Package Health

getformwork/formwork

Formwork 2.3.15 appears to be a healthy, actively maintained release with a long release history, frequent recent releases, a current stable version, an unarchived and correctly associated repository, documented licensing, security policy, automated dependency scanning, and clean workflow-risk results. The main concern is maintenance concentration: 98 commits in the last 3 months came from a single contributor, and neither the package nor repository reports tests, which increases continuity and regression risk. Overall, the project is a reasonable dependency, with normal diligence around its concentrated maintainer base and test coverage.

Latest 2.3.15PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Are you affected? Scan for Free

Health Score Breakdown

Package scaffoldingcaution

The artifact and repository include a substantial README and changelog and use GitHub Releases, but neither reports tests; for a CMS this is a genuine maintenance and regression-testing gap.

Repo bus factorcaution

All 96 counted contributor commits came from one contributor, with one contributor active in the last 3 months; this creates a real continuity and bus-factor risk. Organization backing provides some handoff potential, but no second active contributor is shown.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-27198
getformwork/formwork is vulnerable to Improper Privilege Management in versions 2.0.0 - 2.3.3.
2.0.0 - 2.3.3
High
CVE-2025-65956
getformwork/formwork is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.2.0.
0.0.0 - 2.2.0
Medium
CVE-2024-37160
getformwork/formwork is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.13.1 and 2.0.0-beta.1 - 2.0.0-beta.1.
0.0.0 - 1.13.12.0.0-beta.1 - 2.0.0-beta.1
Medium
CVE-2024-35621
getformwork/formwork is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.13.0.
0.0.0 - 1.13.0
Medium
CVE-2023-24230
getformwork/formwork is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.13.0.
0.0.0 - 1.13.0
Medium

Package versions

Maintainers

Formwork Team

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^3.0
symfony/yaml
Version ^7.0.3
psr/container
Version ^2.0
league/climate
Version ^3.10
symfony/process
Version ^7.3

Weekly Downloads

Info

Last Published
16 days ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform