Skip to content
CAI
Software that uses CAICheck a score

walkor/workerman

64.1

Adequate · 22 September 2026

11.1k

lines of production code

PHP

primary language

7

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a high-performance, asynchronous PHP networking framework designed for building TCP, UDP, HTTP, and WebSocket servers. It provides a modernized core with strict protocol validation, coroutine-aware timers, and multiple event loop backends to handle concurrent connections efficiently. The library includes built-in support for session management, secure WebSocket framing, and comprehensive testing utilities to ensure reliability.

How it got here

2013 — Legacy cleanup and test scaffolding

8 changes.

This period focused on removing legacy PHP-based components, including the old worker, event-loop, protocol parsers, and utility libraries, to streamline the codebase. Concurrently, the project established foundational configuration and introduced a comprehensive test suite for core protocols and connections using modern tools.

2014–2023 — Modern PHP 8+ migration and protocol hardening

8 changes.

The project underwent a comprehensive modernization to support PHP 8.1+, introducing strict typing, new event loop drivers, and enhanced coroutine support. Significant efforts were made to harden protocol implementations, particularly for HTTP and WebSocket, ensuring strict RFC compliance and improved security. The update also expanded functionality with new session handlers and refined core worker and timer components.

Features

Initial project scaffolding and configuration

This change introduces the foundational configuration files for the Workerman project, including .gitattributes and .gitignore to manage repository artifacts, a MIT-LICENSE.txt file for licensing, and a SECURITY.md for vulnerability reporting. It also adds phpstan.neon.dist for static analysis configuration and phpunit.xml.dist for test suite execution, alongside a comprehensive README.md documenting installation, basic usage for HTTP/WebSocket/TCP servers, SSL support, and coroutine examples.

(repo-wide) · high confidence

New event loop implementations for Ev, libevent, Revolt, and Swow

Added new event loop drivers for the Ev extension, libevent, the Revolt EventLoop (via the Fiber class), and the Swow coroutine library. These classes implement the EventInterface, providing users with additional backend options for handling timers, stream I/O, and signals alongside the existing Select and Swoole drivers.

src/Events · high confidence

New file-based and Redis-backed HTTP session handlers

The \src/Protocols/Http/Session\ directory now includes new session handler implementations: \FileSessionHandler\ for storing sessions in the local file system, and \RedisSessionHandler\ and \RedisClusterSessionHandler\ for storing sessions in Redis or Redis Cluster. These handlers implement the new \SessionHandlerInterface\ and provide configurable options for save paths, connection details, timeouts, and prefixes, allowing users to persist HTTP sessions using either local files or distributed Redis storage.

src/Protocols/Http/Session · high confidence

Removals

Removal of UDP-based statistic reporting client

The StatisticClient class, which previously handled the collection and UDP transmission of interface call statistics (including latency, success rates, and error codes) to a monitoring process, has been removed. Users will no longer have this specific UDP-based telemetry capability available in the Clients module.

Clients · high confidence

Removal of core environment checking, configuration, logging, and task scheduling libraries

The \Checker\, \Config\, \Log\, and \Task\ classes in \Core/Lib\ have been removed. This eliminates the built-in capabilities for validating PHP extensions and worker configurations, loading INI-based application settings, handling error logging and directory permissions, and executing scheduled background tasks. Users relying on these specific utility classes for server startup validation, configuration management, logging, or cron-like functionality will no longer have access to these features within this library.

Core/Lib · high confidence

Removal of legacy Core worker and event-loop components

The Core module has removed the legacy worker and event-loop implementation files, including AbstractWorker, SocketWorker, Master, and the event-loop classes (Select, Libevent) along with their BaseEvent interface. This eliminates the old PHP-based process management and event-loop architecture from the codebase.

Core · high confidence

Removal of legacy internal worker classes

The Workers directory has been cleaned up by deleting several internal utility and monitoring classes: BufferWorker, EchoWorker, FileMonitor, Monitor, StatisticService, and StatisticWorker. These files, which previously handled stress testing, file change monitoring, process supervision, and statistical logging, are no longer part of the codebase.

Workers · high confidence

Removal of legacy protocol parsers

The Protocols directory has removed several legacy protocol implementation files: Buffer, FastCGI, HTTP, SimpleFastCgi, SimpleHttp, and the IProtocol interface. These files are no longer part of the codebase, meaning any code relying on these specific protocol handlers for parsing or encoding network data will need to be updated to use alternative implementations.

Protocols · high confidence

Removal of the bin/workermand PHP server management script

The \bin/workermand\ executable, which previously provided command-line management for the PHP-Server (including start, stop, restart, reload, kill, and status operations), has been removed from the repository. Users can no longer use this specific script to control the server lifecycle via the \serverd\ commands.

bin · high confidence

Behavioural changes

HTTP protocol layer rewritten for modern PHP and chunked transfer support

The HTTP protocol implementation in src/Protocols/Http has been completely rewritten to support modern PHP features and stricter standards. The new Request class now handles HTTP/1.1 chunked transfer encoding (including trailers) and uploads of empty files, while the Response class no longer includes the default Server header and supports the AVIF image MIME type. A new Chunk class manages chunked data formatting, and the Session component now supports the igbinary serializer. These changes improve performance, compatibility with PHP 8.4, and adherence to HTTP specifications.

src/Protocols/Http · high confidence

New Frame protocol and stricter HTTP/WebSocket validation

The src/Protocols area introduces a new Frame protocol (src/Protocols/Frame.php) for simple length-prefixed framing, alongside a new ProtocolInterface (src/Protocols/ProtocolInterface.php) and Text protocol (src/Protocols/Text.php). HTTP handling (src/Protocols/Http.php) is significantly stricter: it enforces RFC 9112 request-line syntax, requires a single Host header for HTTP/1.1, validates header field names, rejects invalid Transfer-Encoding/Content-Length combinations, and returns 431 for oversized headers. WebSocket server (src/Protocols/Websocket.php) and client (src/Protocols/Ws.php) implementations now enforce RFC 6455 framing rules, validate rsv bits, limit handshake header size, and manage fragmented messages and permessage-deflate with decompression-bomb safeguards.

src/Protocols · high confidence

Refactored connection classes with strict typing and modern PHP features

The connection classes in src/Connection have been rewritten to use PHP 8+ features, including strict types, property promotion, and explicit return types. This improves code clarity and performance. Key changes include the addition of an AsyncTcpConnection class with proxy support (Socks5 and HTTP), an AsyncUdpConnection class, and a ConnectionInterface with updated statistics tracking. The TcpConnection class now includes WebSocket-specific callbacks and constants, while UdpConnection handles connected socket nuances. These changes enhance type safety and maintainability across the connection layer.

src/Connection · high confidence

Workerman 5.2.2 release with timer and worker improvements

This update introduces Workerman version 5.2.2, bringing significant enhancements to the core Worker and Timer components. The Timer class now supports coroutine-aware sleeping via the new \sleep()\ method, which integrates with Fiber and Swoole event loops for non-blocking delays. Worker process management has been refined with better handling of worker start/exit lifecycle events, improved signal handling for ALARM signals, and optimizations to the task scheduling logic. Additionally, the release includes fixes for Windows-specific issues, such as preventing hangs on the first request and ensuring proper PID file handling, while also improving compatibility with PHP 8.4 through explicit nullable type declarations.

src · high confidence

Test coverage

Added stub server and client scripts for HTTP, UDP, and WebSocket testing; Comprehensive test suite for Workerman protocols and connections.

Dependencies

Initial composer.json with PHP 8.1+ requirement and modern dev dependencies

The project now includes a composer.json file that establishes PHP 8.1 as the minimum runtime version and introduces a suite of development tools: Pest 2/3/4 for testing, Mockery 1.6.12 for mocking, Guzzle 7.10 for HTTP client operations, and PHPStan 2.1 for static analysis. The package defines PSR-4 autoloading for the main library under the Workerman namespace and for tests under the Tests namespace, while also declaring a conflict with ext-swow versions prior to 1.0.0 and suggesting the ext-event extension for improved performance.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 65 → 64 (-0.8)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 68 → 80 (+11.6)
  • Architecture 100 → 85 (-14.7)
  • Maturity 56 → 57 (+1.0)
  • Readiness 63 → 57 (-6.7)
  • Security 100 → 100 (+0.0)

