git history · fair attribution · clean code

Fair Clean Code analysis
for every developer in your repo

CleanLens replays your Git history and compares every file before and after each commit, so every Clean Code violation is charged to the developer who actually introduced it. Each developer then gets a fair quality score that doesn't depend on how much code they wrote.

Runs entirely on your machineNo sign-inJS · TS · React · Python
VS Code · Quick Open
>ext install cleanlens.cleanlens
CleanLens
cleanlens.cleanlens · v0.2.4
LintersSCM ProvidersVisualization
Install from Marketplace

Or inside VS Code: press Ctrl/⌘ + P and paste the command.

the vibe coding problem

Vibe coding ships fast…
and leaves disasters behind

AI assistants generate hundreds of lines in minutes, and rarely does anyone review every one. API keys leak into Git, errors vanish into empty catch blocks, functions bloat and repeat. CleanLens checks every line, tells you the exact file and line, and one click takes you there.

  1. 1

    Catches the dangerous issues

    Keys and passwords written into code, swallowed errors, and operations with no error handling.

  2. 2

    Checks Clean Code too

    Long, complex functions, duplication, unused code and vague names.

  3. 3

    Then points to the line

    Every finding comes with its file, line number and severity, and one click opens the file on that exact line.

Findings4

Just a few examples of what CleanLens can detect.

Click a finding to jump to its line

src/config.jsLn 12
1import { S3Client } from "@aws-sdk/client-s3";
2
3export const config = {
4 region: "eu-central-1",
5 retries: 3,
6 timeoutMs: 8000,
7};
8
9// generated: connect to storage
10export const s3 = new S3Client({
11 region: config.region,
12 credentials: { accessKeyId: "AKIAIOSFODNN7EXAMPLE",
13 secretAccessKey: "wJalrXUtnFEMI/K7MDENG" },
14});
forbidHardcodedSecrets · AWS key hardcoded in source
the problem

Fixing one character shouldn't make you own the whole file

Tools like git blame and ordinary linters charge problems to whoever last edited the line or file. The result is unfair reports: fix a typo in an old file and you inherit all its problems, while the person who wrote them disappears from the picture.

src/orders.jscommit a41f9c · Layla
1import { db } from './lib'
2export async function handle(req, a, b, c, d, e, f) {maxParameters
3 const data1 = await db.query(req.q)clearNames
4 try { save(data1) } catch (err) {}emptyCatch
5 console.log('debug', data1)debugStatement
6 // ...
7 return formatTotal(data1) // was: fromatTotalchanged
8}
git blame / last-touch
4 violations

Charged to Layla, even though she only fixed a typo on line 7.

CleanLens
0 new

All four violations existed before the commit, so they are classified as existing and charged to no one. Line 7 is clean.

Whitespace-only edits are ignored, and code moved between files is tracked.
introduced added by this commit, charged to its authorfixed removed, credited to the authorexisting already there, not chargedexcluded excluded filesunattributed could not be attributed
the pipeline

Five stages from commit to score

Keep scrolling. The lens in the background walks the commit history the same way the analysis does.

01

Git checks and rules

Confirms the folder is a Git repository with commits, then reads .clean-code-tracker.json or uses a built-in preset.

02

Scan

14 Clean Code rules for JS/TS/JSX/TSX using the AST, and for Python using heuristics, plus duplicate-code detection.

03

Replay the history

Walks the newest 500 commits (configurable). For every changed file it runs diff -w -M -C and analyses the version before and after the commit.

04

Classify and attribute

A stable fingerprint per violation (rule + path + symbol + context) recognises it even when its line number moves. It is charged to the author only if it appears on lines they changed or in a function they modified.

05

Score and cache

Each developer gets a score across three categories. Results are cached per commit, so the next run only analyses new commits.

fair scoring

Quality and contribution volume are two different things

The score measures the density of violations a developer introduced per 1,000 lines they wrote. Writing more code doesn't raise or lower it, and contribution is shown separately next to it.

score = 100 · e−adjustedDensity / scale
Structure
45%
Duplication
30%
Hygiene
25%
  • Bayesian shrinkage: developers with little code are pulled toward the project average, so a small sample can't look perfect or disastrous.
  • Ranking threshold: under 1,000 analysed lines? The developer is shown but not ranked.
  • No code, no score: a developer with no analysed code shows «—», not 100.
  • Every weight is configurable from the config file or VS Code settings.

Developer card

Example from the docs
73
Duplication 88Structure 72Hygiene 78Confidence: Reliable
New violations39
Violations fixed12
Existing51
Analysed lines3,140
Contribution42%
Density / KLOC37.58
14 rules

14 rules, all under your control

Turn each one on or off and set its severity (low / medium / high / critical) and threshold. A shared file for the team in the repo, and a local file for your personal overrides.

maxFunctionLines

Function length

A function longer than the limit.

