Current product evaluation
We disclose the completeness of the current release of managed small PaaS and the basis for its judgment.
current score
As of July 29, 2026, the implementation completeness of Cake20 Web is 97/100, grade A+. Evaluate. The current stage is not a prototype, but rather a project managed directly by the operator. This level is applicable to small PaaS and privately managed websites.
The score is more important than the number of features: data loss prevention, deployment regression validation, failure detection, Focusing on actual recoverability and whether operators can check the status. Judgment.
Evaluates the structure, performance design, functional quality, and implementation completeness of the current development stage. Long-term operating performance is not included in deductions.
This evaluation is a self-evaluation based on Cake20’s internal implementation and verification results. It does not imply any third party security certification, availability guarantee or SLA.
Evaluation by area
- Core functions 98 points — website creation, editing, responsive preview, inspection, distribution, The entire life cycle from startup to rollback is connected.
- Development experience/MCP 98 points — source, configuration, PostgreSQL, Redis, Git, log and Distribution control and operational inspection guidance are all handled in one workflow.
- Deployment stability 97 points — atomic source replacement, isolated inspection, release replacement, failure recovery, and Enforces full browser E2E.
- Security/Isolation 96 points — DB, Redis ACL, file, and process boundaries for each website Apply secret·audit log and MCP inspection time protection rules.
- 98 points for documentation — operational data boundaries, workflows, recovery and failure response procedures Public documents and MCP manual are provided together.
- Test score of 95 — Full browser flow and actual ad-hoc scheduled by administrator We provide PostgreSQL·Redis recovery testing.
- Operational response 96 points — Manager, website, DB, Redis, disk, recovery training, E2E Monitors externally and notifies failure and recovery.
- Maintainability 94 points — app/stores and server/hooks, server/routes, Clearly separate user structure and runtime responsibilities with server/tasks package.json and documentation share the same rules.
Verification basis
- At the time of verification on July 26, 2026, 265 automatic tests were passed in total, and environmental dependence One command guard was explicitly skipped. Subsequent changes are related to each We keep checking with unit tests and full scans.
- On July 29, 2026, Editor Preview device, home lock, runtime mode, bottom console, Verify HTML/image conversion, MCP maintenance time, and Nitro compatibility changes I checked cafe1 production build and internal/external HTTP responses.
- Cake20 production build passes and is created → Edit → Inspection → Deploy → The rollback browser scenario passes in an isolated environment.
- Administrators can view E2E's daily and weekly Seoul time schedule, next execution, current status, and recent You can check the results, time required, and logs and execute immediately.
- Physically restore the latest DB backup to temporary PostgreSQL or PGeasy and restore table, Check row and sequence.
- After checking the integrity of the Redis RDB, actually load it into a separate loopback Redis. Compare the number of keys before and after restoration.
- External health Manager DB·Redis, running website, disk, recent recovery training and Reservation E2E results are judged together.
Confirmation of assessment scope and operations
97 points are at the development stage based on the current source, actual implementation, and automatic verification. Product completeness. Long-term operating performance will not be deducted from this score. Reserved E2E, regular PostgreSQL/Redis recovery training, and external failure/recovery notifications are provided. This is a process to continuously check each release and operating environment.
- Scheduled E2E starts at the time you set and the results are E2E scans set by the administrator. Make sure it stays in the tab
- Verify temporary restoration time and success results for operational data size
- Confirm reception of failure notifications from Manager outage/website failure/disk threshold
- After normalization, check that recovery notification is delivered once without duplication
Remaining deduction items
- The Manager has a single device architecture and does not provide automatic failover or multiple regions.
- Based on actual operational data, recovery target RTO and allowable data loss RPO remain to be measured.
- We do not yet provide an operational editing screen that is automatically generated from the content schema.
- File synchronization of operational Manager sources can be deployed cleanly and atomically on a per-release basis. There is room for development through replacement and rollback.
- The overall inspection is the same despite differences in Redis/Runtime fixtures between local and service servers. There is room to make environmental dependence tests more conclusive in producing results.
- When expanding to public SaaS, team roles, granular permissions, payment, abuse response and A separate external security review is required.
The current range of small managed PaaSs offers multi-region and public SaaS functionality. It is not considered a necessary condition. Keeping the product range intentionally small We do not evaluate choices as functional defects.