getgrav/grav
This system is a PHP-based content management framework that manages page rendering, asset pipelines, and user authentication via a modernized Flex data layer. It provides a robust CLI interface for package management, backup scheduling, and system maintenance, while enforcing strict security controls such as Twig sandboxing and path traversal prevention. The architecture emphasizes type safety, lazy loading, and modular service providers to handle configuration, HTTP requests, and template rendering efficiently.
59.2
Adequate · 29 July 2026
97k
lines of production code
PHP
primary language
2
bus factor · 255 authors in all
3
measurements over time
How it got here
2014–2015 · Grav 2.0 architecture and security hardening
This period focused on a comprehensive architectural overhaul for Grav 2.0, introducing a new service container, lazy-loaded page indexing, and a refactored GPM package manager. Significant security hardening was implemented across the codebase, including blocking direct web access to sensitive directories and sanitizing error outputs. The update also modernized dependencies, added native .env support, and improved CLI tooling for system management.
36 changes
2016–2018 · Framework modernization and Flex integration
This period focused on modernizing the Grav framework by introducing PSR-7, PSR-11, and PSR-15 standards, alongside a comprehensive unit testing infrastructure. The work established a new object and collection model, implemented a robust Flex storage system, and refactored core components like assets, forms, and the request pipeline to support these architectural improvements.
52 changes
2019–2021 · Framework architecture and Flex system overhaul
This period focused on a comprehensive architectural overhaul of the Grav framework, introducing extensive new interfaces, traits, and abstract classes to improve type safety and code organization. Key developments included the introduction of a new ACL framework, PSR-7 HTTP message handling, and a robust Flex system for managing pages and users. The era also saw significant improvements in static analysis coverage, CLI tooling, and PHP 8+ compatibility.
40 changes
2022–2026 · Framework modernization and security hardening
This period focused on modernizing the framework by introducing structured object identification, relationship management, and media handling interfaces. It also included compatibility layers for external dependencies like Doctrine Cache, Twig 3, Monolog 3, and Pimple, alongside significant security hardening through Twig sandboxing and comprehensive unit testing.
14 changes
Survey your own repository
getgrav/grav was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point the surveyor at a repository you know and see whether you agree with it.
About this page
- The description of this project is derived from its own commit history, not from its README.
- The score is its highest published measurement, taken on 29 July 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit daaaaf21f9 — the exact code this score is about.
- Scored under rubric rubric-2026.08.18. Score the same commit under that rubric and you get the same number.