$ ossatrisk scan --ecosystem php

ossatrisk surfaces widely-used open source packages with hidden risks, like abandoned maintenance, unpatched CVEs, or a single-maintainer bus factor. Only packages with high impact and broad usage are flagged. The goal is not to name and shame, but to understand the ecosystem and suggest remediation—contacting maintainers, contributing fixes, or forking when needed.

high risk
oss projects at risk
total installs
combined downloads
total stars
combined stars
Package Installs Stars Last Release Open issues CVEs Risk Score Actions
loading