Package Health

filp/whoops

Tests, a changelog, a security policy, and a matching repository improve transparency. Workflow references are all unpinned, and recent activity is light, so pin version 2.18.5 and watch maintenance.

Latest 2.18.5PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Are you affected? Scan for Free

Health Score Breakdown

Repo commit activitycaution

Two commits from two active maintainers in the last three months show recent activity, though the volume is light for a mature project.

Repo toolingcaution

Composer build tooling is present, but no security scanning tool was detected; this is a modest transparency gap rather than a dependency-blocking concern.

Workflow auditcaution

The sole workflow was fully analyzed with no untrusted checkout, script injection, or audit findings, but all five action references are unpinned, leaving them exposed to upstream changes.

Vulnerabilities

TitleVersionsSeverity
CVE-2017-16880
filp/whoops is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.1.13.
0.0.0 - 2.1.13
Medium

Package versions

Maintainers

Filipe Dobreira

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.0.1 || ^2.0 || ^3.0

Weekly Downloads

Info

Last Published
4 days ago
Created
13 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform