Skip to content
CAI
Software that uses CAICheck a score

socketio/socket.io

57.5

Adequate · 28 September 2026

31.1k

lines of production code

TypeScript

with JavaScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the Socket.IO library, a real-time application framework that enables bidirectional, event-based communication between clients and servers. It provides a robust engine for managing WebSocket connections with fallbacks to long-polling, supporting features like room-based broadcasting, connection state recovery, and horizontal scaling via cluster adapters. The codebase includes extensive examples demonstrating integration with various frontend frameworks, backend architectures, and deployment strategies.

How it got here

2010–2020 — Legacy cleanup and modern examples

18 changes.

This period focused on removing legacy client-side code, including deprecated transports, MooTools utilities, and outdated vendor dependencies, to streamline the library. Concurrently, the project expanded its documentation with a wide array of modern examples covering WebTransport, clustering, authentication, and integration with popular frameworks like React and Angular.

2021–2024 — TypeScript migration and clustering support

44 changes.

The project underwent a comprehensive rewrite of its core libraries (Socket.IO, Engine.IO, and their parsers) into TypeScript, introducing new APIs for broadcasting and connection state recovery. This period also established a robust clustering architecture with dedicated adapters and engines for Redis, PostgreSQL, and Node.js native clusters, significantly expanding horizontal scaling capabilities. Concurrently, the repository expanded its example suite to cover modern frameworks like Next.js, Nuxt, and React Native, alongside various authentication and bundling patterns.

2025–2026 — Security hardening and clustering features

6 changes.

This period focused on addressing a critical SQL injection vulnerability in the PostgreSQL emitter and refactoring the cluster adapter to simplify its architecture. It also introduced new capabilities for cross-process communication via a Redis Streams emitter and expanded documentation with examples for HTTP/2 and PM2 clustering.

Features

Add Angular TodoMVC example with Socket.IO synchronization

This change introduces a new Angular TodoMVC example in the \examples/angular-todomvc\ directory. The example demonstrates real-time collaboration by integrating Socket.IO: a Node.js server (\server.ts\) manages the todo list state and broadcasts updates, while the Angular frontend uses a \RemoteTodoStore\ to synchronize changes via Socket.IO events. The entry includes the full project scaffolding generated by Angular CLI 11.0.4, including configuration files (\angular.json\, \tsconfig.json\), unit and end-to-end tests (Karma and Protractor), and the application source code.

examples/angular-todomvc · high confidence

Add Create React App example with Socket.IO integration

A new Create React App example has been added to the documentation, providing a complete client-server setup for Socket.IO. The example includes a React 18 client application that connects to a local Socket.IO server, demonstrating real-time messaging and connection status updates. It also includes a simple Node.js server that emits periodic messages and handles client connections, along with standard Create React App configuration files, testing setup, and service worker support for offline capabilities.

examples/create-react-app-example · high confidence

Add HTTP/2 example with secure server and certificate generation

An example demonstrating Socket.IO over HTTP/2 has been added to the examples directory. This includes a Node.js server using \createSecureServer\ with TLS certificates, a client-side HTML page that displays connection status and transport upgrades, a script to generate self-signed certificates, and a gitignore file to exclude the generated keys.

examples/http2-example · high confidence

Add NW.js integration example

Added a new example in the examples/nwjs-example directory demonstrating how to use Socket.IO with NW.js. This includes a client-side HTML and JavaScript setup that connects to a local server, updates UI status and transport information, and emits events, along with a corresponding Node.js server implementation.

examples/nwjs-example · high confidence

Add NestJS example with WebSocket support

Added a new NestJS example project in the examples/nestjs-example directory. This example demonstrates a Node.js application using the NestJS framework, featuring a basic HTTP endpoint and a WebSocket gateway for real-time communication. It includes configuration for TypeScript, ESLint, Prettier, and the Nest CLI, along with unit and end-to-end tests, and a Handlebars view for the client-side socket interaction.

examples/nestjs-example · high confidence

Add Next.js examples with Socket.IO integration

Added two new example projects demonstrating Next.js applications with real-time Socket.IO connectivity: one using the App Router (\examples/nextjs-app-router\) and another using the Pages Router (\examples/nextjs-pages-router\). Both examples include a custom server setup with Socket.IO, client-side components that display connection status and transport type, and standard Next.js scaffolding files such as configuration, styles, and documentation.

examples/nextjs-app-router, examples/nextjs-pages-router · high confidence

Add Nuxt 4 example with Socket.IO WebSocket support

A new Nuxt 4 example has been added to the repository, demonstrating how to integrate Socket.IO for real-time communication. The example includes a client-side component that displays connection status and transport details, alongside a server-side Nitro plugin that binds the Socket.IO server to the Nitro engine to handle WebSocket connections. Configuration enables experimental WebSocket support in Nitro and sets a compatibility date of 2025-07-15.

examples/nuxt-example · high confidence

Add Socket.IO WebTransport example

Added a new example in the \examples/webtransport\ directory demonstrating how to use Socket.IO with the WebTransport protocol. The example includes a Node.js server (\index.js\) that initializes a Socket.IO server with WebTransport support and integrates with an HTTP/3 server (\@fails-components/webtransport\) to handle WebTransport sessions. It also provides client-side code (\index.html\) to connect using WebTransport, along with helper scripts (\generate\_cert.sh\, \open\_chrome.sh\) to generate self-signed certificates and launch Chrome with the necessary flags for testing.

(repo-wide) · high confidence

Add Socket.IO chat example with Traefik and Redis

Added a new example in the \examples/cluster-traefik\ directory demonstrating a Socket.IO chat application configured for clustering. This example uses Traefik as a reverse proxy with sticky sessions (via cookies) and Redis for inter-node communication, allowing users to scale the server to multiple instances using Docker Compose.

examples/cluster-traefik · high confidence

Add Socket.IO chat example with nginx load balancing

Added a new cluster-nginx example demonstrating a multi-node Socket.IO chat application. The example uses Docker Compose to orchestrate four Node.js server instances behind an nginx reverse proxy configured with ip\_hash for sticky sessions, and a Redis backend for cross-node message broadcasting. It includes a client container for testing load balancing and routing, along with the necessary Dockerfiles, nginx configuration, and frontend assets.

examples/cluster-nginx · high confidence

Add TypeScript client example for CommonJS and ESM builds

The examples/typescript-client-example directory now includes TypeScript source files and configuration for both CommonJS (cjs) and ES Module (esm) outputs. These new files provide a reference implementation for connecting to a Socket.IO server, demonstrating event handling and latency measurement, with specific tsconfig.json settings for each module system.

examples/typescript-client-example · high confidence

Add Webpack build example for Socket.IO client

A new example demonstrating how to bundle the Socket.IO client using Webpack has been added to the examples directory. This includes a sample HTML page, a JavaScript entry point connecting to a local server, a Webpack configuration file, and a README with usage instructions, providing a reference for users integrating Socket.IO into a Webpack-based project.

examples/webpack-build · high confidence

Add basic WebSocket-only Socket.IO client example

A new example project has been added at \examples/basic-websocket-client\ that demonstrates a minimal, WebSocket-only Socket.IO client implementation. This example includes the source code for a lightweight client (\src/index.js\) that handles the EIO 4 protocol over WebSockets, a pre-built minified bundle (\bundle/socket.io.min.js\), and a test suite (\test/index.js\) verifying connection, event emission, buffering, reconnection, and ping/pong behavior.

examples/basic-websocket-client · high confidence

Add cluster-engine examples for Node.js and Redis

Added example projects demonstrating the \@socket.io/cluster-engine\ package. The \examples/cluster-engine-node-cluster\ directory shows how to use \NodeClusterEngine\ with Node.js clusters to synchronize workers via IPC, removing the need for sticky sessions. The \examples/cluster-engine-redis\ directory demonstrates \RedisEngine\ for synchronizing multiple Socket.IO servers across distinct ports using Redis pub/sub, including a proxy setup for load balancing.

examples/cluster-engine-node-cluster, examples/cluster-engine-redis · high confidence

Add collaborative whiteboard example with touch support

A new Socket.IO collaborative whiteboard example has been added to the documentation. This demo allows multiple users to draw on a shared canvas in real-time and includes specific support for touch interactions on mobile devices, enabling drawing via touchstart, touchend, and touchmove events alongside standard mouse controls.

examples/whiteboard · high confidence

Add connection state recovery example

Added a new example demonstrating the connection state recovery feature, available in both CommonJS and ES module variants. The example includes server-side configuration for \connectionStateRecovery\ (setting \maxDisconnectionDuration\ and \skipMiddlewares\) and client-side logic to display connection status and recovery state, along with CodeSandbox and StackBlitz configurations for easy online testing.

