Healthy and suitable to depend on. It has a long release history, recent releases, active repository work, organizational backing, and strong testing and security practices, though recent commits are concentrated in one contributor.
88%
Total Score
75
100
100
90
All 24 commits in the last three months came from one contributor, creating a genuine short-term concentration risk. Organizational ownership partly compensates because maintenance can potentially be handed off within Auth0.
The repository recorded 24 commits in the last three months, demonstrating recent development, although all were made by one active maintainer.
Two workflows omit top-level permissions and one release workflow has write permissions, leaving some workflow privilege scope less explicit. The analyzed workflows otherwise include read-only or job-level permissions, so this is a limited hygiene concern.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-34236 auth0/auth0-php is vulnerable to Insufficient Entropy in versions 8.0.0 - 8.18.0. | 8.0.0 - 8.18.0 | High |
CVE-2025-68129 auth0/auth0-php is vulnerable to Incorrect Authorization in versions 8.0.0 - 8.18.0. | 8.0.0 - 8.18.0 | Medium |
CVE-2025-58769 auth0/auth0-php is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 3.3.0 - 8.16.0. | 3.3.0 - 8.16.0 | Low |
CVE-2025-48951 auth0/auth0-php is vulnerable to Deserialization of Untrusted Data in versions 8.0.0-BETA3 - 8.3.1. | 8.0.0-BETA3 - 8.3.1 | Critical |
CVE-2025-47275 auth0/auth0-php is vulnerable to Improper Authentication in versions 8.0.0-BETA1 - 8.14.0. | 8.0.0-BETA1 - 8.14.0 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
psr-discovery/all Version ^1 | — | — |
php-http/discovery Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.