WildflowerJS Reactive JS, No BS*

A no-build reactive JavaScript framework, rooted in the web platform.
No build step. No dependencies. No compromises.

Latest release: v1.5.0 · see what's new
<script src="wildflower.min.js"></script> ...and start building.

Back to Basics

With WildflowerJS, you write 100% standard code. HTML stays HTML. JavaScript stays JavaScript. CSS stays CSS. There's no JSX, templating language, or custom syntax to learn. If you know the standards, you already know how to use WildflowerJS.

WildflowerJS extends the web platform. It doesn't replace it.

Your Development Simplified

Because you develop with 100% web standards, every tool in your existing chain already understands the code: IDE, browser DevTools, linter, formatter, screen reader, SEO crawler. There's nothing to install, and no custom file types or sourcemaps. Save the file, refresh, and your change is live.

Just be a web developer.

Batteries Included: One Mental Model

Router, SSR, queries, stores, computed properties, two-way binding, event modifiers, data pools, and TypeScript types, all built in, all using the same API. Learn data-bind once and you know binding everywhere: in lists, pools, stores, plugins. There's no five-library stack to keep in sync.

One script tag. Everything you need.

<div data-component="counter">
  <span data-bind="count"></span>
  <button data-action="increment">
    +1
  </button>
</div>

<script>
wildflower.component('counter', {
  state: { count: 0 },
  increment() { this.count++ }
})
</script>

How It Works

data-bind connects state to the DOM.

data-action connects events to methods.

this.count++ triggers a precise DOM update.

Mutate state. The DOM updates.

Two Reactivity Modes

data-list is for automatic reactivity: mutate state, the DOM updates. data-pool is for explicit control: plain objects, zero proxy overhead, you say what changed.

Both use the same template syntax and differ in performance profile, from interactive forms to per-frame particle systems. You choose the tradeoff that fits the job.

Try it. Right-click, inspect this demo. Every dot is a real DOM element.

See full demo →

* Build Step

No Toolchain

Modern frameworks ask you to install a compiler, a bundler, a package manager, hundreds of fragile transitive dependencies, and a framework-specific file format, before you write a single line of your application.

WildflowerJS was built starting from a single principle: no build step, no tooling. Ever.

WildflowerJS asks you to add a script tag.

There's no CLI scaffolding step, config file, or .vue/.jsx/.svelte source format. You don't debug through sourcemaps or wait on a build pipeline. Your project has zero dependencies.

Performance isn't a tradeoff. Build steps optimize bundle delivery, not the runtime work that follows it. WildflowerJS writes directly to the DOM, with no virtual DOM or reconciliation pass between state change and update, so it doesn't need a build step to be fast.

The framework is full-featured without the toolchain, including router, SSR, stores, computed properties, transitions, and pools.

my-app/
  index.html
  app.js
  style.css
  wildflower.min.js

That's the entire project. No package.json, no node_modules, no config files. NONE of that.

No Install. No Attack Surface.

Every dependency you install lets a maintainer you have never met run scripts on your dev machine and in your CI. A typical React + Vite + UI‑lib setup pulls in 300+ transitive packages before you write a feature.

Each one is a potential intrusion vector. NPM worms, OAuth chains compromising deploy platforms, postinstall hijacking: the supply chain is now where production code gets compromised, not the deploy. And signing isn't a backstop: Mini Shai‑Hulud (May 2026) compromised 170+ packages whose malicious versions carried valid SLSA Build Level 3 provenance, because the attestation came from build infrastructure the worm had already taken over.

A WildflowerJS project has none of that surface. There is no npm install, postinstall script, or transitive package graph. The framework is one file you copy or pin by hash.

As of v1.1, the same holds for building the framework itself. WildflowerJS bundles with a vendored rollup and terser pipeline pulled as three SHA‑512‑pinned tarballs, with no npm install and no transitive packages in the build path. The entire toolchain is three files verified by hash.

