Package Health

auth0/auth0-php

Healthy and suitable to depend on. It has a long release history, recent releases, active repository work, organizational backing, and strong testing and security practices, though recent commits are concentrated in one contributor.

Latest 9.2.0PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Are you affected? Scan for Free

Health Score Breakdown

Repo bus factorcaution

All 24 commits in the last three months came from one contributor, creating a genuine short-term concentration risk. Organizational ownership partly compensates because maintenance can potentially be handed off within Auth0.

Repo commit activitycaution

The repository recorded 24 commits in the last three months, demonstrating recent development, although all were made by one active maintainer.

Token permissionscaution

Two workflows omit top-level permissions and one release workflow has write permissions, leaving some workflow privilege scope less explicit. The analyzed workflows otherwise include read-only or job-level permissions, so this is a limited hygiene concern.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-34236
auth0/auth0-php is vulnerable to Insufficient Entropy in versions 8.0.0 - 8.18.0.
8.0.0 - 8.18.0
High
CVE-2025-68129
auth0/auth0-php is vulnerable to Incorrect Authorization in versions 8.0.0 - 8.18.0.
8.0.0 - 8.18.0
Medium
CVE-2025-58769
auth0/auth0-php is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 3.3.0 - 8.16.0.
3.3.0 - 8.16.0
Low
CVE-2025-48951
auth0/auth0-php is vulnerable to Deserialization of Untrusted Data in versions 8.0.0-BETA3 - 8.3.1.
8.0.0-BETA3 - 8.3.1
Critical
CVE-2025-47275
auth0/auth0-php is vulnerable to Improper Authentication in versions 8.0.0-BETA1 - 8.14.0.
8.0.0-BETA1 - 8.14.0
Critical

Package versions

Maintainers

Auth0

Direct Dependencies

DependencyLast ReleaseScore
psr/http-client
Version ^1.0
psr/http-factory
Version ^1.0
psr/http-message
Version ^1.1 || ^2.0
psr-discovery/all
Version ^1
php-http/discovery
Version ^1.0

Weekly Downloads

Info

Last Published
20 days ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform