walkor/workerman
64.1
Adequate · 22 September 2026
11.1k
lines of production code
PHP
primary language
7
measurements over time
What this system is
This system is a high-performance, asynchronous PHP networking framework designed for building TCP, UDP, HTTP, and WebSocket servers. It provides a modernized core with strict protocol validation, coroutine-aware timers, and multiple event loop backends to handle concurrent connections efficiently. The library includes built-in support for session management, secure WebSocket framing, and comprehensive testing utilities to ensure reliability.
How it got here
2013 — Legacy cleanup and test scaffolding
8 changes.
This period focused on removing legacy PHP-based components, including the old worker, event-loop, protocol parsers, and utility libraries, to streamline the codebase. Concurrently, the project established foundational configuration and introduced a comprehensive test suite for core protocols and connections using modern tools.
2014–2023 — Modern PHP 8+ migration and protocol hardening
8 changes.
The project underwent a comprehensive modernization to support PHP 8.1+, introducing strict typing, new event loop drivers, and enhanced coroutine support. Significant efforts were made to harden protocol implementations, particularly for HTTP and WebSocket, ensuring strict RFC compliance and improved security. The update also expanded functionality with new session handlers and refined core worker and timer components.
Features
Initial project scaffolding and configuration
This change introduces the foundational configuration files for the Workerman project, including .gitattributes and .gitignore to manage repository artifacts, a MIT-LICENSE.txt file for licensing, and a SECURITY.md for vulnerability reporting. It also adds phpstan.neon.dist for static analysis configuration and phpunit.xml.dist for test suite execution, alongside a comprehensive README.md documenting installation, basic usage for HTTP/WebSocket/TCP servers, SSL support, and coroutine examples.
(repo-wide) · high confidence
New event loop implementations for Ev, libevent, Revolt, and Swow
Added new event loop drivers for the Ev extension, libevent, the Revolt EventLoop (via the Fiber class), and the Swow coroutine library. These classes implement the EventInterface, providing users with additional backend options for handling timers, stream I/O, and signals alongside the existing Select and Swoole drivers.
src/Events · high confidence
New file-based and Redis-backed HTTP session handlers
The \src/Protocols/Http/Session\ directory now includes new session handler implementations: \FileSessionHandler\ for storing sessions in the local file system, and \RedisSessionHandler\ and \RedisClusterSessionHandler\ for storing sessions in Redis or Redis Cluster. These handlers implement the new \SessionHandlerInterface\ and provide configurable options for save paths, connection details, timeouts, and prefixes, allowing users to persist HTTP sessions using either local files or distributed Redis storage.
src/Protocols/Http/Session · high confidence
Removals
Removal of UDP-based statistic reporting client
The StatisticClient class, which previously handled the collection and UDP transmission of interface call statistics (including latency, success rates, and error codes) to a monitoring process, has been removed. Users will no longer have this specific UDP-based telemetry capability available in the Clients module.
Clients · high confidence
Removal of core environment checking, configuration, logging, and task scheduling libraries
The \Checker\, \Config\, \Log\, and \Task\ classes in \Core/Lib\ have been removed. This eliminates the built-in capabilities for validating PHP extensions and worker configurations, loading INI-based application settings, handling error logging and directory permissions, and executing scheduled background tasks. Users relying on these specific utility classes for server startup validation, configuration management, logging, or cron-like functionality will no longer have access to these features within this library.
Core/Lib · high confidence
Removal of legacy Core worker and event-loop components
The Core module has removed the legacy worker and event-loop implementation files, including AbstractWorker, SocketWorker, Master, and the event-loop classes (Select, Libevent) along with their BaseEvent interface. This eliminates the old PHP-based process management and event-loop architecture from the codebase.
Core · high confidence
Removal of legacy internal worker classes
The Workers directory has been cleaned up by deleting several internal utility and monitoring classes: BufferWorker, EchoWorker, FileMonitor, Monitor, StatisticService, and StatisticWorker. These files, which previously handled stress testing, file change monitoring, process supervision, and statistical logging, are no longer part of the codebase.