A typical React/Vue project:

  npm install
  ├── hundreds of packages
  ├── from hundreds of maintainers
  ├── postinstall scripts run on install
  └── tens to hundreds of MB of transitive code

WildflowerJS:

  <script src="wildflower.min.js"></script>
  └── 1 file.
      No transitive dependencies.

No Compromise

WildflowerJS doesn't compromise performance for ease-of-use. Even with no build step, WildflowerJS performs at the level of frontier frameworks on the official js-framework-benchmark board, where its data-pool entry outpaces every major framework and its standard entry sits with the fastest signal-based compilers. And for per-frame workloads, data pools lead every framework we tested in our Lorenz attractor simulation demo.

The charts here are the overall geomean standings and the operation breakdown from the official September 2026 run, plus the sustained frame rate from our per-frame animation sweep. Click any chart to see it full size.

Delivery is fast too, because there's less to deliver. It ships as one file, with no runtime split across chunks and no hydration pass. Lighthouse scores hold their own against compiled frameworks without a single build artifact.

WildflowerJS doesn't trade simplicity of interface for performance of implementation.

Benchmark setup: the two js-framework-benchmark charts show the official September 2026 run (Chrome 152; MacBook Pro 14, M4 14/20 cores, 48 GB RAM, macOS 26.6.2; puppeteer driver), operations 1 through 9, total-duration medians, lower is better. The frame-rate chart is our own sweep: each framework's fastest variant on the Lorenz attractor for 8 seconds per particle count, fullscreen on a 120 Hz panel, higher is better; Apple M5 Pro, 24 GB RAM, macOS 26.5.2, Google Chrome 150 (stable, headed).

Bar chart of the official weighted geometric mean slowdown versus the fastest implementation per operation, Chrome 152: WF-pool 1.09, Vue Vapor 1.12, Solid 1.13, WF 1.16, Svelte 1.17, Vue 1.31; vanilla 1.04 and React 1.58 not shown. Lower is better.
Geomean slowdown vs fastest per operation. Lower is better.
Grouped bar chart of all nine js-framework-benchmark operations for Solid, Svelte, Vue, Vue Vapor, WF, and WF-pool from the official Chrome 152 run, with per-operation rankings. WF-pool is fastest on most operations.
All nine operations, side by side. Stars mark the fastest.
Line chart of sustained FPS versus particle count on the Lorenz attractor for Solid, Svelte, Vue, Vue Vapor, WF, and WF-pool. WF-pool holds the highest frame rate at every count, staying above 60 FPS past 4500 particles.
Per-frame animation. Sustained FPS as particle count grows; higher is better.

No Lock-in

WildflowerJS works with the DOM, not instead of it. There's no virtual DOM intercepting your code and no compiler rewriting your markup. The render cycle is yours alone.

That means Leaflet, DataTables, Chart.js, D3, Three.js, any library that touches the DOM, just works. There are no wrapper packages or framework-specific escape hatches required. Drop in a script tag, it's ready to go.

Because your code is standard HTML and JavaScript, you're never locked in. Your skills transfer and your code is more portable. If you outgrow the framework, your knowledge doesn't expire.

This also means your "ecosystem" is the whole of vanilla JS, with no compromises or hacks.

<!-- Use any library directly -->
<div data-component="map-view">
  <div id="map" style="height: 400px"></div>
</div>
wildflower.component('map-view', {
  state: { lat: 51.505, lng: -0.09 },
  init() {
    // Leaflet works as-is. No wrappers.
    this._map = L.map('map')
      .setView([this.lat, this.lng], 13);
    L.tileLayer('https://{s}.tile.osm.org'
      + '/{z}/{x}/{y}.png').addTo(this._map);
  }
})

Precise Reactivity

When you write this.count++, WildflowerJS updates the single DOM node bound to count. Nothing else is touched. There's no tree diffing or reconciliation pass to figure that out.

You get fine-grained updates and a simple mental model. Change a property, the bound element updates. That's the entire reactivity model.