examples/client-side-load-balancing-example, examples/connection-state-recovery-example · high confidence

Add custom parsers example

Added a new example demonstrating how to use custom parsers with Socket.IO, including implementations for msgpack, native JSON, and a custom schemapack-based parser, along with performance comparison results.

examples/custom-parsers · high confidence

Add example demonstrating Socket.IO clustering with PostgreSQL adapter

Added a new example in \examples/postgres-adapter-example\ that demonstrates how to set up a Socket.IO cluster using the \@socket.io/postgres-adapter\ for cross-process communication. The example includes a Docker Compose file to spin up a PostgreSQL 14 instance, a Node.js cluster script to launch multiple server instances, a server implementation that initializes the PostgreSQL adapter, and a client script to test the connection and message broadcasting.

examples/postgres-adapter-example · high confidence

Add express-session integration example

Added a new example demonstrating how to share session context between Express and Socket.IO using the express-session library. The example includes implementations in CommonJS (cjs), ES Modules (esm), and TypeScript (ts), showing how to attach the session middleware to the HTTP server and Socket.IO engine, join rooms based on session IDs, and handle session-based events like incrementing a counter and logging out.

examples/express-session-example · high confidence

Add httpd cluster example with Socket.IO and Redis

A new cluster example has been added to demonstrate a scalable Socket.IO chat application using Apache httpd as a load balancer. The setup includes four Node.js server instances (named John, Paul, George, and Ringo) connected to a shared Redis backend for cross-node message broadcasting. The httpd proxy is configured with sticky sessions via cookies to maintain WebSocket connections, and the example is containerized using Docker Compose v2 for easy local deployment.

examples/cluster-httpd · high confidence

Add server-side Socket.IO API for real-time CRUD operations

The server component of the basic CRUD example now implements a real-time backend using Socket.IO, replacing or supplementing previous HTTP-only interactions. This change introduces a new application structure that listens on port 3000, configures CORS for the Angular client at localhost:4200, and exposes WebSocket events for creating, reading, updating, and deleting todos. The implementation includes an in-memory repository for data persistence, input validation via Joi, and broadcast notifications to connected clients upon changes, providing a complete real-time synchronization layer for the example application.

examples/basic-crud-application/server · high confidence

Add server-side Webpack build example

Added a new example demonstrating how to bundle the Socket.IO server using Webpack. The example includes a Webpack 5 configuration targeting Node.js, a server entry point that manually serves the client distribution files, and documentation on optional native dependencies and client-serving behavior.

examples/webpack-build-server · high confidence

Added PM2 cluster example with sticky sessions

Added a new example in the \examples/pm2-example\ directory demonstrating how to run a Socket.IO application with PM2 in cluster mode. The example includes both a Node.js HTTP server entry point and a Fastify-based entry point, both configured to use the \@socket.io/cluster-adapter\ and \@socket.io/sticky\ to ensure sticky sessions across multiple worker instances. It also provides an HTML client that displays connection status, node ID, and transport information to verify the clustering behavior.

examples/pm2-example · high confidence

Added React Native example app with Socket.IO connectivity demo

A new React Native example application has been added to the repository, providing a complete, bootstrapped project for both Android and iOS platforms. The app demonstrates real-time connectivity by connecting to a Socket.IO server, displaying the current connection status and the active transport protocol (e.g., WebSocket) in the UI. The implementation includes native project configurations for Xcode and Android Studio, standard React Native tooling (Babel, ESLint, Prettier), and basic unit tests to verify the app renders correctly.

examples/ReactNativeExample, examples/ReactNativeExample/android, examples/expo-example · high confidence

Added TypeScript Socket.IO examples for CommonJS and ESM

The TypeScript example directory now includes ready-to-run client and server implementations using Socket.IO, provided in both CommonJS (cjs) and ES Module (esm) variants. Each variant contains a server that listens on port 8080 and a client that connects to it, demonstrating connection handling and a ping/pong latency measurement loop. Corresponding tsconfig.json files configure the TypeScript compiler for each module system (nodenext for CommonJS, node for ESM) targeting ES2022.

examples/typescript-example · high confidence

Added private messaging example with persistent sessions and Redis-backed scaling

The private messaging example now includes a complete implementation featuring persistent user sessions and message history. The server supports horizontal scaling via a Redis adapter and sticky sessions, while the frontend Vue application allows users to select a username, view online contacts, and exchange private messages with real-time updates.