Workers · high confidence
Removal of legacy protocol parsers
The Protocols directory has removed several legacy protocol implementation files: Buffer, FastCGI, HTTP, SimpleFastCgi, SimpleHttp, and the IProtocol interface. These files are no longer part of the codebase, meaning any code relying on these specific protocol handlers for parsing or encoding network data will need to be updated to use alternative implementations.
Protocols · high confidence
Removal of the bin/workermand PHP server management script
The \bin/workermand\ executable, which previously provided command-line management for the PHP-Server (including start, stop, restart, reload, kill, and status operations), has been removed from the repository. Users can no longer use this specific script to control the server lifecycle via the \serverd\ commands.
bin · high confidence
Behavioural changes
HTTP protocol layer rewritten for modern PHP and chunked transfer support
The HTTP protocol implementation in src/Protocols/Http has been completely rewritten to support modern PHP features and stricter standards. The new Request class now handles HTTP/1.1 chunked transfer encoding (including trailers) and uploads of empty files, while the Response class no longer includes the default Server header and supports the AVIF image MIME type. A new Chunk class manages chunked data formatting, and the Session component now supports the igbinary serializer. These changes improve performance, compatibility with PHP 8.4, and adherence to HTTP specifications.
src/Protocols/Http · high confidence
New Frame protocol and stricter HTTP/WebSocket validation
The src/Protocols area introduces a new Frame protocol (src/Protocols/Frame.php) for simple length-prefixed framing, alongside a new ProtocolInterface (src/Protocols/ProtocolInterface.php) and Text protocol (src/Protocols/Text.php). HTTP handling (src/Protocols/Http.php) is significantly stricter: it enforces RFC 9112 request-line syntax, requires a single Host header for HTTP/1.1, validates header field names, rejects invalid Transfer-Encoding/Content-Length combinations, and returns 431 for oversized headers. WebSocket server (src/Protocols/Websocket.php) and client (src/Protocols/Ws.php) implementations now enforce RFC 6455 framing rules, validate rsv bits, limit handshake header size, and manage fragmented messages and permessage-deflate with decompression-bomb safeguards.
src/Protocols · high confidence
Refactored connection classes with strict typing and modern PHP features
The connection classes in src/Connection have been rewritten to use PHP 8+ features, including strict types, property promotion, and explicit return types. This improves code clarity and performance. Key changes include the addition of an AsyncTcpConnection class with proxy support (Socks5 and HTTP), an AsyncUdpConnection class, and a ConnectionInterface with updated statistics tracking. The TcpConnection class now includes WebSocket-specific callbacks and constants, while UdpConnection handles connected socket nuances. These changes enhance type safety and maintainability across the connection layer.
src/Connection · high confidence
Workerman 5.2.2 release with timer and worker improvements
This update introduces Workerman version 5.2.2, bringing significant enhancements to the core Worker and Timer components. The Timer class now supports coroutine-aware sleeping via the new \sleep()\ method, which integrates with Fiber and Swoole event loops for non-blocking delays. Worker process management has been refined with better handling of worker start/exit lifecycle events, improved signal handling for ALARM signals, and optimizations to the task scheduling logic. Additionally, the release includes fixes for Windows-specific issues, such as preventing hangs on the first request and ensuring proper PID file handling, while also improving compatibility with PHP 8.4 through explicit nullable type declarations.
src · high confidence
Test coverage
Added stub server and client scripts for HTTP, UDP, and WebSocket testing; Comprehensive test suite for Workerman protocols and connections.
Dependencies
Initial composer.json with PHP 8.1+ requirement and modern dev dependencies
The project now includes a composer.json file that establishes PHP 8.1 as the minimum runtime version and introduces a suite of development tools: Pest 2/3/4 for testing, Mockery 1.6.12 for mocking, Guzzle 7.10 for HTTP client operations, and PHPStan 2.1 for static analysis. The package defines PSR-4 autoloading for the main library under the Workerman namespace and for tests under the Tests namespace, while also declaring a conflict with ext-swow versions prior to 1.0.0 and suggesting the ext-event extension for improved performance.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 65 → 64 (-0.8)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 68 → 80 (+11.6)
- Architecture 100 → 85 (-14.7)
- Maturity 56 → 57 (+1.0)
- Readiness 63 → 57 (-6.7)
- Security 100 → 100 (+0.0)
Resolved (18)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (10 lines × 3) (src/Connection/AsyncTcpConnection.php)
- Duplicated block (11 lines × 2) (src/Protocols/Websocket.php)
- Duplicated block (12 lines × 2) (src/Protocols/Websocket.php)
- Duplicated block (12 lines × 2) (src/Protocols/Websocket.php)
- Duplicated block (13 lines × 2) (src/Worker.php)
- Duplicated block (14 lines × 2) (src/Protocols/Websocket.php)
- Duplicated block (17 lines × 2) (src/Protocols/Http/Response.php)
- Duplicated block (17 lines × 2) (src/Protocols/Websocket.php)
- Duplicated block (6 lines × 2) (src/Connection/AsyncTcpConnection.php)
- Duplicated block (7 lines × 2) (src/Protocols/Ws.php)
- Duplicated block (9 lines × 2) (src/Connection/AsyncTcpConnection.php)
- Hotspot: src/Protocols/Http.php (src/Protocols/Http.php)
- No exposed public API
- Off-boarding risk: anonymized user #1
- Test reliability not included
- The 'Basic Usage' section only covers a single protocol (WebSocket) and omits other supported transports like HTTP, TCP, and SSL with code examples. (README.md)
New (43)
- ClassTooLong: TcpConnection (src/Connection/TcpConnection.php)
- ClassTooLong: Worker (src/Worker.php)
- Dependency hygiene PARTLY measured — Composer dependencies read, no committed lock to grade for currency
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (11 lines × 2) (src/Connection/AsyncTcpConnection.php)
- Duplicated block (11 lines × 3) (src/Connection/AsyncTcpConnection.php)
- Duplicated block (12–13 lines × 2) (src/Protocols/Websocket.php)
- Duplicated block (16 lines × 2) (src/Protocols/Websocket.php)
- Duplicated block (19 lines × 2) (src/Protocols/Websocket.php)
- Duplicated block (20–21 lines × 2) (src/Protocols/Websocket.php)
- Duplicated block (22–24 lines × 2) (src/Protocols/Websocket.php)
- Duplicated block (24 lines × 2) (src/Worker.php)
- Duplicated block (27 lines × 2) (src/Protocols/Http/Response.php)
- Duplicated block (37 lines × 2) (src/Protocols/Websocket.php)
- Duplicated block (6 lines × 2) (src/Connection/AsyncTcpConnection.php)
- Duplicated block (6 lines × 2) (src/Connection/TcpConnection.php)
- Duplicated block (6 lines × 2) (src/Connection/TcpConnection.php)
- Duplicated block (6 lines × 2) (src/Protocols/Ws.php)
- Duplicated block (6 lines × 3) (src/Events/Ev.php)
- …and 23 more
Changes since last survey
- 16 commits — 5 feature/other, 11 fixes
By area
- src/Worker.php — 7 commits
- (repo) — 3 commits
- src/Connection — 2 commits
- tests/Unit — 2 commits
- src/Events — 1 commit
- src/Timer.php — 1 commit
Notable commits
- fix: Merge pull request #1166 from Tinywan/fix-embed-sapi-and-strict-callbacks
- fix: Merge pull request #1167 from Tinywan/fix-select-onsignal-closure-argument
- fix: fix(select): allow variable arguments in onSignal closure to accept pcntl_signal arguments
- fix: fix(worker): accept variable arguments in checkErrors
- fix: fix(worker): allow variable arguments in ob_start output handler
- fix: fix(worker): avoid assigning null to resource-typed outputStream
- fix: fix(worker): safely check and close stream resources in resetStd to fix daemon mode crash
- fix: fix(worker): wrap register_shutdown_function unlink in closure to prevent signature mismatch
- fix: fix(worker,tcp): allow variable arguments in set_error_handler callbacks
- fix: fix(worker,timer): allow variable arguments in signal handlers to prevent ArgumentCountError with pcntl_signal
- fix: fix: improve PHP 8 strict callback compatibility, visibility, and allow embed SAPI
- change: Change spl_object_hash() for spl_object_id()
- change: Improve SSL and WebSocket handling
- change: Merge pull request #1164 from joanhey/patch-3
- change: Update Worker::getId() to use int
- change: tests
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
walkor/workerman was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit a64a81b53231d5133e3869898a46c2953f9db593 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.