Other frameworks ask you to learn signals, accessors, memos, effects, and subscription lifecycles to achieve what WildflowerJS does with a standard JS property assignment.

wildflower.component('dashboard', {
  state: {
    users: 1420,
    status: 'healthy'
  },
  computed: {
    summary() {
      return this.users + ' users, ' + this.status;
    }
  },
  refresh() {
    this.users = 1421;
    // Only the elements bound to 'users'
    // and 'summary' update. Everything
    // else on the page is untouched.
  }
})

One Reactivity Model. Everywhere.

Components, Stores, and Plugins, Pools, and now Data Queries all share the same reactive foundation. State, computed properties, and methods work identically no matter where they live. Learn it once, it works the same way across all of those entities.

Other frameworks make you learn a different system for each layer. React components use hooks, but stores need Redux or Zustand, which are completely different APIs. Vue components use reactive data, but Pinia stores have their own patterns. Every layer is a new mental model.

In WildflowerJS, there's one model. A store is a component without a template. A plugin is an entity that extends the framework itself, adding directives, lifecycle hooks, and services. The same this.count++ triggers the same reactivity everywhere.

This makes patterns possible that other frameworks cannot express. A store can run headless physics simulations with tick(), feeding data into a component that renders it through a pool, all using the same reactive primitives, no glue code required.

// Component: reactive UI
wildflower.component('cart', {
  state: { items: [] },
  computed: {
    total() { return this.items.length; }
  }
})

// Store: global shared state
wildflower.store('user', {
  state: { name: '', role: 'guest' },
  computed: {
    isAdmin() { return this.role === 'admin'; }
  }
})

// Plugin: extends the framework
wildflower.plugin({
  name: 'notifications',
  state: { items: [], unreadCount: 0 },
  computed: {
    hasUnread() { return this.unreadCount > 0; }
  },
  add(msg) { this.items.push(msg); this.unreadCount++; }
})
// Access globally: wildflower.$notifications.add(...)

// Same state. Same computed. Same methods.

Live Server Data: Built In, Stays True

With WildflowerJS SSR, the page arrives with its data already in the HTML. The server (your server, whatever back-end you prefer) renders your data into real HTML, so the first paint is real content, indexable and readable before a line of JavaScript runs. And because the markup is genuine HTML, hydration reads the page's state straight back out of the document. Server-rendered components end up exactly equivalent to client-rendered ones.

v1.3 brings data-query, which does for the rest of the page's life what SSR does for first load. Most frameworks hand you fetch() and leave the rest to you. There's an entire ecosystem of client data libraries that exists to fill that gap. WildflowerJS makes it a declaration instead. Name a source, point an element at it, say how fresh it should stay. Loading and error states, refresh on demand, request racing, and the whole refresh ladder (poll, conditional GET, focus, reconnect, server push) come with it. There is also no query language. Refinement is an ordinary computed property, and filtering happens client-side without a network round trip.

v1.5 completes the shape with writes. A query that declares where its rows come from can declare where changes go: to: is the transport, write() applies the change on screen immediately, and confirmation: decides what the server's answer means. If the server refuses, only the fields that write still owns revert, so two writes to the same row never clobber each other and you write no cancellation logic to get it. Computed properties may also return a promise now, holding the last settled value while the next one resolves.

Together, Wildflower's SSR and data-query cover one job at two different times. The server renders the page with real data. Because hydration reads the page itself, there's no flash of empty content, no loading spinner over data the user can already see, and no hydration scripts locking up the main thread. The server's render is the actual UI. When paired with data-query, your SSR becomes the first result of a standing query. The query adopts that markup and keeps it updated from there.

In the example above, the markup is 100% HTML.

<div data-component="product-board">
  <p data-show="$products.isLoading">
    Loading…
  </p>
  <p data-show="$products.error">
    Failed.
    <button data-action="retry">Retry</button>
  </p>

  <span data-bind="$products.count"></span>
  products

  <tbody data-query="products">
    <template>
      <tr>
        <td data-bind="name"></td>
        <td data-bind="stock"></td>
      </tr>
    </template>
  </tbody>
</div>
// The entire data layer:
wildflower.query('products', {
  from: '/api/products',
  key: 'id',
  refresh: ['focus', 'etag:60'],

  // v1.5: where changes go
  to: '/api/products/:id',
  body: (item) => item,
  confirmation: (d) => d.product
});

// The key plus only what changed. On screen
// at once; if the server refuses, only those
// fields revert.
getQuery('products')
  .write({ id: 42, stock: 40 });

// Server-rendered page? Add data-ssr="true"
// and the markup the server sent becomes the
// query's first result. Live from there.

