The linked project has only one commit in three months and no security policy. Pin a stable 4.x release instead of this release candidate.
62%
Total Score
83
100
79
50
A post-update Composer lifecycle script runs during updates, adding execution during package maintenance even though no harmful behavior is shown by this signal.
The package includes a README, tests, a changelog, and release notes, but the README explicitly says this is pre-release code and should not be used in production.
Only one commit was recorded in the last three months, indicating weak recent development activity despite the package's broader release history.
Composer is used for builds, but no security scanning tools were detected, leaving a modest transparency and hygiene gap.
The repository has no security policy, making vulnerability reporting and response expectations less transparent for a security-sensitive web framework.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-63223 codeigniter4/framework is vulnerable to Unrestricted Upload of File with Dangerous Type in versions 0.0.0 - 4.7.4. | 0.0.0 - 4.7.4 | Critical |
CVE-2026-63222 codeigniter4/framework is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 4.7.4. | 0.0.0 - 4.7.4 | High |
CVE-2026-63221 codeigniter4/framework is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 4.3.0 - 4.7.4. | 4.3.0 - 4.7.4 | Critical |
CVE-2026-63220 codeigniter4/framework is vulnerable to Use of Less Trusted Source in versions 0.0.0 - 4.7.4. | 0.0.0 - 4.7.4 | Medium |
CVE-2026-48062 codeigniter4/framework is vulnerable to Unrestricted Upload of File with Dangerous Type in versions 0.0.0 - 4.7.2. | 0.0.0 - 4.7.2 | Critical |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 | — | — |
kint-php/kint Version ^2.1 | — | — |
zendframework/zend-escaper Version ^2.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.