Cotonti Verona 1.0.0: A PHP CMF That Puts Templates First
Fast, reliable and flexible PHP CMF/CMS
At a glance
- What is it?
- Cotonti Verona is a BSD-licensed PHP content management framework that separates layout from logic with a custom template engine. This review covers its architecture, installation requirements, and where it falls short for modern PHP projects.
- Who is it for?
- Adopt Cotonti Verona if you need a lightweight, BSD-licensed PHP CMF with a simple template engine and are willing to run PHP 7.3 or higher on MySQL 5.0.8 or newer. Do not adopt it if you require modern PHP 8.2+ features, a built-in ORM, or a package manager like Composer, as the repository does not indicate these.
- Can I use it commercially?
- Yes. BSD-3-Clause is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 165 days ago.
- What is it written in?
- Mainly PHP, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on October 6, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What Cotonti Solves and Who It Targets
Cotonti addresses a specific niche: developers who want a content management system that behaves like a framework. The README positions it as a combination of a web framework and a CMS, offering user accounts, content creation, file management, and community tools out of the box. The target audience is not the end user who clicks through a dashboard, but the programmer who needs to build a custom site without writing every authentication and content module from scratch. The emphasis on a template engine that is "fast and easy to learn" suggests it aims at developers who find Laravel or Symfony too heavy and who dislike the template syntax of WordPress. It is a niche between a micro-framework and a full-stack CMS, and that positioning is clear from the first paragraph of the README.
The Template Engine as the Core Mechanism
The central architectural choice in Cotonti is its own template engine, which the README claims is both fast and easy to learn. The phrase "layout separated from logic" is the key to how it works. Instead of embedding PHP logic directly in HTML files, Cotonti uses templates that are separate from the PHP code that populates them. This separation is a common pattern in CMSes, but Cotonti implements it with a custom engine rather than adopting an existing one like Twig or Blade. The README does not provide syntax examples, so the exact template tags are not visible in the material. What is clear is that the engine is a deliberate trade-off: it reduces the learning curve for non-programmers, but it also means developers must learn a proprietary syntax that does not transfer to other projects. The speed claim is not backed by benchmarks in the README, so it should be taken as a design goal rather than a measured fact.
Server Requirements and Installation Path
Cotonti has a hard set of server prerequisites. The README lists a WWW server (Apache, nginx, etc.), PHP 7.3.0 or higher, and MySQL 5.0.8 or higher. It also states that PHP must be compiled with a specific set of extensions: GD, Hash, Mbstring, MySQL, PCRE, PDO and PDO_MySQL, Sessions, and Zlib. This is a strict list, and a missing extension will prevent a successful run. For SEF (Search Engine Friendly) URLs, you additionally need mod_rewrite and the ability to use local .htaccess files, which means Apache or a compatible server. The installation itself is not described in the README; it points to an Install.txt file in the repository. That file is not included in the provided material, so the exact steps are unknown. However, the requirement list implies a manual setup: upload files, configure the web server, and likely run a web-based installer. There is no mention of Composer, npm, or any package manager, which suggests a traditional FTP-style deployment.
The 1.0.0 Release and Versioning Context
The repository shows a recent 1.0.0 release, codenamed Verona, pushed on 2026-04-23. This is a significant milestone because the previous releases are 0.9.25 (Siena) from 2024-09-03 and 0.9.24.2 from 2024-02-23. The jump from 0.9.x to 1.0.0 usually signals API stability, but the README does not list any changes or migration notes. The release notes are on a dedicated GitHub page, which is not part of the provided material. This is a gap: anyone considering an upgrade from 0.9.25 to 1.0.0 needs to check that page for breaking changes. The versioning pattern with codenames (Verona, Siena) is a stylistic choice that does not affect functionality. The long gap between 0.9.24.2 and 0.9.25, then the jump to 1.0.0, suggests a slow but steady maintenance cadence, though the material does not confirm active development frequency.
Modularity and Extensibility as a Double-Edged Sword
Cotonti is described as "modular and extensible," with modules and plugins as the extension mechanism. This is a standard approach, but the README gives no details on how modules are structured, how they are installed, or whether there is a central repository for them. The lack of a package manager is a real limitation. In modern PHP, Composer is the de facto standard for dependency management, and its absence means that installing a module likely involves manually copying files and possibly editing configuration. The extension system is also a risk: without a documented API or a stable release history, third-party modules may break between versions. The 1.0.0 release should provide a stable base, but the README does not state any backward compatibility guarantees. For a developer used to WordPress plugins or Drupal modules, Cotonti's approach will feel more hands-on and less standardized.
