Small enough to read end-to-end. Real enough that several live products already run on it.
The conventions here — the data layer, the auth system, the notification pattern, the multi-app routing — are documented specifically so a coding agent (Claude Code, or any other) can read them once and reuse them, rather than inventing a new one-off stack for every new app.
That only works if the conventions are actually worth reusing. A parameterized query builder, hardened session handling with a dated public fix history, and a real inter-app API aren't aspirational — they're what's already there.
A fluent query builder that's parameterized by construction, plus a lightweight Active Record ORM with real multi-database context switching.
Hardened sessions, AES-256-GCM encryption, login throttling, CSRF — and a dated log of specific vulnerabilities found and fixed, not a marketing claim.
Several apps can share one login and session under a single install, and call each other directly over a built-in API — not a hypothetical, it's running in production today.
No package ecosystem to trust blindly, no DI container hiding what calls what. What you can't see isn't there — you can read the whole thing.
Being honest about trade-offs is part of the pitch, not a footnote:
FRAMEWORK.md for the reasoning.The reference implementation renders this framework's own integration guide — code and docs together, not a separate pitch.
Explore the Reference App