Healthy and suitable to depend on. It has a long release history, frequent recent releases, active commits, tests in the repository, and clear security and licensing practices. Maintenance is concentrated in one contributor, which is the main caveat.
88%
Total Score
88
100
100
90
Two contributors were active in the last 3 months, but one made 46 of 48 commits, leaving maintenance highly concentrated. Organization backing provides some handoff capacity, but does not eliminate the continuity risk.
Seven of eight workflows omit top-level token permissions, and one workflow grants top-level write permissions; this is a workflow-hardening gap, though no dangerous workflow patterns were detected.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-22145 nesbot/carbon is vulnerable to Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') in versions 3.0.0 - 3.8.4 and 0.0.0 - 2.72.6. | 0.0.0 - 2.72.63.0.0 - 3.8.4 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
psr/clock Version ^1.0 | — | — |
symfony/clock Version ^6.3.12 || ^7.0 || ^8.0 | — | — |
symfony/translation Version ^4.4.18 || ^5.2.1 || ^6.0 || ^7.0 || ^8.0 | — | — |
symfony/polyfill-mbstring Version ^1.0 | — | — |
carbonphp/carbon-doctrine-types Version <100.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.