See how it all fits together
Get the big picture of any project, including its structure, its connections, and its most complicated parts, without reading every file one by one.
Turn any software project's source code into spreadsheet maps.
A codebase is the collection of files that makes a piece of software work. Codebase Cartography reads through any project folder on your computer, charts what it finds, and saves it as three coordinated spreadsheets: a Project Map, a Feature Map, and a Content Map. They're available as standard portable .csv / .tsv files, which are formats universally recognized as spreadsheets. Sort and filter them to find answers fast, audit your code, keep snapshots as your project grows, and give AI tools a clear, compact picture of your project.
01 · Overview
Opening an unfamiliar project can feel daunting without a map: hundreds or thousands of files, and no obvious place to start. Codebase Cartography draws the map for you. It lists every file, script, and folder, then records key facts about each one, often called metadata: what kind of file it is, its size, what other code it relies on, what it does, and how complex it is.
For more than 20 programming languages, including Python, JavaScript, Rust, and C#, it looks even deeper: at the functions each file defines (the named building blocks of a program), the code it brings in, the information that flows in and out, what each function hands back, and where stored information changes.
Beginners can get started in a few clicks: choose a folder, scan it, and save your maps. Experienced developers get plenty of depth: detailed code measurements, fine-tuned filters, protection for passwords and keys, and tools for AI prompts and automation. Either way, it saves hours of digging through files by hand.
And because nearly all software is made of files and folders, it fits almost any project, from websites, apps, and games to research scripts and automation tools, and almost any team, from solo developers to large companies in finance, healthcare, retail, education, and beyond.
Get the big picture of any project, including its structure, its connections, and its most complicated parts, without reading every file one by one.
Give developers, testers, designers, translators, accessibility specialists, and project managers the same up-to-date record to work from.
Give AI coding assistants and LLMs (Large Language Models) organized facts instead of scattered snippets of code. Their suggestions are more likely to fit your project, and they use fewer tokens, the small chunks of text that AI tools read and often charge by.
02 · The three maps
Each map looks at your project from a different angle. All three share each file’s path, its address inside the project, so you can follow a thread from one map to the next.
The physical layer
What’s in the project?
Every file and folder gets its own row. Columns record the basics, such as type, size, and location, then go deeper for code: what other code each file depends on, the functions it defines, how information moves through it, what it changes along the way, how it handles errors, and how complex it is.
The logical layer
What can the code do?
Each row describes a feature, something the software can do, and links it to the files involved. The app fills in a first draft for you, including a classification, descriptive tags, and a complexity score. Then you add what only your team knows: company-specific naming conventions, whether each feature works, what still needs work, QA (Quality Assurance testing guidelines) notes, observations, and your own categories.
The surface layer
What do people see?
Lists the parts of the UI (User Interface), meaning everything people see and use on screen: The front-end surface - buttons, labels, headings, form fields, menus, paragraphs, and tooltips (the small hints that pop up when you point at something), and more. Each entry records its text, the file it comes from, when it appears, and where it sits in the layout. It gives you a head start on UX (User Experience) reviews, translation, and accessibility work, which helps make software usable by everyone.
Trace in any direction
Start with a button. Find the file that displays it, see what that file depends on and how complex it is, then see which feature it belongs to.
Start with a file. See everything it puts on screen and every feature it helps power.
Start with a feature. Find the files that build it and every part of the screen people use to reach it.
Your input
The automatic analysis gives you a strong start. Add the context only your team knows, and the Feature Map becomes a living guide to your project.
Even a quick pass, such as naming your 20 most important features and marking whether they work, makes the map far more useful.
03 · How it works
Choose any folder of code on your computer, or load a snapshot you saved earlier.
Optional: common clutter, such as downloaded code libraries and build output, is skipped automatically, and you can add anything else you’d like to leave out.
The app reads through the project, sorts every file into categories, and pulls out the details that matter.
Check file counts and types, preview the maps, and see any possible passwords or keys it found, all before you export anything.