40 lines
maxFileLines

File length

A file longer than the limit.

400 lines
maxParameters

Parameter count

A function that takes too many parameters.

5
maxComplexity

Complexity

Cyclomatic complexity above the limit.

10
maxNestingDepth

Nesting depth

Deeply nested conditions and loops.

4
detectDuplicateCode

Duplicate code

An identical block repeated across the project.

6 lines
detectUnusedCode

Unused code

An import, variable or function that is never used.

requireClearVariableNames

Clear names

Vague names such as data1 or x.

requireErrorHandling

Error handling

An operation that can fail, with no try.

forbidEmptyCatchBlocks

Empty catch

An empty catch or except block.

forbidHardcodedSecrets

Hardcoded secrets

An API key or password written directly in the code.

forbidDebugStatements

Debug statements

console.log, debugger and print.

requireSingleResponsibility

Single responsibility

A class with too many methods, or a function that is both long and complex.

10 methods
requireDocumentationForComplexCode

Document complex code

A complex function with no JSDoc or docstring.

complexity ≥ 15
Presets: JavaScriptReactPythonDjangoExcluded by default: node_modules · dist · build · lock files
get started

From install to your first report in two minutes

Two front-ends over one analysis engine: a VS Code extension for daily work, and a CLI for teams and CI.

Four steps

  1. Install the extension

    From the Marketplace, then open a folder that contains a Git repository.

  2. CleanLens: Initialize Project

    From the Command Palette Ctrl/⌘ + Shift + P. It detects the project type, suggests a preset, and writes the rules file after you confirm.

  3. CleanLens: Run Analysis

    Runs the full analysis and opens the Dashboard automatically.

  4. Click any violation

    It opens the file at the exact line. Reopen the Dashboard any time with Open Dashboard.

Diagnostics as you type

Violations show up in the editor like any linter, without waiting for a full analysis: a squiggle, a hover with the details, and an entry in the Problems panel.

function handleRequest(req, res) {
  // 63 lines ...
}
Long function: Function handleRequest has 63 lines (limit 40).
CleanLens: Configure RulesOpens the rules file, and offers to create it if it's missing.
built for

Who CleanLens is for

Team leads and engineering managers

A fair, data-based picture: who raises code quality, who adds new problems, and who fixes old ones.

JS/TS and Python teams

Continuous code-quality review, without anyone carrying a legacy they didn't write.

DevOps and CI

A quality gate in the pipeline or before commit, with JSON output and clear exit codes.

Individual developers

Instant feedback in the editor while you type, before a problem reaches a commit.

Privacy-minded companies

No code leaves the machine and there's no cloud service, so it suits sensitive and closed-source projects.

100% local

Your code never leaves your machine

All analysis runs locally. No source code or developer data is sent anywhere, and there is no account or sign-in.

No cloudNo sign-inLocal per-commit cacheDocs in English and Arabic
good to know

What your team should know

We state the tool's limits plainly, because fairness starts with transparency.

A signal, not a verdict

The score is a signal for improving project quality. Always show it with the violation details, the confidence level and the ruleset used.

JS/TS and Python only

Files in other languages count as not analysed.

The commit window

Violations older than the window show as existing and are never charged. Widen it with --full-history.

Cross-file duplication

Detected on the latest snapshot (HEAD) only. Within each commit, duplication is measured inside the file.

coming next

What we're building next

CleanLens keeps evolving. These are the features we're building for upcoming releases, and they reach you automatically through VS Code updates as soon as they ship.

In progress

Load & stress testing for your site

Run a stress test against your site or API and find out how many concurrent users it can handle before it slows down or fails, and where it starts to break.

  • Simulate thousands of concurrent users
  • Response time and error rate at every load level
  • A clear report with the safe maximum
00.5k1k1.5k2k01s2s
Response timeSafe limit ≈ 1,200 concurrent usersIllustrative example
In progress

A tailored setup for every project

Rules and thresholds that adapt to your project type: a React front end, a Node API, a Python service or a library, with every setting adjustable to your team's needs.

Planned

Deeper security checks

Flag risky patterns such as SQL injection, eval and unvalidated input, on top of today's secret detection.

Planned

One-click fixes

Automatic fix suggestions for the most common findings, right in the editor, like removing a console.log or handling an empty catch.

Planned

Automatic pull request reviews

CleanLens comments on every GitHub pull request, showing only the issues that change introduced.

Install CleanLens today, and every new feature arrives automatically with updates.

Install free

Timelines and details may change during development.

free · open in vs code

Give your team fair quality reports

Install CleanLens, run the analysis, and find out who actually introduced each problem.

Install from VS Code Marketplace