Resolved (18)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 3) (src/Connection/AsyncTcpConnection.php)
  • Duplicated block (11 lines × 2) (src/Protocols/Websocket.php)
  • Duplicated block (12 lines × 2) (src/Protocols/Websocket.php)
  • Duplicated block (12 lines × 2) (src/Protocols/Websocket.php)
  • Duplicated block (13 lines × 2) (src/Worker.php)
  • Duplicated block (14 lines × 2) (src/Protocols/Websocket.php)
  • Duplicated block (17 lines × 2) (src/Protocols/Http/Response.php)
  • Duplicated block (17 lines × 2) (src/Protocols/Websocket.php)
  • Duplicated block (6 lines × 2) (src/Connection/AsyncTcpConnection.php)
  • Duplicated block (7 lines × 2) (src/Protocols/Ws.php)
  • Duplicated block (9 lines × 2) (src/Connection/AsyncTcpConnection.php)
  • Hotspot: src/Protocols/Http.php (src/Protocols/Http.php)
  • No exposed public API
  • Off-boarding risk: anonymized user #1
  • Test reliability not included
  • The 'Basic Usage' section only covers a single protocol (WebSocket) and omits other supported transports like HTTP, TCP, and SSL with code examples. (README.md)

New (43)

  • ClassTooLong: TcpConnection (src/Connection/TcpConnection.php)
  • ClassTooLong: Worker (src/Worker.php)
  • Dependency hygiene PARTLY measured — Composer dependencies read, no committed lock to grade for currency
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (11 lines × 2) (src/Connection/AsyncTcpConnection.php)
  • Duplicated block (11 lines × 3) (src/Connection/AsyncTcpConnection.php)
  • Duplicated block (12–13 lines × 2) (src/Protocols/Websocket.php)
  • Duplicated block (16 lines × 2) (src/Protocols/Websocket.php)
  • Duplicated block (19 lines × 2) (src/Protocols/Websocket.php)
  • Duplicated block (20–21 lines × 2) (src/Protocols/Websocket.php)
  • Duplicated block (22–24 lines × 2) (src/Protocols/Websocket.php)
  • Duplicated block (24 lines × 2) (src/Worker.php)
  • Duplicated block (27 lines × 2) (src/Protocols/Http/Response.php)
  • Duplicated block (37 lines × 2) (src/Protocols/Websocket.php)
  • Duplicated block (6 lines × 2) (src/Connection/AsyncTcpConnection.php)
  • Duplicated block (6 lines × 2) (src/Connection/TcpConnection.php)
  • Duplicated block (6 lines × 2) (src/Connection/TcpConnection.php)
  • Duplicated block (6 lines × 2) (src/Protocols/Ws.php)
  • Duplicated block (6 lines × 3) (src/Events/Ev.php)
  • …and 23 more

Changes since last survey

  • 16 commits — 5 feature/other, 11 fixes

By area

  • src/Worker.php — 7 commits
  • (repo) — 3 commits
  • src/Connection — 2 commits
  • tests/Unit — 2 commits
  • src/Events — 1 commit
  • src/Timer.php — 1 commit

Notable commits

  • fix: Merge pull request #1166 from Tinywan/fix-embed-sapi-and-strict-callbacks
  • fix: Merge pull request #1167 from Tinywan/fix-select-onsignal-closure-argument
  • fix: fix(select): allow variable arguments in onSignal closure to accept pcntl_signal arguments
  • fix: fix(worker): accept variable arguments in checkErrors
  • fix: fix(worker): allow variable arguments in ob_start output handler
  • fix: fix(worker): avoid assigning null to resource-typed outputStream
  • fix: fix(worker): safely check and close stream resources in resetStd to fix daemon mode crash
  • fix: fix(worker): wrap register_shutdown_function unlink in closure to prevent signature mismatch
  • fix: fix(worker,tcp): allow variable arguments in set_error_handler callbacks
  • fix: fix(worker,timer): allow variable arguments in signal handlers to prevent ArgumentCountError with pcntl_signal
  • fix: fix: improve PHP 8 strict callback compatibility, visibility, and allow embed SAPI
  • change: Change spl_object_hash() for spl_object_id()
  • change: Improve SSL and WebSocket handling
  • change: Merge pull request #1164 from joanhey/patch-3
  • change: Update Worker::getId() to use int
  • change: tests

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

walkor/workerman was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit a64a81b53231d5133e3869898a46c2953f9db593 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.