examples/private-messaging · high confidence

Added server bundling example using Rollup

A new example located at examples/rollup-server-bundle demonstrates how to bundle a Socket.IO server using Rollup. The example includes a minimal entry point that initializes a server instance, a Rollup configuration that bundles the code into an ES module named bundle.js, and a .gitignore file to exclude the generated bundle from version control.

examples/rollup-server-bundle · high confidence

Added tweet-stream example using Socket.IO v4

A new example application has been added to the examples/tweet-stream directory that demonstrates real-time tweet streaming. The example uses the node-tweet-stream library to track specific keywords and broadcasts incoming tweets to connected clients via Socket.IO v4, including an initial buffer of recent tweets upon connection.

examples/tweet-stream · high confidence

Engine.IO core library and example applications added

The \packages/engine.io/lib\ directory now contains the full Engine.IO server implementation, including the main server and socket classes, polling and WebSocket transports (with uWebSockets.js support), WebTransport integration, and the v3/v4 packet parsers. This release also introduces new example applications for measuring latency and monitoring memory usage, including a specific WebTransport memory usage demo, alongside an ESM import example to demonstrate modern module usage.

packages/engine.io/lib · high confidence

Initial release of the Socket.IO chat example

The chat example is now available in the public directory, providing a complete client-side implementation for testing Socket.IO connections. The new files include an HTML page with login and chat interfaces, a JavaScript file handling real-time messaging, user typing indicators, and username color hashing, and a CSS stylesheet for layout and styling. This example demonstrates core features such as user authentication, message broadcasting, and input sanitization to prevent markup injection.

examples/chat/public · high confidence

Introduce cluster-ready adapter and in-memory adapter base classes

The socket.io-adapter package now exposes a new \ClusterAdapter\ abstract class and a \ClusterAdapterWithHeartbeat\ implementation, enabling Socket.IO servers to coordinate room state and broadcasts across multiple nodes in a cluster. This change introduces a new message protocol (defined by \MessageType\ and \ClusterMessage\) for inter-node communication, including heartbeat mechanisms and request/response handling for operations like fetching sockets and server-side emits. It also provides the foundational \Adapter\ and \SessionAwareAdapter\ classes in \in-memory-adapter.ts\ which handle local room management and socket tracking, serving as the base for both single-node and cluster deployments.

packages/socket.io-adapter/lib · high confidence

Introduce socket.io cluster engine for multi-node deployments

This release adds the \@socket.io/cluster-engine\ package, providing a clustering solution for Socket.IO servers running across multiple Node.js processes or machines. The package includes a \NodeClusterEngine\ that leverages the native \node:cluster\ module for inter-process communication, as well as a \RedisEngine\ that uses Redis Pub/Sub to coordinate state and message forwarding between nodes. It exports \setupPrimary\ and \setupPrimaryWithRedis\ helpers to configure the primary process, along with \ClusterEngineOptions\ for tuning timeouts and upgrade behaviors, enabling horizontal scaling of Socket.IO applications.

packages/socket.io-cluster-engine/lib · high confidence

Introducing the Redis Streams Emitter for cross-process Socket.IO communication

The new @socket.io/redis-streams-emitter package allows you to emit events, manage rooms, and perform server-side operations on a cluster of Socket.IO servers from an external Node.js process. By leveraging Redis Streams, this emitter works in conjunction with the @socket.io/redis-streams-adapter to broadcast messages, join or leave rooms, and trigger server-side events across multiple server instances. The package supports both standalone Redis and Redis clusters, and is compatible with both the 'redis' and 'ioredis' client libraries.

packages/socket.io-redis-streams-emitter · high confidence

New Passport.js authentication example for Socket.IO

Added a new example in the examples/passport-example directory demonstrating how to integrate Socket.IO with Passport.js for session-based authentication. The example includes implementations in CommonJS (cjs), ES Modules (esm), and TypeScript (ts), showing how to retrieve the authentication context from an Express application during the Socket.IO handshake and manage user sessions.

examples/passport-example · high confidence

New basic CRUD example with Angular, Vue, and Postgres-backed cluster server

The \examples/basic-crud-application\ directory now includes a complete reference implementation for a real-time TODO application. This example features an Angular v17 client and a Vue client, both connecting to a Socket.IO server. The server side now offers two deployment options: a standard in-memory TypeScript server and a new JavaScript-based server configured for clustering using \@socket.io/sticky\ and \@socket.io/postgres-adapter\ with a Postgres database.

