Package Health

laravel/framework

Healthy and suitable to depend on. It has a long release history, frequent recent releases, active work from dozens of contributors, strong repository backing, and clear licensing and security practices.

Latest v13.32.0PackagistPackagist

98%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Are you affected? Scan for Free

Health Score Breakdown

Token permissionscaution

All analyzed workflows declare permissions; seven are read-only, while six request top-level write access for project automation, a controlled but non-minimal configuration.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-11075
laravel/framework is vulnerable to CRLF Injection in versions 0.0.1 - 12.59.0 and 13.0.0 - 13.9.0.
0.0.1 - 12.59.013.0.0 - 13.9.0
High
AIKIDO-2026-10659 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
laravel/framework is vulnerable to Insufficient Verification of Data Authenticity in versions 5.6.0 - 12.56.0 and 13.0.0 - 13.6.0.
5.6.0 - 12.56.013.0.0 - 13.6.0
High
AIKIDO-2025-10363 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
laravel/framework is vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere in versions 12.0.0 - 12.17.0.
12.0.0 - 12.17.0
Low
CVE-2024-13919
laravel/framework is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 11.9.0 - 11.36.0.
11.9.0 - 11.36.0
Medium
CVE-2024-13918
laravel/framework is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 11.9.0 - 11.36.0.
11.9.0 - 11.36.0
Medium

Package versions

Maintainers

Taylor Otwell

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.0 || ^2.0 || ^3.0
brick/math
Version ^0.14.2 || ^0.15 || ^0.16 || ^0.17 || ^0.18 || ^0.19
league/uri
Version ^7.5.1
ramsey/uuid
Version ^4.7
symfony/uid
Version ^7.4.0 || ^8.0.0

Weekly Downloads

Info

Last Published
6 days ago
Created
13 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform