-anchored semantic domains.overlap.mjs) detects duplicated logic and parallel implementations. It compares
each candidate with the actual function bodies by using token-shingle similarity. This check
prevents name coincidences from becoming findings. A structural pass over
identifier-normalized skeletons also finds renamed Type-2 clones
(find-similar --structural).build-report.mjs) converts graph.json into the self-contained report.html and
report.md files.For a language that the extractor cannot parse, codeweb uses the agent path.
codeweb-dissector agents extract nodes and edges for each subsystem. codeweb-domain-mapper
then assigns domains and overlaps.
Both paths produce the same graph.json schema. In external mode, each path also adds an
adoption verdict.
Versus a language server (LSP): an LSP answers one hop on demand — definitions, direct references — inside an editor session. codeweb builds one deterministic whole-graph artifact: transitive impact, duplication with body evidence, dead code, and domain coupling.
Agents query that artifact over MCP, and CI diffs it to gate a PR. The two compose — codeweb replaces the grep loop, not your language server.
Choose a reading path in the documentation index, which also explains repository ownership. The component map details the engine.
scripts/grammars/PROVENANCE.md.Recent releases added the agent-intelligence suite (hotspots, campaign, reading-order, Type-2 clone detection, and suppression memory), a live interactive demo, Go and Rust on the fast path, duplication trend data, and the one-command CI regression gate with a GitHub Action. codeweb currently provides 28 tools.
The maintenance commands below require a Codeweb source checkout.
codeweb follows Semantic Versioning. It records changes in
CHANGELOG.md, which uses the
Keep a Changelog format. Each capability, benchmark, and fix ships
in a tagged GitHub release.
package.json is the source of truth for the version.
scripts/mcp-server.mjs is the source of truth for the MCP tool count. The release tools derive
and verify the other values:
check-consistency runs in CI. It gates version strings on every surface, recognized prose patterns for
the tool and language counts, the CHANGELOG entry for the current version, and every evidence
file the ledger cites.
Built by GhostlyGawd. AI agents helped write much of the code.
The commit co-author trailers identify those contributions. Open an issue for questions or
problems. Use SECURITY.md to report a security issue.
Stay current: codeweb does not contact an update service. To receive release notifications, select Watch → Custom → Releases on GitHub.
The rule, ratified in CHARTER.md: anything that runs on one laptop against one
repo is free forever; money buys hosting, multi-repo aggregation, and human attention.
Everything in this repository is that free half — the map, the MCP tools, the hooks, the report, the CLI, the self-hosted gate Action, and every language codeweb learns. MIT, no accounts, no telemetry, no license keys. Nothing here moves behind a payment later.
The planned paid half is a separate hosted service, codeweb Teams: the gate run for you, and history held across every repo in an org. Billing lives only in that service, so a payment problem degrades the hosted tier and never breaks your local tooling or your CI.
Hosted availability is not established by this repository’s local checks. The pricing page retains the sign-up doorway.
Read the full contract on the boundary page, and the planned Teams price on the pricing page.
Sponsoring supports the project. Sponsorship also provides advertising. Top sponsors can put their logo at the top of this README, and each sponsor can join the supporters list. See the support page for details.
Running codeweb at an organization and need help? Send email through the GitHub profile.
You can send codeweb outputs to refactor-cleaner, codebase-onboarding, or code-tour if you
have those tools. codeweb does not require them.
For a useful next step, apply the highest-ranked ready merge from optimize.md. Then run
codeweb again and compare the findings count.