Data Pools

Every framework wraps collection items in reactive proxies, whether the item needs it or not. WildflowerJS gives you a choice: data-list for push reactivity (automatic), data-pool for pull reactivity (explicit control, zero proxy overhead).

Pools render plain objects with the same template syntax as lists. Mutate the object, call markDirty(), and only that item updates. Full CRUD, selection, bulk operations, all faster than the push-reactive path.

And because pools use pull-based rendering, they scale to simulations, games, particle systems, and data visualizations at native frame rate, which a virtual DOM cannot sustain. No other framework offers this choice.

<div data-component="user-table">
  <tbody data-pool="users" data-key="id">
    <template>
      <tr>
        <td data-bind="name"></td>
        <td data-bind="status"
            data-bind-class="status === 'active'
              ? 'badge success'
              : 'badge inactive'"></td>
      </tr>
    </template>
  </tbody>
</div>
wildflower.component('user-table', {
  pools: { users: {} },

  init() {
    // Populate: plain objects, no proxies
    data.forEach(u => this.pools.users.add(u));
  },

  // Optional: add tick() and the same pool
  // renders every frame. Same template, same
  // data, different rendering frequency.
  // That's the only difference between a
  // display table and a particle system.
})

Built for AI-Assisted Development

Because WildflowerJS is standard HTML and JavaScript, AI code assistants already know how to write it. There's no custom syntax to hallucinate or compiler quirks to work around. The code an AI generates runs exactly as written, with no build step between generation and execution.

WildflowerJS ships an AI-optimized reference page with patterns, anti-patterns, and examples designed for code generation context windows. Our llms.txt file follows the llms.txt convention for machine-readable documentation.

You: "Build me a todo app with
WildflowerJS"

AI reads llms.txt or ai-assistant.html
     ↓
Generates standard HTML + JS
     ↓
<div data-component="todo-app">
  <input data-model="newItem">
  <button data-action="addItem">
    Add
  </button>
  <ul data-list="items">
    <template>
      <li data-bind="text"></li>
    </template>
  </ul>
</div>
     ↓
Open in your browser. It works, and you can read and understand the code.

Boundaries and Guarantees FULL v1.5+

What a query guarantees at its edges, and where it will not guess. None of this is needed to use a query. It answers the question behind a surprising result, and it states the limits of each guarantee.

Not Ready Is Not Failed

A read that cannot resolve a :token in its path sends nothing, records nothing, and waits. A write in the same position rejects and identifies the token (WF-972).

A read fires on the framework's schedule and may simply be early, so treating an unresolved token as a failure would turn ordinary route timing into an error state. A write runs because your code called it, so a missing value there is a bug in the call rather than a matter of timing.

// route.slug is still null here.
wildflower.getQuery('comments').refresh();   // waits, isLoading stays true
wildflower.getQuery('comments').write({ id: 7, body: 'edited' });
// rejects: the :slug token has no value

Development builds warn about a waiting token once, so a route that has not resolved yet is distinguishable from a token misspelled badly enough that it never will.

What a Token Can Be

URLs that worked before templates existed still work. A token has to be an identifier and can never start with a digit, so the port in http://localhost:3000/api/tasks is not a token. Only the path is scanned, never the scheme, the authority, or the query string, so ?filter=type:book and https://user:pass@host/api are untouched. There is nothing to escape.

Token values are percent-encoded, so one token is always exactly one path segment. A value containing a slash cannot become two segments, and a value carrying .. cannot climb the path, so application state interpolated into a URL cannot retarget the request.

