Skip to content
CAI
Software that uses CAICheck a score

ratchetphp/Ratchet

65.6

Adequate · 19 September 2026

2.5k

lines of production code

PHP

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is the Ratchet library, a PHP framework for building real-time, bidirectional WebSocket and WAMP applications. It provides a modernized server architecture that handles HTTP upgrades, WebSocket framing, and WAMP pub/sub and RPC protocols while integrating with existing PHP session management. The codebase includes utilities for routing, security middleware, and connection management, all built on top of the ReactPHP event loop.

How it got here

2011–2012 — Modernization and WAMP support

13 changes.

This period focused on modernizing the Ratchet codebase by removing legacy socket and protocol implementations, updating dependencies for PHP 8+ and Symfony 6-8, and refactoring the WebSocket messaging API to align with RFC6455. It also introduced significant new features, including WAMP protocol support for pub/sub and RPC, and a SessionProvider for integrating WebSocket connections with existing web application sessions.

2013–2015 — PSR-7 HTTP refactoring and test expansion

9 changes.

The HTTP layer was refactored to adopt PSR-7 standards, introducing structured routing, security middleware, and standardized error handling. This architectural shift was accompanied by a significant expansion of the test suite, adding comprehensive unit tests for core components and fuzzing scripts to ensure protocol compliance.

Features

Add SessionProvider for WebSocket session integration

Introduces a new SessionProvider component that enables WebSocket connections to access and share session data from existing web applications. By implementing HttpServerInterface and leveraging Symfony HttpFoundation, the provider extracts session identifiers from HTTP cookies during the connection handshake, allowing developers to maintain user state across WebSocket sessions without requiring PHP's native session auto-start.

src/Ratchet/Session · high confidence

Added PHP session serialization handlers

Introduced new session serialization components in the \src/Ratchet/Session/Serialize\ directory, including a \HandlerInterface\ defining \serialize\ and \unserialize\ contracts, a \PhpHandler\ for standard PHP session format, and a \PhpBinaryHandler\ for binary format. These implementations support PHP 8.3 by suppressing warnings related to trailing data during unserialization, ensuring compatibility with stricter error reporting in newer PHP versions.

src/Ratchet/Session/Serialize · high confidence

Initial WAMP protocol support with pub/sub and RPC capabilities

This change introduces the WAMP (WebSocket Application Messaging Protocol) component to the library, enabling real-time publish/subscribe and remote procedure call patterns. It adds a new \ServerProtocol\ class to parse WAMP messages, a \TopicManager\ to handle topic subscriptions and broadcasting with support for exclude/eligible client lists, and a \WampServer\ wrapper to integrate WAMP into the existing Ratchet architecture. The update also includes \WampConnection\ for client interactions, a \Topic\ class for managing subscriber groups, and specific exception handling for JSON errors, allowing developers to build WAMP-compliant WebSocket applications.

src/Ratchet/Wamp · high confidence

Removals

Removal of legacy Ratchet socket components

The legacy \Ratchet\\Client\ and \Ratchet\\Socket\ classes have been removed from the library. These components, which previously provided a basic wrapper around PHP's socket functions, are no longer part of the codebase, indicating a shift in how low-level socket interactions are handled within the Ratchet framework.

lib/Ratchet · high confidence

Removal of obsolete WebSocket protocol stubs and adapter

The WebSocket protocol layer has been cleaned up by removing the \Adapter\ class and the stub implementations for the Hixie-76 and HyBi-10 protocol versions. This change eliminates legacy or incomplete code structures from the \lib/Ratchet/Protocol/WebSocket\ directory, streamlining the protocol handling by removing these specific version handlers and the dispatcher that selected between them.

lib/Ratchet/Protocol · high confidence

Behavioural changes

HTTP layer refactored to PSR-7 with new routing and security middleware

The HTTP handling in src/Ratchet/Http has been rewritten to use PSR-7 request objects instead of raw string parsing. This introduces an HttpRequestParser to buffer and parse incoming HTTP headers into PSR-7 Request objects, which are then passed to an HttpServerInterface. The HttpServer now acts as a facade that buffers requests until headers are complete, delegating to a wrapped component. A new Router component integrates with Symfony's UrlMatcher to route requests to specific controllers, passing matched route parameters and query strings to the controller's onOpen method. Additionally, an OriginCheck middleware is provided to enforce same-origin policies by rejecting connections from unauthorized domains with a 403 status, and a NoOpHttpServerController serves as a default controller for impatient clients or unmatched routes. The CloseResponseTrait provides a consistent way to send HTTP error responses (e.g., 400, 403, 404, 405, 413, 500) and close connections.

src/Ratchet/Http · high confidence

New server-side components and IoServer refactoring

The server layer introduces several new application components: EchoServer for simple message echoing, FlashPolicy to handle Adobe Flash cross-domain policy requests, and IpBlackList to block specific IP addresses. The core IoServer class has been refactored to expose its loop, app, and socket properties publicly and now supports modern ReactPHP APIs (Loop and SocketServer) while maintaining backward compatibility with legacy versions. Additionally, IoConnection now wraps React socket connections and properly populates the remoteAddress property on the connection object.

