v1.0.0
NaluzPHP is a modern, secure PHP framework for monolithic web apps and REST APIs, with a built-in ORM and an independent query builder. It requires PHP 8.2+ and is MIT licensed.
This repository is the application skeleton: clone it, run composer install, and start building. The framework
itself is the separate package naluz/framework, installed into
vendor/ by Composer.
Quick start
Section titled “Quick start”git clone https://github.com/taliffsss/framework my-app && cd my-appcomposer installcp .env.example .env && php naluz key:generate --jwtphp naluz migratephp naluz run:server --port=8001 # http://127.0.0.1:8001Highlights
Section titled “Highlights”HTTP & routing — PSR-7/15 pipeline, route groups and middleware, route caching, CORS, rate limiting, security headers, JSON resources and pagination.
Database — query builder (identifier validation, bound values) and active-record ORM: HasOne/HasMany/BelongsTo/ BelongsToMany, polymorphic and has-many-through relations, eager loading, soft deletes, casts, events, factories and seeders, migrations, and a lazy-loading guard that turns N+1 queries into errors in development and tests. Drivers: SQLite, MySQL/MariaDB, PostgreSQL and SQL Server.
Read/write connections — separate primary and replica sessions that never share state: replica pools
(DB_READ_HOST=a,b), sticky reads after writes, failover to the primary, read-only replicas, useWritePdo().
Transactions, FOR UPDATE, RETURNING, migrations, queues and validation always read from the primary.
NoSQL — document stores (file, memory, MongoDB) with MongoDB-style filters and an injection-safe query
builder.
Model caching — set MODEL_CACHING=true (MODEL_CACHE_DRIVER=redis|local): queries are cached for 5 minutes by
default and invalidated and re-cached automatically after writes, with transaction safety and a fallback to the database
if the cache store fails.
Queues, mail, scheduler, storage — sync/database/Redis queues with retries and a failed-job table; SMTP/log/array mail with header-injection protection; cron-style scheduler; root-confined file storage and safe uploads.
Templates — compiled, auto-escaping engine (*.naluz.php, {{ }} escapes, {!! !!} raw).
Security — Argon2id hashing, encryption, JWT, CSRF, sessions, validation, SSRF-guarded HTTP client.
Logging — PSR-3 channels: daily, single, stderr, error_log, Slack, stack and custom; JSON or line format.
Standards — PSR-1, 3, 4, 6, 7, 11, 12, 13, 14, 15, 16, 17, 18 (Guzzle) and 20, each covered by tests.
CLI — php naluz: run:server [--port --host --workers], migrate, db:seed, queue:work, schedule:run,
route:cache, model-cache:flush, new and more.
Tested on
Section titled “Tested on”PHP 8.2, 8.3, 8.4 and 8.5 in CI: 698 tests, PSR-12 coding standard enforced.
Known limitations
Section titled “Known limitations”- SQL Server support is verified by SQL-generation tests only; there is no live SQL Server in CI. Validate it against
your own instance before relying on it. It needs the
pdo_sqlsrvextension. - The MongoDB adapter is tested against a fake collection, not a live server (needs
mongodb/mongodbandext-mongodb). ThefileandmemoryNoSQL drivers are fully tested. - MySQL and PostgreSQL grammars are verified by SQL-generation tests; the integration suite runs on SQLite (and a real Redis server).
- Rate limiting is a fixed window.
Upgrading / notes
Section titled “Upgrading / notes”- Real environment variables take precedence over
.env. php naluz servewas replaced byphp naluz run:server.- The framework is required as
naluz/framework; see Architecture.
Full details: the CHANGELOG in the application repository and the rest of this documentation.