Package Health

codeigniter4/framework

The linked project has only one commit in three months and no security policy. Pin a stable 4.x release instead of this release candidate.

Latest v4.0.0-rc.2.1PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Are you affected? Scan for Free

Health Score Breakdown

Lifecycle scriptscaution

A post-update Composer lifecycle script runs during updates, adding execution during package maintenance even though no harmful behavior is shown by this signal.

Package scaffoldingcaution

The package includes a README, tests, a changelog, and release notes, but the README explicitly says this is pre-release code and should not be used in production.

Repo commit activitycaution

Only one commit was recorded in the last three months, indicating weak recent development activity despite the package's broader release history.

Repo toolingcaution

Composer is used for builds, but no security scanning tools were detected, leaving a modest transparency and hygiene gap.

Security policycaution

The repository has no security policy, making vulnerability reporting and response expectations less transparent for a security-sensitive web framework.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-63223
codeigniter4/framework is vulnerable to Unrestricted Upload of File with Dangerous Type in versions 0.0.0 - 4.7.4.
0.0.0 - 4.7.4
Critical
CVE-2026-63222
codeigniter4/framework is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 4.7.4.
0.0.0 - 4.7.4
High
CVE-2026-63221
codeigniter4/framework is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 4.3.0 - 4.7.4.
4.3.0 - 4.7.4
Critical
CVE-2026-63220
codeigniter4/framework is vulnerable to Use of Less Trusted Source in versions 0.0.0 - 4.7.4.
0.0.0 - 4.7.4
Medium
CVE-2026-48062
codeigniter4/framework is vulnerable to Unrestricted Upload of File with Dangerous Type in versions 0.0.0 - 4.7.2.
0.0.0 - 4.7.2
Critical

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.1
kint-php/kint
Version ^2.1
zendframework/zend-escaper
Version ^2.5

Weekly Downloads

Info

Last Published
6 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform