Skip to content
CAI
Produce a survey ↗Verify a survey

getgrav/grav

This system is a PHP-based content management framework that manages page rendering, asset pipelines, and user authentication via a modernized Flex data layer. It provides a robust CLI interface for package management, backup scheduling, and system maintenance, while enforcing strict security controls such as Twig sandboxing and path traversal prevention. The architecture emphasizes type safety, lazy loading, and modular service providers to handle configuration, HTTP requests, and template rendering efficiently.

59.2

Adequate · 29 July 2026

97k

lines of production code

PHP

primary language

2

bus factor · 255 authors in all

3

measurements over time

CAI band scale
CAI trend line

How it got here

2014–2015 · Grav 2.0 architecture and security hardening

This period focused on a comprehensive architectural overhaul for Grav 2.0, introducing a new service container, lazy-loaded page indexing, and a refactored GPM package manager. Significant security hardening was implemented across the codebase, including blocking direct web access to sensitive directories and sanitizing error outputs. The update also modernized dependencies, added native .env support, and improved CLI tooling for system management.

36 changes

2016–2018 · Framework modernization and Flex integration

This period focused on modernizing the Grav framework by introducing PSR-7, PSR-11, and PSR-15 standards, alongside a comprehensive unit testing infrastructure. The work established a new object and collection model, implemented a robust Flex storage system, and refactored core components like assets, forms, and the request pipeline to support these architectural improvements.

52 changes

2019–2021 · Framework architecture and Flex system overhaul

This period focused on a comprehensive architectural overhaul of the Grav framework, introducing extensive new interfaces, traits, and abstract classes to improve type safety and code organization. Key developments included the introduction of a new ACL framework, PSR-7 HTTP message handling, and a robust Flex system for managing pages and users. The era also saw significant improvements in static analysis coverage, CLI tooling, and PHP 8+ compatibility.

40 changes

2022–2026 · Framework modernization and security hardening

This period focused on modernizing the framework by introducing structured object identification, relationship management, and media handling interfaces. It also included compatibility layers for external dependencies like Doctrine Cache, Twig 3, Monolog 3, and Pimple, alongside significant security hardening through Twig sandboxing and comprehensive unit testing.

14 changes

CAI lens gauges

Survey your own repository

getgrav/grav was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point the surveyor at a repository you know and see whether you agree with it.

Survey a repository

About this page

  • The description of this project is derived from its own commit history, not from its README.
  • The score is its highest published measurement, taken on 29 July 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit daaaaf21f9 — the exact code this score is about.
  • Scored under rubric rubric-2026.08.18. Score the same commit under that rubric and you get the same number.
CAI link cards