Package Health

gcgov/framework

Open source framework for PHP applications. Includes MongoDB modelling system.

Latest v7.0.0-rc.4PackagistPackagist

78%

Total Score

healthy

Healthy, with steady releases and active organization-backed maintenance outweighing prerelease and workflow-hygiene concerns.

Health Score Breakdown

Dependency profilecaution

The framework declares 32 runtime dependencies across authentication, database, cloud, and web tooling; this is a broad dependency surface that increases upgrade and compatibility burden.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected, leaving a modest process gap for a framework with a broad dependency surface.

Security policycaution

The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.

Version stabilitycaution

This release is a prerelease, which adds some compatibility uncertainty, although it is the latest version and prereleases are only 20% of recent releases.

Workflow auditcaution

The only workflow was fully analyzed, uses read-only permissions, and has no audited findings or untrusted-code sinks. However, all 4 action references are unpinned, creating a workflow supply-chain hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
lcobucci/jwt
Version ^5.6
—
—
lcobucci/clock
Version ^2.0
—
—
symfony/dotenv
Version ^7.1
—
—
mongodb/mongodb
Version ^2.1
—
—
monolog/monolog
Version ^3.4
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform