$ ossatrisk scan --ecosystem php

ossatrisk surfaces widely-used open source packages with hidden risks, like abandoned maintenance, unpatched CVEs, or a single-maintainer bus factor. Only packages with high impact and broad usage are flagged. The goal isn’t to blame anyone, but to get a clear picture of the ecosystem and act constructively, through contributions, forks where necessary, and fixes that help everyone relying on the code.

high risk
oss projects at risk
total installs
combined downloads
total stars
combined stars
Package Installs Stars Last Release Open issues CVEs Risk Score Actions
loading