src/Ratchet/Server · high confidence

Ratchet v0.4.4 release with modernized App facade and PHP 8.2+ compatibility

This release introduces version 0.4.4 of the Ratchet library, featuring a refactored \App\ facade that simplifies WebSocket server creation by defaulting to the global React Event Loop (v1.2+) and using the modern \SocketServer\ API (react/socket v1.9+), while maintaining backward compatibility with older versions. The \App\ class now includes built-in support for Flash Policy servers, configurable HTTP host origins, and automatic keep-alive handling for WAMP and WebSocket components. Additionally, the codebase addresses PHP 8.2+ compatibility by implementing the \AbstractConnectionDecorator\ to handle dynamic property forwarding safely without relying on the \\#\[\\AllowDynamicProperties\]\ attribute, and updates the namespace structure to \src/Ratchet\ with new core interfaces like \ComponentInterface\ and \ConnectionInterface\.

src/Ratchet · high confidence

Refactored WebSocket messaging to use RFC6455 Message objects

The WebSocket component has been refactored to align with the RFC6455 standard by introducing a new message-based API. Application components now implement the new \MessageComponentInterface\, which receives \MessageInterface\ objects in \onMessage\ rather than raw string payloads. This change enables proper binary messaging support and structured frame handling via the new \WsConnection\ and \ConnContext\ classes, while maintaining backward compatibility for components still using the legacy \MessageComponentInterface\ by automatically extracting the payload string.

src/Ratchet/WebSocket · high confidence

Repository initialization with legacy test support and updated PHPUnit configuration

The repository has been initialized with core project files including a comprehensive CHANGELOG, MIT LICENSE, SECURITY policy, and README documentation. The testing infrastructure has been updated to support PHPUnit 9.6+ via a new \phpunit.xml.dist\ configuration, while retaining a \phpunit.xml.legacy\ file for older PHPUnit versions. A \.gitignore\ file has been added to exclude build artifacts, vendor directories, and lock files, and a \Makefile\ has been introduced to streamline testing, coverage reporting, and Autobahn compliance checks.

(repo-wide) · high confidence

Session storage updated for Symfony 6, 7, and 8 compatibility

The session storage implementation in src/Ratchet/Session/Storage now supports Symfony 6, 7, and 8 by introducing version-specific proxy and storage classes (VirtualProxyForSymfony6, VirtualProxyForSymfony7, VirtualSessionStorageForSymfony6, VirtualSessionStorageForSymfony7). These classes adapt to native type declarations introduced in newer PHP versions (8+ for Symfony 6, 8.2+ for Symfony 7, 8.4+ for Symfony 8), ensuring correct method signatures for session ID handling and storage operations. The main VirtualProxy and VirtualSessionStorage classes now use runtime detection to alias to the appropriate version-specific implementation, maintaining backward compatibility while supporting modern Symfony versions.

src/Ratchet/Session/Storage · high confidence

Test coverage

Added Autobahn fuzzing server test script; Added test helper mocks and stubs for Ratchet components; Added unit tests for Server components; Added unit tests for VirtualSessionStorage with PDO; Added unit tests for WAMP protocol components; Added unit tests for connection decorators, App initialization, and session handling; Added unit tests for session serialization handlers; Initial unit test coverage for HTTP components; Migrate test bootstrap to PSR-4 autoloading; Removed Hybi10 WebSocket version test.

Dependencies

Updated dependency constraints for Symfony, React, and Guzzle

The library's composer.json has been updated to support newer versions of its core dependencies. PHP minimum requirement is set to 5.4.2. Symfony components (http-foundation and routing) now accept versions up to 8.0. React components (socket and event-loop) accept versions up to 1.0 and 0.5 respectively. Guzzle's PSR-7 implementation (guzzlehttp/psr7) is allowed in versions 1.7 or 2.0. PHPUnit testing framework is constrained to versions 9.6, 8.5, 5.7, or 4.8.36.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 66.

Lenses

  • Code Health 98
  • Architecture 93
  • Maturity 54
  • Readiness 57
  • Security 100

Changes since last survey

  • 300 commits — 250 feature/other, 50 fixes

By area

  • src/Ratchet — 107 commits
  • (repo) — 98 commits
  • (root) — 72 commits
  • tests/unit — 19 commits
  • .github/FUNDING.yml — 1 commit
  • .github/ISSUE_TEMPLATE — 1 commit
  • .github/workflows — 1 commit
  • tests/autobahn — 1 commit

Notable commits

  • fix: Added unit test for query parameter fix
  • fix: Attempt to fix Travis
  • fix: Fix UTF-8 check
  • fix: Fix and test for uncommon payload length issue
  • fix: Fix case on futureTick
  • fix: Fix compatibility with react/socket v1.9+ in App for FlashPolicy
  • fix: Fix event arguments
  • fix: Fix event arguments
  • fix: Fix example in README.md fixes #690
  • fix: Fix loss of query params in Router and unit test
  • fix: Fix readme headers, update apigen with 0.4
  • fix: Fix rejecting invalid HTTP request starting with newlines
  • fix: Fix server configuration link on docs
  • fix: Fix unsolicited pong crash with keep alive enabled. Fixes #430
  • fix: Fix version badge
  • fix: Fix warning when handling HTTP request with missing Origin header
  • fix: Fixed Router/tests with PSR-7 integration
  • fix: Fixed Session unit tests from PSR-7
  • fix: Fixed failing HTTP unit tests from PSR-7
  • fix: Fixed frame creation type bug
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

ratchetphp/Ratchet was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit e621c6c40bf684bbbb877102416ad5303d05a9cc — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.