Package Health

codeigniter/framework

The project has a clear MIT license, a substantial repository, and documentation-backed ownership. Its workflow uses three unpinned actions, and no security policy is present.

Latest 3.1.13PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Are you affected? Scan for Free

Health Score Breakdown

Release historydanger

The package has made no releases in the past 12 months, with the latest release in March 2022; this is a substantial maintenance concern for a framework dependency.

Lifecycle scriptscaution

Post-install and post-update scripts run during dependency operations, adding execution surface that warrants caution even though this signal alone does not establish a health failure.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the past three months, indicating currently inactive development.

Repo issue activitycaution

There were no new or closed issues or pull requests in the past month, while 71 issues and 35 pull requests remain open; this reinforces the signs of limited current maintenance.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented for a security-sensitive framework.

Vulnerabilities

TitleVersionsSeverity
CVE-2020-24950
codeigniter/framework is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 1.4.9.
0.0.0 - 1.4.9
High
CVE-2014-8684
codeigniter/framework is vulnerable to Security Vulnerability in versions 0.0.0 - 3.0.0.
0.0.0 - 3.0.0
Critical
CVE-2018-12071
codeigniter/framework is vulnerable to Session Fixation in versions 0.0.0 - 3.1.10.
0.0.0 - 3.1.10
Critical

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
4 years ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform