Package Health

flarum/core

Delightfully simple forum software.

Latest v0.1.0-beta.14.1PackagistPackagist

92%

Total Score

Dependencies
Dependencies
Evaluates the health and security of package dependencies

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Vulnerabilities

TitleVersionsSeverity
CVE-2025-27794
flarum/core is vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in versions 0.0.0 - 1.8.10.
0.0.0 - 1.8.10
Medium
CVE-2024-21641
flarum/core is vulnerable to URL Redirection to Untrusted Site ('Open Redirect') in versions 0.0.0 - 1.8.5.
0.0.0 - 1.8.5
Medium
CVE-2023-40033
flarum/core is vulnerable to Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') in versions 0.0.0 - 1.8.0.
0.0.0 - 1.8.0
High
CVE-2023-27577
flarum/core is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 1.7.0.
0.0.0 - 1.7.0
Medium
CVE-2023-22489
flarum/core is vulnerable to Missing Authorization in versions 1.3.0 - 1.6.3.
1.3.0 - 1.6.3
Low

Package versions

Maintainers

Franz Liedke
Daniël Klabbers
David Sevilla Martin
Clark Winkelmann
Matthew Kilgore
Alexander (Sasha) Skvortsov

Direct Dependencies

DependencyLast ReleaseScore
symfony/yaml
Version ^4.3.4
axy/sourcemap
Version ^0.1.4
doctrine/dbal
Version ^2.7
nesbot/carbon
Version ^2.0
illuminate/bus
Version ^6.0

Weekly Downloads

Info

Last Published
5 years ago
Created
10 years ago