examples/basic-crud-application · high confidence

New example demonstrating Socket.IO authentication with JWT and Passport

Added a new example in the \examples/passport-jwt-example\ directory that shows how to integrate Socket.IO with Express and Passport using JSON Web Tokens (JWT). The example includes implementations in CommonJS (\cjs/\), ES Modules (\esm/\), and TypeScript (\ts/\), along with a shared HTML client. It demonstrates sending the JWT in the \authorization\ header during the Socket.IO handshake and retrieving the user context on the server side.

examples/passport-jwt-example · high confidence

Socket.IO client library rewritten in TypeScript

The Socket.IO client source code in \packages/socket.io-client/lib\ has been completely rewritten in TypeScript, replacing the previous implementation. This change introduces a new, type-safe architecture with dedicated modules for the main entry point (\browser-entrypoint.ts\, \index.ts\), connection management (\manager.ts\), socket handling (\socket.ts\), and URL parsing (\url.ts\). It also includes a new backoff utility (\contrib/backo2.ts\) and a helper for event subscription (\on.ts\). For users, this means the client now provides full TypeScript definitions out of the box, improving developer experience and type safety when integrating Socket.IO into TypeScript projects, while maintaining the same public API surface (\io()\, \Socket\, \Manager\, etc.).

packages/socket.io-client/lib · high confidence

Socket.IO component-emitter package added to monorepo

The \@socket.io/component-emitter\ package has been introduced as a new module within the project structure, providing the core event emitter functionality used by Socket.IO. This addition includes the CommonJS and ES module implementations of the \Emitter\ class, along with comprehensive TypeScript type definitions that support typed event maps and reserved events. The package also brings its own test suite, documentation, and changelog, establishing it as a distinct, self-contained component for event handling within the broader Socket.IO ecosystem.

packages/socket.io-component-emitter · high confidence

Removals

Removal of legacy MooTools-based utility modules

The library has removed several legacy utility modules (\array\, \events\, \json\, \object\, \options\, and the base \util\ namespace) that were previously based on MooTools. This cleanup eliminates external dependencies on the MooTools codebase and simplifies the internal utility structure, likely as part of a broader effort to reduce code size and remove deprecated patterns.

lib/util · high confidence

Removed legacy Socket.IO client implementation

The legacy client-side Socket.IO library (versions prior to 1.0) has been removed from the \lib\ directory. This change deletes \lib/io.js\, \lib/socket.js\, and \lib/transport.js\, eliminating the old \io.Socket\ API, the abstract \io.Transport\ class, and the global \jQuery.io\ integration. Users relying on this legacy client code will no longer have access to these components.

lib · high confidence

Removed legacy browser transports (Flash, HTMLFile, Server-Events, XHR variants)

The \lib/transports\ directory has removed the implementation files for FlashSocket, HTMLFile, Server-Events, XHR-Multipart, XHR-Polling, and the base XHR transport. This eliminates support for legacy fallback mechanisms such as Flash-based connections, IE-specific HTMLFile framing, and older XHR polling strategies, effectively narrowing the client's transport capabilities to modern standards (primarily WebSocket) and requiring server-side or client-side configuration to handle environments that previously relied on these deprecated transports.

lib/transports · high confidence

Removed vendor submodules for LABjs, js-oo, and web-socket-js

The vendor directory no longer includes the LABjs, js-oo, and web-socket-js libraries as Git submodules. These external dependencies have been removed from the repository structure, which may require users to source these libraries from alternative locations or remove references to them in their build processes.

lib/vendor · high confidence

Security

Engine.IO client v6.6.7 release with security and bug fixes

This release updates the Engine.IO client to version 6.6.7, addressing security vulnerabilities in the underlying \ws\ dependency by bumping it to version \~8.21.0 (fixing [CVE redacted]). It also includes bug fixes such as restoring default transport resolution, exporting reserved event interfaces for TypeScript users, and preserving transport literal suggestions. The package now includes a dedicated \.gitignore\ and \.prettierignore\ for the local directory, and the changelog reflects these changes alongside the dependency updates.

packages/engine.io-client · high confidence

Fix SQL injection vulnerability in PostgreSQL NOTIFY command

The @socket.io/postgres-emitter package now uses parameterized queries when sending the PostgreSQL NOTIFY command, preventing potential SQL injection attacks that could occur if event data was previously interpolated directly into the SQL string. This change ensures that all data passed through the emitter is safely escaped before being sent to the database.