Save the maps as CSV (Comma-Separated Values) or TSV (Tab-Separated Values) spreadsheet files, copy them to your clipboard, and keep snapshots to compare later.
Lays out every folder and file for you, automatically.
Sorts scripts into categories and records the measurements that matter for each kind.
Tracks functions, dependencies, complexity, the flow of information, and more.
Focuses on the parts you care about and leaves out the clutter.
Totals file types, sizes, and code measurements at a glance.
Saves files that open in Microsoft Excel, Google Sheets, Apple Numbers, and other spreadsheet apps, or copies them straight to your clipboard.
04 · What it records
Each column answers a different question about a file: how it’s built, how it behaves, and how safe it is to change. Here’s what each one means in everyday words. Learn about every Project, Feature, and Content Map column.
05 · Built-in tools
Codebase Cartography also includes tools for protecting secrets, publishing readable copies of your code, preparing AI prompts, and running exports automatically. Each has its own guide inside the app; here they are in one place.
The Exclusions area has three separate filters: folder and file names, file types, and a check of each file’s contents. Together they keep clutter out of your maps, including downloaded libraries, build output, caches, logs, temporary files, and files that aren’t text.
Skips folders and files whose names match the patterns you choose, including generated and minified files (code compressed to take up as little space as possible). Skipping a folder also skips everything inside it.
Skips files by type or by extension, the ending after the dot in a file’s name (such as .log). Important package and settings files written in JSON (JavaScript Object Notation) stay protected from this filter.
Reads the first 1,024 bytes of each file and skips it if that sample contains a null byte, a telltale sign of binary (non-text) files such as images and compiled programs. This works even when a file’s extension is missing or misleading.
Code sometimes contains secrets by accident: passwords, API keys (codes that let a program use an online service), access tokens, database connection strings, private keys, cloud credentials, webhook signing secrets, and other sign-in details. Codebase Cartography looks for text that resembles these and lists possible findings in the Summary section before you export.
It recognizes the telltale prefixes many services put at the start of their keys, long secret-looking values next to labels such as api_key or client_secret, web addresses with logins built in, private-key blocks, and settings files that often hold secrets. When redaction (hiding sensitive values) is on, each value it finds is replaced with a safe placeholder, and the rest of the map stays useful.
Pattern matching can miss unusual secrets, and it can flag harmless examples or test data. It never checks whether a secret is real and never contacts outside services. Always review your exports before sharing them, especially for private projects, live systems, customer data, internal infrastructure, or proprietary code.
AI and cloud providers; sign-in (authentication) systems; server infrastructure; private keys and signing files; databases and message queues; messaging services and webhooks (automatic messages sent between web services); mobile SDKs (Software Development Kits); monitoring and SaaS (Software as a Service) tools; package registries (online libraries of reusable code); payment services; source control and code-hosting services; and CI/CD (Continuous Integration and Continuous Delivery) systems, which build, test, and release code automatically.
Formats change, so belonging to a family doesn’t guarantee that every credential will be found.
Choose a project folder, and Codebase Publisher turns it into a self-contained website: one neatly formatted page for each file, linked from a clickable index. Pick a visual style, font sizes, and page width. The result is a set of HTML (HyperText Markup Language) web pages that open in any browser, right from your computer.
On ordinary web pages, long lines of code run off the edge of the screen, and printouts often wrap code without regard for its structure. Codebase Publisher lets you choose how many characters fit on a line and keeps the indentation when lines wrap, so nested code still looks nested. With syntax highlighting, each kind of code, such as numbers, text strings, variables, types, functions, and operators, can have its own color, and comments get their own color and size.
The result reads like a well-typeset document on screen or on paper: a handy way to share, review, or archive a snapshot of your project.
A prompt is the request you give an AI assistant. Prompt Tools combines your maps, a project profile, your feature notes, and any reference documents into detailed, well-organized prompts. It doesn’t write code or contact an AI service itself; it prepares the context you paste into the AI chat of your code editor or IDE (Integrated Development Environment).
codebase-repository-profile.json, a profile that tells prompts how your project is organized and which conventions it follows.The prompts ask the assistant to trace how a feature really works before claiming success: where it starts, which code owns and saves its information, which public APIs and outside code depend on it, what runs in the background, and how it’s built and verified. You can compare the assistant’s plan with your maps, profile, and reference document before accepting any change.
Automation lets another program on your computer, running under your own user account, ask Codebase Cartography to run a Generate All Maps preset (a saved, reusable setup) that you’ve already reviewed. The project, save location, file formats, and safety settings stay inside Codebase Cartography, so a request can’t change them.
Saves a reusable setup using the project and output folders you picked in the app. Every preset exports the Project, Feature, and Content Maps. Saving a preset doesn’t let outside programs run it.
The master switch. Each preset must also be valid and on the approved list, known as the allowlist. Turning authorization off blocks future runs and clears the allowlist, but it doesn’t cancel a request that has already been accepted.
Shows the presets that pass the app’s checks. An outside program refers to a preset only by its fixed ID, so it can’t change the approved folders or output choices.
Prepares everything another program needs: where the app is installed, the chosen preset, the request format in JSON, examples, and a test command. Export tests create real map files; the separate readiness check doesn’t.
Includes setup steps, version and launch details, examples grouped by category, a readiness check that doesn’t export anything, an export test, and a security-hardened example program for Node.js (a popular way to run JavaScript outside a web browser).
A short, best-effort history of recent requests, not a tamper-proof audit log. The result returned to the program that made the request is the final word on each one.
A web app that runs on your own computer, built with HTML, CSS (Cascading Style Sheets), and JavaScript, can request an approved preset through a small Node.js helper called a bridge. Web browsers can’t safely start desktop apps on their own, so the bridge keeps the app’s location, the preset ID, your project folders, and export settings out of the browser.
The bridge should listen only on 127.0.0.1, the address a computer uses to reach itself. It should accept requests only from your exact local pages, allow one fixed action with an empty request, run one job at a time, and reply with short, safe status codes. The browser should never receive project folders, the app’s location, the preset ID, or redaction settings.
06 · Ways to use it
Before you edit a file, see what depends on it, which features it supports, and which screens it affects.
Give AI assistants targeted rows from each map instead of whole folders of code, for more accurate answers and fewer hallucinations (confident-sounding mistakes).
Describe your project in a compact, organized form instead of pasting large amounts of raw code into an AI model, saving both time and tokens.
Move from plain-language features to the words on screen, then down into the code that makes them work.
Compare exports over time to catch growing files, unexpected changes on screen, features that stopped working, and technical debt (code that needs tidying up later).
Start with a list of every piece of on-screen text, linked to its source file, with its type, when it appears, its translation status, and its locale key (the label used to look up each translation).
Give new teammates, developers, and contractors guided orientations of the project from day one.
Taking over someone else’s code, an older system, or an acquired product? Get your bearings quickly, before you change anything.
Agencies and freelancers can deliver a clear record of what was built, alongside the code itself.
Give reviewers, auditors, and security teams a clear inventory of the code, what it relies on, and where possible secrets turned up, in finance, healthcare, government, or any other field.
Share a project’s size, shape, and progress in a format almost everyone already knows how to use: a spreadsheet.
Show students how real software is organized, one file and one function at a time.
Map gameplay scripts, engine code, and tools written in C#, C++, Lua, and more, so a growing game stays easy to change, debug, and hand off.
Keep pipeline scripts, tools, and project folders organized and documented, from Python add-ons for 3D apps to the files a production depends on.
Trace the code behind a game’s or app’s audio, from the scripts that trigger sounds to plug-in and processing code, and keep audio tools and files in order.
Document firmware, automation scripts, and parametric CAD code, and keep machine settings and project files organized from prototype to production.
Codebase Cartography
Developed by Harrison Creative LLC