Skip to content

v1.0.0

NaluzPHP is a modern, secure PHP framework for monolithic web apps and REST APIs, with a built-in ORM and an independent query builder. It requires PHP 8.2+ and is MIT licensed.

This repository is the application skeleton: clone it, run composer install, and start building. The framework itself is the separate package naluz/framework, installed into vendor/ by Composer.

Terminal window
git clone https://github.com/taliffsss/framework my-app && cd my-app
composer install
cp .env.example .env && php naluz key:generate --jwt
php naluz migrate
php naluz run:server --port=8001 # http://127.0.0.1:8001

HTTP & routing — PSR-7/15 pipeline, route groups and middleware, route caching, CORS, rate limiting, security headers, JSON resources and pagination.

Database — query builder (identifier validation, bound values) and active-record ORM: HasOne/HasMany/BelongsTo/ BelongsToMany, polymorphic and has-many-through relations, eager loading, soft deletes, casts, events, factories and seeders, migrations, and a lazy-loading guard that turns N+1 queries into errors in development and tests. Drivers: SQLite, MySQL/MariaDB, PostgreSQL and SQL Server.

Read/write connections — separate primary and replica sessions that never share state: replica pools (DB_READ_HOST=a,b), sticky reads after writes, failover to the primary, read-only replicas, useWritePdo(). Transactions, FOR UPDATE, RETURNING, migrations, queues and validation always read from the primary.

NoSQL — document stores (file, memory, MongoDB) with MongoDB-style filters and an injection-safe query builder.

Model caching — set MODEL_CACHING=true (MODEL_CACHE_DRIVER=redis|local): queries are cached for 5 minutes by default and invalidated and re-cached automatically after writes, with transaction safety and a fallback to the database if the cache store fails.

Queues, mail, scheduler, storage — sync/database/Redis queues with retries and a failed-job table; SMTP/log/array mail with header-injection protection; cron-style scheduler; root-confined file storage and safe uploads.

Templates — compiled, auto-escaping engine (*.naluz.php, {{ }} escapes, {!! !!} raw).

Security — Argon2id hashing, encryption, JWT, CSRF, sessions, validation, SSRF-guarded HTTP client.

Logging — PSR-3 channels: daily, single, stderr, error_log, Slack, stack and custom; JSON or line format.

Standards — PSR-1, 3, 4, 6, 7, 11, 12, 13, 14, 15, 16, 17, 18 (Guzzle) and 20, each covered by tests.

CLI — php naluz: run:server [--port --host --workers], migrate, db:seed, queue:work, schedule:run, route:cache, model-cache:flush, new and more.

PHP 8.2, 8.3, 8.4 and 8.5 in CI: 698 tests, PSR-12 coding standard enforced.

  • SQL Server support is verified by SQL-generation tests only; there is no live SQL Server in CI. Validate it against your own instance before relying on it. It needs the pdo_sqlsrv extension.
  • The MongoDB adapter is tested against a fake collection, not a live server (needs mongodb/mongodb and ext-mongodb). The file and memory NoSQL drivers are fully tested.
  • MySQL and PostgreSQL grammars are verified by SQL-generation tests; the integration suite runs on SQLite (and a real Redis server).
  • Rate limiting is a fixed window.
  • Real environment variables take precedence over .env.
  • php naluz serve was replaced by php naluz run:server.
  • The framework is required as naluz/framework; see Architecture.

Full details: the CHANGELOG in the application repository and the rest of this documentation.