packages/socket.io-postgres-emitter · high confidence

Behavioural changes

Engine.IO package structure and configuration added

The engine.io package now includes its core configuration files, establishing the build and linting setup. This adds a TypeScript configuration targeting ES2018 (Node.js 10) with CommonJS output, an ESLint configuration extending Prettier, and a Prettier ignore rule for the parser-v3 directory. Additionally, a wrapper module is introduced to export the main Engine.IO classes and utilities (Server, Socket, Transport, etc.) from the built output, alongside the standard LICENSE and README documentation.

packages/engine.io · high confidence

Engine.io-client library rewritten in TypeScript with platform-specific entry points

The engine.io-client library has been rewritten in TypeScript, introducing separate entry points for browser and Node.js environments (browser-entrypoint.ts, globals.node.ts) to handle platform-specific globals and cookie management. This refactor improves type safety and transport resolution, ensuring that the 'offline' event listener is registered early for Service Worker compatibility and that transport options are not mutated by the client.

packages/engine.io-client/lib · high confidence

Engine.io-parser refactored with platform-specific modules and new stream APIs

The engine.io-parser library has been restructured to support both Node.js and browser environments by introducing separate implementation files (e.g., \decodePacket.browser.ts\, \encodePacket.browser.ts\) alongside their Node.js counterparts. This change includes the addition of \createPacketEncoderStream\ and \createPacketDecoderStream\ functions, which expose \TransformStream\-based APIs for streaming packet encoding and decoding. The parser now also includes a dedicated base64-arraybuffer utility for browser environments and updates the internal packet type definitions and binary mapping logic to handle \Blob\, \ArrayBuffer\, and \Buffer\ types more robustly across platforms.

packages/engine.io-parser/lib · high confidence

New build and bundle-size measurement tooling for engine.io-client

The engine.io-client package now includes a dedicated support directory containing configuration files and scripts to standardize its build process. This adds Rollup configurations for generating ESM and UMD bundles, a Webpack configuration for development builds, and a script to measure the compressed size of the resulting distribution files. These changes establish the infrastructure for consistent bundling and size tracking, preparing the package for monorepo integration.

packages/engine.io-client/support · high confidence

New build infrastructure and bundle-size reporting for Socket.IO client

The Socket.IO client now includes a dedicated support directory that establishes the build pipeline for generating UMD, ESM, and MsgPack bundles, alongside a new script to report their compressed sizes. The build configuration ensures that private properties starting with an underscore are mangled during minification to reduce bundle size, while explicitly reserving the '\_placeholder' property to prevent breakage. Additionally, the UMD build now uses Babel's loose mode for class transformation and the @rollup/plugin-terser plugin for minification.

packages/socket.io-client/support · high confidence

Refactored transport layer to support multiple runtimes and new protocols

The transport implementation in engine.io-client has been restructured to explicitly support Node.js, Deno, and Bun alongside browsers. Long-polling now offers two backends: a new Fetch-based transport for modern environments and an XMLHttpRequest-based transport (using the xmlhttprequest-ssl package) for Node.js. WebSocket support is split into a built-in implementation for browsers and Node.js v21+, and a separate implementation using the ws package for older Node.js versions. Additionally, a new WebTransport transport has been added for environments that support it.

packages/engine.io-client/lib/transports · high confidence

Socket.IO client v4.8.4 release with TypeScript type exports and dependency updates

The socket.io-client package has been updated to version 4.8.4. This release addresses TypeScript type definitions by exporting the ExtendedError interface for the connect\_error event and exporting reserved event interfaces, improving type safety for consumers. It also updates the ws dependency to version \~8.21.0. Additionally, the package structure now includes a CHANGELOG.md documenting version history and bundle sizes, a .prettierignore file to exclude lib/contrib files from formatting, and standardized MIT license text.

packages/socket.io-client · high confidence

Socket.IO cluster adapter refactored to delegate logic to socket.io-adapter

The \@socket.io/cluster-adapter\ package has been refactored to version 0.3.0, moving the core adapter logic into the \ClusterAdapter\ class of the \socket.io-adapter\ package. This change simplifies the cluster adapter implementation by inheriting from \ClusterAdapterWithHeartbeat\ and is part of the migration to the \socket.io\ monorepo. Users should ensure they are using compatible versions of \socket.io\ and \socket.io-adapter\ to maintain cluster broadcasting functionality.

