Git checks and rules
Confirms the folder is a Git repository with commits, then reads .clean-code-tracker.json or uses a built-in preset.
CleanLens replays your Git history and compares every file before and after each commit, so every Clean Code violation is charged to the developer who actually introduced it. Each developer then gets a fair quality score that doesn't depend on how much code they wrote.
Or inside VS Code: press Ctrl/⌘ + P and paste the command.
AI assistants generate hundreds of lines in minutes, and rarely does anyone review every one. API keys leak into Git, errors vanish into empty catch blocks, functions bloat and repeat. CleanLens checks every line, tells you the exact file and line, and one click takes you there.
Keys and passwords written into code, swallowed errors, and operations with no error handling.
Long, complex functions, duplication, unused code and vague names.
Every finding comes with its file, line number and severity, and one click opens the file on that exact line.
Just a few examples of what CleanLens can detect.
Click a finding to jump to its line
1import { S3Client } from "@aws-sdk/client-s3";23export const config = {4 region: "eu-central-1",5 retries: 3,6 timeoutMs: 8000,7};89// generated: connect to storage10export const s3 = new S3Client({11 region: config.region,12 credentials: { accessKeyId: "AKIAIOSFODNN7EXAMPLE",13 secretAccessKey: "wJalrXUtnFEMI/K7MDENG" },14});
Tools like git blame and ordinary linters charge problems to whoever last edited the line or file. The result is unfair reports: fix a typo in an old file and you inherit all its problems, while the person who wrote them disappears from the picture.
1import { db } from './lib'2export async function handle(req, a, b, c, d, e, f) {maxParameters3 const data1 = await db.query(req.q)clearNames4 try { save(data1) } catch (err) {}emptyCatch5 console.log('debug', data1)debugStatement6 // ...7 return formatTotal(data1) // was: fromatTotalchanged8}
Charged to Layla, even though she only fixed a typo on line 7.
All four violations existed before the commit, so they are classified as existing and charged to no one. Line 7 is clean.
Whitespace-only edits are ignored, and code moved between files is tracked.Keep scrolling. The lens in the background walks the commit history the same way the analysis does.
Confirms the folder is a Git repository with commits, then reads .clean-code-tracker.json or uses a built-in preset.
14 Clean Code rules for JS/TS/JSX/TSX using the AST, and for Python using heuristics, plus duplicate-code detection.
Walks the newest 500 commits (configurable). For every changed file it runs diff -w -M -C and analyses the version before and after the commit.
A stable fingerprint per violation (rule + path + symbol + context) recognises it even when its line number moves. It is charged to the author only if it appears on lines they changed or in a function they modified.
Each developer gets a score across three categories. Results are cached per commit, so the next run only analyses new commits.
The score measures the density of violations a developer introduced per 1,000 lines they wrote. Writing more code doesn't raise or lower it, and contribution is shown separately next to it.
Turn each one on or off and set its severity (low / medium / high / critical) and threshold. A shared file for the team in the repo, and a local file for your personal overrides.
A function longer than the limit.
40 linesA file longer than the limit.
400 linesA function that takes too many parameters.
5Cyclomatic complexity above the limit.
10Deeply nested conditions and loops.
4An identical block repeated across the project.
6 linesAn import, variable or function that is never used.
Vague names such as data1 or x.
An operation that can fail, with no try.
An empty catch or except block.
An API key or password written directly in the code.
console.log, debugger and print.
A class with too many methods, or a function that is both long and complex.
10 methodsA complex function with no JSDoc or docstring.
complexity ≥ 15Two front-ends over one analysis engine: a VS Code extension for daily work, and a CLI for teams and CI.
From the Marketplace, then open a folder that contains a Git repository.
From the Command Palette Ctrl/⌘ + Shift + P. It detects the project type, suggests a preset, and writes the rules file after you confirm.
Runs the full analysis and opens the Dashboard automatically.
It opens the file at the exact line. Reopen the Dashboard any time with Open Dashboard.
Violations show up in the editor like any linter, without waiting for a full analysis: a squiggle, a hover with the details, and an entry in the Problems panel.
function handleRequest(req, res) { // 63 lines ... }
CleanLens: Configure RulesOpens the rules file, and offers to create it if it's missing.# text report for the current repo $ cleanlens # every violation, with the Django preset $ cleanlens ./services/api --preset django --violations # Markdown report to share with the team $ cleanlens --markdown > report.md # JSON for dashboards and diffs between runs $ cleanlens --json > clean-code.json # quality gate: fail on any high or critical violation $ cleanlens --fail-on high Developers: 5 · Analyzed commits: 480 ✖ exit 1 violations at or above "high"
# .github/workflows/clean-code.yml
on: [pull_request]
jobs:
analyze:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with: { fetch-depth: 0 }
- uses: actions/setup-node@v4
with: { node-version: 20 }
- run: npx cleanlens --fail-on criticalfetch-depth: 0 is required because attribution needs the full commit history. Exit codes: 0 success, 1 quality gate failed, 2 could not analyse.
A fair, data-based picture: who raises code quality, who adds new problems, and who fixes old ones.
Continuous code-quality review, without anyone carrying a legacy they didn't write.
A quality gate in the pipeline or before commit, with JSON output and clear exit codes.
Instant feedback in the editor while you type, before a problem reaches a commit.
No code leaves the machine and there's no cloud service, so it suits sensitive and closed-source projects.
All analysis runs locally. No source code or developer data is sent anywhere, and there is no account or sign-in.
We state the tool's limits plainly, because fairness starts with transparency.
The score is a signal for improving project quality. Always show it with the violation details, the confidence level and the ruleset used.
Files in other languages count as not analysed.
Violations older than the window show as existing and are never charged. Widen it with --full-history.
Detected on the latest snapshot (HEAD) only. Within each commit, duplication is measured inside the file.
CleanLens keeps evolving. These are the features we're building for upcoming releases, and they reach you automatically through VS Code updates as soon as they ship.
Run a stress test against your site or API and find out how many concurrent users it can handle before it slows down or fails, and where it starts to break.
Rules and thresholds that adapt to your project type: a React front end, a Node API, a Python service or a library, with every setting adjustable to your team's needs.
Flag risky patterns such as SQL injection, eval and unvalidated input, on top of today's secret detection.
Automatic fix suggestions for the most common findings, right in the editor, like removing a console.log or handling an empty catch.
CleanLens comments on every GitHub pull request, showing only the issues that change introduced.
Install CleanLens today, and every new feature arrives automatically with updates.
Install freeTimelines and details may change during development.
Install CleanLens, run the analysis, and find out who actually introduced each problem.