The Joomla Framework is a platform for writing Web and command line applications in PHP.
12%
Total Score
critical
Unfit to use: the package is deprecated and its source repository is archived with no recent maintenance.
Packagist marks the entire package as abandoned, with no replacement listed. Package-level deprecation is a severe warning for a new dependency.
The latest release was published about 12 years ago, with no releases in the last 12 months. This strongly indicates that the package is no longer maintained.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the archived status and indicating no current maintenance capacity.
The linked repository is archived, and its last push was about 11 years ago. An archived source project is unlikely to receive fixes or maintenance.
There were no new or closed issues or pull requests in the last month, while 38 issues and 5 pull requests remain open. The lack of current issue activity reinforces the abandonment concern.
| Title | Versions | Severity |
|---|---|---|
CVE-2018-17856 joomla/framework is vulnerable to Security Vulnerability in versions 2.5.4 - 3.8.12. | 2.5.4 - 3.8.12 | High |
CVE-2008-4104 joomla/framework is vulnerable to URL Redirection to Untrusted Site ('Open Redirect') in versions 1.5.0 - 1.5.7. | 1.5.0 - 1.5.7 | Medium |
CVE-2008-3227 joomla/framework is vulnerable to Improper Link Resolution Before File Access ('Link Following') in versions 0.0.0 - 1.5.4. | 0.0.0 - 1.5.4 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.