One case has no escape syntax: a literal :word in a path, as in Google-style custom methods. Percent-encode the colon.

from: '/api/articles/:slug/comments'   // :slug is a token
from: 'http://localhost:3000/api/tasks' // :3000 is a port, not a token
from: '/api/items?filter=type:book'     // query string is never scanned
from: '/v1/items%3AbatchGet'            // a literal colon, percent-encoded

Credentials and Redirects

Framework-level header defaults are keyed by origin. from and to can name any host, so a default with no origin attached would be sent to the first third-party host someone adds a query for. Scoping also makes "which origins receive credentials" one readable declaration rather than a search.

The guarantee covers the request you make, and stops at a redirect. On a cross-origin hop the platform removes Authorization and forwards every other header, so an API key declared for the first origin arrives at the second. No framework code runs between the two requests, so the hop can be reported but not intercepted: development builds warn (WF-986) the first time a response with declared headers shows one. Point from at the final URL so no redirect happens.

Headers are not scrubbed on the hop. A scrub is a list of header names to remove, and such a list becomes incomplete as new credential headers appear; the platform's own list grew from Authorization to cookies to proxy credentials over years. The warning reports every cross-origin hop regardless of which headers are involved.

What a Function Source Cannot Honor

A function from is called with no arguments and builds its own request, so params and select have nothing to act on for reads, and development builds warn at registration with WF-978.

There is one exception. params still fills :token segments in write URLs, so a query can keep a function source and declare params for its writes. That mixed shape fits a read that chooses between two endpoints at runtime, which a single URL cannot express, and it keeps the write side declarative where the read side cannot be.

The Refetch Race

A write that resolves with nothing is followed by a refetch, and that refetch asks your server for the rows immediately after the save. If the machine answering reads is a step behind the machine that took the write, which happens with read replicas and with caches in front of an API, the answer can still be the old data. The save worked, but the rows repaint from before it, and the change appears to vanish until a later refresh brings it back.

The query applies what the server says. It cannot tell a stale replica answer from a change another user just made, and discarding the second to protect against the first would lose real edits. Where your infrastructure reads from a replica, declare a confirmation. The save's own response then carries the saved record, applies directly, and no refetch follows it.

// Refetches after the save, and can read from a lagging replica:
to: '/api/items/:id',
body: item => item

// Applies the save's own response, so no read follows it:
to: {
    update: {
        url: '/api/items/:id',
        method: 'PATCH',
        body: item => item,
        confirmation: d => d.item
    }
}

The reverse race is handled for you. A refresh already in flight when a save confirms describes the world from before the save, so its answer is discarded rather than allowed to overwrite confirmed rows. The next refresh fetches normally.

Why Writes Never Retry

Reads retry on a ladder; writes revert. A failed read can safely re-run because a GET is idempotent. A POST is not: one that failed after the server had already committed the change looks, from the client's side, identical to one that failed before it arrived. Retrying blind risks creating the same order twice.

So the choice of whether to retry, and the write() call that does it, stay with you. The retry option is a read-side option and never applies to writes.

Why Two Queries Do Not Share a Row

Queries are independent stores, each holding its own copy of whatever rows it has. The same server entity appearing in two queries means two copies, each with its own claims, and a write through one leaves the other alone until that query refreshes on its own schedule.

The alternative is a shared entity, where a write in one place updates every view of that row. That requires a normalized cache, with identity rules, merge policies, and a dependency graph to keep the copies consistent. Independent copies mean a write cannot reach a view it was not aimed at. The cost is lag between sibling views, and invalidateQueries() closes it where two views must agree immediately.

await wildflower.getQuery('order-detail').write({ id: 42, status: 'shipped' });
await wildflower.invalidateQueries('orders', 'dashboard-counts');

The Store Is Engine-Owned

A query's store fields belong to the engine. Assigning to rows or to the sync flags from application code draws a development warning (WF-950), because the next sync overwrites whatever you wrote. patch() is the sanctioned form of that write: it never warns, it merges by key, and staleness tracking stays accurate.