Security and Reliability Claims Without Evidence
The README lists "secure and reliable" as major features, but it provides no specifics. There is no mention of input sanitization, CSRF protection, or SQL injection prevention. The requirement for Mbstring and PCRE suggests that string handling and regular expressions are central, but that does not demonstrate security. The project has a long history, with copyright notices going back to 2001, which implies years of field use. However, the material does not include any security advisories, audit results, or vulnerability disclosures. As a reviewer, I cannot verify the security claims. This is a common issue with open-source CMSes, but it is worth noting that the README's confidence is not backed by evidence. For a project that will handle user accounts and content, the absence of security documentation in the README is a gap that potential adopters should investigate by reading the code or checking the issue tracker.
Licensing and Maintenance Costs
Cotonti is released under the BSD 3-Clause License, which is permissive and allows commercial use, modification, and redistribution with attribution. This is a low-risk license for adoption, as it does not impose copyleft obligations like the GPL. The copyright holders are listed as the Cotonti Team (2008-2026) and Neocrome (2001-2008), indicating a long lineage. The maintenance cost is not explicitly documented, but the release history shows infrequent updates: 0.9.24.2 in February 2024, 0.9.25 in September 2024, and then 1.0.0 in April 2026. That is roughly a 19-month gap between the last 0.9.x release and the 1.0.0. This slow cadence means that security patches may be delayed, and compatibility with new PHP versions is not guaranteed. The requirement for PHP 7.3.0 or higher is notably old; PHP 7.3 reached end-of-life in December 2021. The README does not state support for PHP 8.x, which is a significant limitation for any new deployment in 2026.
Alternatives and Where Cotonti Fits
The closest alternative to Cotonti is a lightweight PHP CMS like GetSimple or a flat-file CMS like Grav, but the differences are instructive. GetSimple also focuses on simplicity and does not require a database, whereas Cotonti requires MySQL. Grav uses Markdown files and a modern PHP stack, while Cotonti uses a traditional MySQL and server-side templating. Another alternative is a micro-framework like Slim or Laminas Mezzio, which gives you full control but no built-in CMS features. Cotonti sits between these: it offers CMS features out of the box but with a custom template engine and a dated PHP requirement. Compared to a full-stack CMS like WordPress, Cotonti is lighter and more developer-oriented, but it lacks the massive plugin ecosystem. The choice comes down to whether you value the template separation and speed claims over the convenience of a larger community and more modern dependencies.
Editorial conclusion
Adopt Cotonti Verona if you need a lightweight, BSD-licensed PHP CMF with a simple template engine and are willing to run PHP 7.3 or higher on MySQL 5.0.8 or newer. Do not adopt it if you require modern PHP 8.2+ features, a built-in ORM, or a package manager like Composer, as the repository does not indicate these. Before deploying, verify that your host compiles PHP with GD, Hash, Mbstring, MySQL, PCRE, PDO, PDO_MySQL, Sessions, and Zlib, and confirm that SEF URLs work with mod_rewrite and .htaccess if you need them. The 1.0.0 release on 2026-04-23 is a stable milestone, but check the release notes for any breaking changes from 0.9.25.
Frequently asked questions
What are Cotonti's server requirements?
A WWW server such as Apache or nginx, PHP 7.3.0 or higher, and MySQL 5.0.8 or higher. In addition, PHP must be compiled with support for GD, Hash, Mbstring, MySQL, PCRE, PDO and PDO_MySQL, Sessions, and Zlib.
What do I need for SEF URLs in Cotonti?
mod_rewrite and the ability to use local .htaccess files. The repository ships both sef-urls.htaccess and sef-urls.nginx.conf, so SEF URLs work on Apache and on nginx.
How do I install Cotonti?
Step-by-step instructions are in Install.txt at the repository root. The tree also contains install.php and a setup/ directory, so the setup runs as a web installer, which means you need to plan for what to do with that file after installation.
How do I extend Cotonti with my own code?
With modules or plugins. Despite user accounts, content creation, file management, and community tools being available out of the box, the repository has separate modules/ and plugins/ directories for extensions.
What licence is Cotonti released under?
The three-clause BSD licence, also called New-BSD. The copyright covers 2008 to 2026 for the Cotonti Team and 2001 to 2008 for Neocrome.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/cotonti-cotonti)