Code complexity calculator
Paste a function and get its cyclomatic and cognitive complexity score, rated against the thresholds in our practical guide to code complexity. No account, nothing stored.
Read as (auto-detected) · total cyclomatic · total cognitive
No code left to score once comments and strings were removed.
-
line- Cyclomatic
- Cognitive
A token-based estimate, not a full parser: comments and strings are removed, then every branching keyword and operator is counted. Closures and nested functions are scored as part of the function that contains them.
How the score is calculated
Cyclomatic complexity
Start at 1 and add 1 for every decision point:
if,
else if /
elseif /
elif,
for,
foreach,
while,
do,
each case and match arm,
catch /
except,
&&,
||,
and,
or,
and the ternary ? :.
The null-coalescing ?? is not a branch and does not count.
The result is the minimum number of tests needed to cover every path.
Cognitive complexity
SonarSource's measure of how hard code is to read. Each
if, loop,
switch,
catch and ternary adds 1,
plus 1 for every level it is nested.
else and
else if add a flat 1, and a run of
the same boolean operator counts once: a && b && c
is 1, a && b || c is 2.
Guard clauses that return early cost almost nothing, which is the point.
What the numbers mean
| Cyclomatic | Rating | What it means |
|---|---|---|
| 1–5 | Simple | Easy to understand and test. Where most code should be. |
| 6–10 | Moderate | Manageable, but starting to get complex. |
| 11–20 | High | Difficult to test thoroughly. Refactoring is recommended. |
| 21–50 | Very high | Almost certainly hiding bugs. Break it apart. |
| 50+ | Untestable | A liability. It needs attention now. |
For cognitive complexity, keep each function at 15 or below; 16–25 is a warning and anything above 25 needs refactoring. These are the same thresholds, with the reasoning and worked examples, in Understanding Code Complexity: A Practical Guide.
What it cannot tell you
This is a token-based estimate, not a compiler. It strips comments and string literals, then recognises functions and blocks from the tokens around them. For ordinary code that lands within a point or two of what a linter reports; macros, unusual syntax or code that only parses with a language's full grammar can be counted differently.
More importantly, complexity is a property of one function at one moment. It does not tell you whether that function changes every week or has not been touched in three years, and a complex function nobody edits costs far less than a moderate one everybody does.
One function is a curiosity. Your pull requests are the cost.
Complex code shows up in delivery long before anyone measures it: pull requests that grow too large to review, sit waiting for the one person who understands the module, and come back with rework. Coderbuds measures those directly from your repositories:
- Which pull requests are too large to review well, and who keeps opening them?
- Where does review wait longest, and is it always the same reviewer?
- How long does a change take from first commit to production?
- Which changes fail once they are out?
Free trial, no credit card. Authorize your repositories and we sync the last 30 days of history, so there is something to read straight away.
Frequently asked questions
What is a good code complexity score?
For cyclomatic complexity, 1 to 5 is simple and 6 to 10 is manageable; most teams refactor anything above 10, and above 20 a function is very hard to test thoroughly. For cognitive complexity, aim to keep each function at 15 or below, treat 16 to 25 as a warning, and refactor above 25.
What is the difference between cyclomatic and cognitive complexity?
Cyclomatic complexity counts the independent paths through a function, which tells you how many test cases it needs to cover every path. Cognitive complexity measures how hard the function is to read: it charges extra for structures nested inside other structures, so a flat list of guard clauses scores low while the same logic written as nested if/else scores high.
How accurate is this calculator?
It is a token-based estimate, not a full parser. Comments and string literals are removed first so they never count, and every branching keyword and operator is counted, so for ordinary functions the result is usually within a point or two of what ESLint, SonarQube or radon report; each of those makes slightly different counting choices of its own. Unusual syntax, such as macros, single-expression lambdas or code that only parses with a full grammar, can be counted differently.
Which languages does it support?
JavaScript and TypeScript, PHP, Python, and the C family: Java, C#, Go, C and C++. Leave the language on auto-detect or pick it yourself if the guess is wrong.
Do you store the code I paste?
No. The code is sent to our server, scored in memory and the result is returned. Nothing you paste is written to a database.
How do I measure complexity across a whole codebase?
Use a linter in CI: the ESLint complexity rule for JavaScript and TypeScript, PHPMD or PHPStan extensions for PHP, radon for Python, or SonarQube across languages. Fail the build when a function crosses your threshold, so complexity cannot creep in one pull request at a time.
You're subscribed!
Check your email for a confirmation link. You'll start receiving weekly engineering insights soon.
More like this, roughly weekly
What we learn measuring review load, delivery and code quality across real engineering teams. No product announcements.