Cyclomatic Complexity in C#
blog.ndepend.com
blog.ndepend.com
That means that it really only counts explicit branching. So, for example, in an OO language like C#, calling a virtual method doesn’t increment cyclomatic complexity even though the method invocation could go down many code paths. Potentially thousands if you’re dealing with a common interface like IEnumerable. If you’re working on a library then the number of potential code paths in this kind of situation is unbounded.
As an aside, it’s interesting to think how it might apply to a language like Smalltalk that doesn’t even have if or switch statements.
OO isn’t the only monkey wrench, either. Higher-order functions also introduce forms of branching that cyclomatic complexity doesn’t measure.
Again that doesn’t make it a useless metric. Just don’t think that a cyclomatic complexity limit in your codebase is some sort of maintainability panacea. Some of the least comprehensible functions I’ve deciphered had quite low cyclomatic complexities.
Taking the example provided in the article, I don't feel like the new code is meaningfully less complex. In fact, since it added some additional indirection, I could argue it's slightly more complex.
The core code with the nested if statements is something that I would probably refactor in some other way entirely. Maybe by taking advantage of other language features. It is a toy example so it's hard to say but that's part that feels like it needs simplification and untouched in this example.
You could additionally test the three helper functions. But the original tests against ProcessOrder would still be needed for completeness, so they wouldn’t necessarily add much except in an Uncle Bob style, “He who dies with the largest burden of gratuitous micro-tests wins,” sort of way.
Now if I really wanted to make that code easier to test, I’d instead be looking into ways to make the whole thing less stateful. Temporal coupling is much more confusing than if statements.
In agreement with your post, this research that measures cognitive load via EEG and time spent shows that the metrics we use for complexity and readability are only partial matches to what is going on: https://pmc.ncbi.nlm.nih.gov/articles/PMC9942489/
theThing() .map(someLamda) .filter(someLamda) .reduce(someLamda)....
Have I actually reduced complexity? I certainly prefer this over loops and if statements but does the pipeline and lamdas count as reducing cyclomatic complexity?
I think generally when you run into something like this, the better way to handle it is to sit back, and reconsider how your overall handling is designed.
There’s a bit of an assumption that the branching _has_ to exist, but so often it doesn’t.
To be fair, the article does suggest other techniques: hinting at separating pure/impure code for example, which I would say often results in a “net” cyclomatic complexity reduction. But I would disagree with “extract method” as the most effective… yes very effective in reducing cyclomatic complexity, but that ignores downsides, especially if the code needs to be thought about as a whole.
[1] https://nocomplexity.com/documents/codeaudit/complexitycheck...
Worst things happen always when 2 or more systems are combined because each system might be simple on its own, yet a combination is always much more complex.
It’s also the case that some of the most common sources of vulnerabilities, such as SQL injection, introduce no additional cyclomatic complexity. Heck, buffer overflows are good for your cyclomatic complexity - those array bounds checks are all extra branches.
Now, it's probably not a direct correlation. I'd think security bugs are more likely from programmers that unintentionally raise CC without really realizing it. Aka, overreaching their own knowledge when simpler structures are avaliable.
Here’s an oldie but goodie: https://cs.du.edu/~snarayan/sada/teaching/COMP3705/lecture/p...
I’ve personally had better success thinking of it as more of a measure of readability than of quality.
For something the the prior statement it is never a weird question to ask of there actually evidence of this or just it seems like it should be true so we believe it.
There are tons of things that seem like they would obviously be true, but it turns out they aren't.
That is just maths here working. Two systems combined always will have more states and inputs/outputs.
There is nothing to check here as it can be proven purely by maths.
Complex systems having more attack surface are obviously less secure.
They might be less interesting for attackers if they have to scan huge attack surface like IPv6 vs IPv4 but no one is claiming IPv6 network is more secure.
Just more I/O isn’t more complicated nor a bigger risk. More entanglement is more complicated.
> That is just maths here working
No this is just numerology here, it's meaningless.But in the process they created three additional functions to call. That means the overall system has more possible code paths, and introduces a need to think about what happens if they are ever called from somewhere other than the original entry point. Introducing ways to screw things up that did not previously exist is not reducing complexity and it is not increasing maintainability.
Your insistence that this somehow managed complexity is exactly why I wrote the top level comment cautioning people about how they interpret cyclomatic complexity. If you don’t understand what it’s actually measuring - not complexity, not really - then it will mislead you into bad decisions.
Some nice papers: https://arxiv.org/pdf/2002.07135 , https://arxiv.org/abs/2411.17343, https://doi.org/10.25300/MISQ/2025/49.1.075 or see https://arxiv.org/abs/2411.17343
There are many studies about this subject, but mind that complexity in code something different than 'complex' systems. You will need to dive into complexity science , but hard and 'soft' aspects should be taken into account when it comes to cyber security!
(a) We have plenty of evidence that buffer overflows etc play a role (caused by using manual memory management), but not so for cyclomatic complexity.
(b) Trying to reduce cyclomatic complexity in one function typically increases the complexity somewhere else, and so is not helping. Often this is just moving stuff around, and sometimes makes things more complex.
I do agree you need to keep nesting depth down, because that really does break my brain.
But a long sequence of cases or elifs needn't always be a problem, and here they make it sound like it is.
Personally I have a some tools that build dependency graphs (C# and Python) and store the results in a local database. Agents seem quite good at poking at this and coming up with refactor ideas. Graph analysis tools are useful here, simple application will detect cyclical dependencies, but I encourage the agents to use more complex tools like clustering to poke at the data.