packages/socket.io-cluster-adapter · high confidence

Socket.IO package structure and documentation restored

The \packages/socket.io\ directory has been restructured to include the core package assets, including a comprehensive changelog covering versions 2.x through 4.8.4, an MIT license file, release instructions, and an updated README. The package now exports \Server\, \Namespace\, and \Socket\ via a new \wrapper.mjs\ entry point and uses a TypeScript configuration targeting ES2017. This change restores the standalone package location within the monorepo, ensuring users have access to the full library documentation and correct module exports.

packages/socket.io · high confidence

Socket.IO v5 core library rewritten in TypeScript with new broadcast and connection APIs

The \packages/socket.io/lib\ directory has been completely rewritten in TypeScript, introducing a new \BroadcastOperator\ class that enables fluent, chainable room targeting (e.g., \io.to('room').emit()\) and modifiers like \volatile\, \local\, and \timeout\. The internal connection handling is now managed by a dedicated \Client\ class, while the \Server\ and \Namespace\ classes have been restructured to support dynamic namespaces via \ParentNamespace\ and improved connection state recovery. Additionally, the library now includes an internalized \base64id\ generator and a specialized \uws\ module that patches the adapter to use uWebSockets.js topics for efficient WebSocket broadcasting.

packages/socket.io/lib · high confidence

engine.io-parser v5.2.3 release and monorepo preparation

This change introduces engine.io-parser version 5.2.3, which includes a bug fix to prevent the exposure of the internal TransformStream type. The package structure has been refactored to support migration to a monorepo, evidenced by the addition of separate TypeScript configurations for CommonJS and ESM builds, a post-compilation script to handle package metadata, and a new .prettierignore file. Documentation, licensing, and benchmarking tools have also been added to the package root.

packages/engine.io-parser · high confidence

socket.io-parser v4.2.7: Binary packet safety and toJSON() support

The socket.io-parser library has been updated to version 4.2.7, introducing two key behavioral changes for binary data handling. First, the parser now strictly rejects binary packets that declare attachments but contain zero actual binary buffers, preventing potential parsing errors or undefined behavior. Second, when deconstructing packets for encoding, the parser now respects the \toJSON()\ method on custom objects, ensuring that binary data nested within such objects is correctly identified and processed rather than being ignored or mishandled.

packages/socket.io-parser · high confidence

Fixes

Export reserved event interfaces to fix TypeScript declaration emit

The \SocketReservedEvents\, \ManagerReservedEvents\, \TransportReservedEvents\, and related type maps are now exported from the public types. This resolves a TypeScript declaration emit failure (ts(4023)) that occurred when consuming public APIs like \socket.listeners\ or \engine.write\, as their inferred types previously referenced these internal maps which were not accessible during declaration generation.

examples/typescript-check-public-exports · high confidence

Test coverage

Added SSL certificate fixtures and generation script for engine.io tests; Added browser and Node.js-specific test suites for engine.io-parser; Added comprehensive test suite for Socket.IO client; Added comprehensive test suite for Socket.IO server; Added test suite for Engine.IO server; Added test suite for socket.io-adapter; Expanded test coverage for engine.io-client binary handling and connection behavior; Initial test suite for socket.io-cluster-engine; Removed legacy browser test runner.

Dependencies

Add lockfile for the Engine.IO protocol v3 test suite

A new \package-lock.json\ file has been added for the \docs/engine.io-protocol/v3-test-suite\ directory, pinning the versions of its development dependencies (including \mocha\, \chai\, \ws\, and \node-fetch\) to ensure reproducible test environments.

(dependencies) · high confidence

Socket.IO client library updated to version 4.8.4

The bundled client-side JavaScript for Socket.IO has been updated to version 4.8.4. This release includes the latest engine.io-client and socket.io-parser implementations, ensuring compatibility with the corresponding server-side updates and providing any bug fixes or performance improvements included in the 4.8.x series.

packages/socket.io/client-dist · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 35 → 57 (+22.5)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.16) — scores are not directly comparable.

Lenses

  • Code Health 54 → 71 (+17.3)
  • Architecture 90 → 93 (+3.2)
  • Maturity 58 → 75 (+17.4)
  • Readiness 14 → 50 (+35.5)
  • Security 46 → 58 (+11.3)
  • Domain Modelling 100 (new)
  • Performance 60 (new)

Resolved (131)

  • (anonymous) (cognitive 24) (packages/socket.io/client-dist/socket.io.js)
  • (anonymous) (cyclomatic 22) (packages/socket.io/client-dist/socket.io.js)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Dimension evaluation failed
  • FileTooLong: client-dist/socket.io.js (packages/socket.io/client-dist/socket.io.js)
  • FileTooLong: test/server.js (packages/engine.io/test/server.js)
  • FileTooLong: test/webtransport.mjs (packages/engine.io/test/webtransport.mjs)
  • FileTooLong: v5-test-suite/test-suite.js (docs/socket.io-protocol/v5-test-suite/test-suite.js)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • …and 111 more

New (385)

  • Adapter.apply (cognitive 27) (packages/socket.io-adapter/lib/in-memory-adapter.ts)
  • BaseServer.verify (cognitive 21) (packages/engine.io/lib/server.ts)
  • ClassTooLong: Socket (packages/engine.io-client/lib/socket.ts)
  • ClusterAdapter.onMessage (cyclomatic 16) (packages/socket.io-adapter/lib/cluster-adapter.ts)
  • ClusterEngine.onMessage (cognitive 38) (packages/socket.io-cluster-engine/lib/engine.ts)
  • ClusterEngine.onMessage (cyclomatic 29) (packages/socket.io-cluster-engine/lib/engine.ts)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Decoder.add (cognitive 16) (packages/socket.io-parser/lib/index.ts)
  • Decoder.decodeString (cognitive 38) (packages/socket.io-parser/lib/index.ts)
  • Decoder.decodeString (cyclomatic 23) (packages/socket.io-parser/lib/index.ts)
  • Documentation: no project overview (examples/nestjs-example/README.md)
  • FileTooLong: lib/cluster-adapter.ts (packages/socket.io-adapter/lib/cluster-adapter.ts)
  • FileTooLong: lib/server.ts (packages/engine.io/lib/server.ts)
  • FileTooLong: lib/socket.ts (packages/engine.io-client/lib/socket.ts)
  • FixmeComment (packages/engine.io/lib/userver.ts)
  • FixmeComment (packages/engine.io/lib/userver.ts)
  • FixmeComment (packages/socket.io-client/lib/socket.ts)
  • FixmeComment (packages/socket.io-redis-streams-emitter/lib/index.ts)
  • FixmeComment (packages/socket.io/lib/socket.ts)
  • …and 365 more

Changes since last survey

  • 35 commits — 23 feature/other, 12 fixes

By area

  • packages/socket.io-cluster-engine — 10 commits
  • packages/engine.io — 9 commits
  • packages/socket.io — 5 commits
  • (root) — 3 commits
  • packages/engine.io-client — 3 commits
  • packages/socket.io-client — 2 commits
  • docs/socket.io-protocol — 1 commit
  • examples/create-react-app-example — 1 commit
  • examples/typescript-check-public-exports — 1 commit

Notable commits

  • fix: fix(cluster-engine): guard client lookups against prototype pollution
  • fix: fix(cluster-engine): properly export options
  • fix: fix(cluster-engine): properly handle upgrade failures
  • fix: fix(cluster-engine): skip side effects when lock acquisition fails
  • fix: fix(eio): refresh ping timeout on incoming packets
  • fix: fix(eio): reject protocol mismatch for existing sessions
  • fix: fix(eio): run the polling write callback when the client aborts a compressed response (#5540)
  • fix: fix(eio-client): restore default transport resolution
  • fix: fix(eio-client/types): export reserved event interfaces (#5533)
  • fix: fix(sio): reject stateful regexps for dynamic namespaces
  • fix: fix(sio-client/types): export ExtendedError for connect_error event (#5548)
  • fix: fix(sio-client/types): export reserved event interfaces (#5533)
  • change: chore(release): @socket.io/cluster-engine@0.1.1
  • change: chore(release): engine.io-client@6.6.7
  • change: chore(release): engine.io@6.6.10
  • change: chore(release): engine.io@6.6.11
  • change: chore(release): socket.io-client@4.8.4
  • change: chore(release): socket.io@4.8.4
  • change: chore: use @rollup/plugin-terser instead of rollup-plugin-terser
  • change: docs(cluster-engine): add sequence diagrams
  • …and 15 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

socketio/socket.io was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit deee824c0e480c7590b74797e33d45a7ad993880 — the exact code this score is about.
  • Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-eb9197011364.