HTTP/2 binary framing protocol implementation
72%
Total Score
caution
Usable with caveats: recent project activity is concentrated in one contributor, despite strong organization backing.
Only three commits were recorded in the last three months, which is modest activity and leaves less evidence of sustained maintenance than the release history provides.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-48979 php-standard-library/h2 is vulnerable to Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in versions 6.1.0 - 6.1.2 and 6.2.0 - 6.2.1. | 6.1.0 - 6.1.26.2.0 - 6.2.1 | High |
| Dependency | Last Release | Score |
|---|---|---|
php-standard-library/io Version ^6.0 | — | — |
php-standard-library/async Version ^6.0 | — | — |
php-standard-library/hpack Version ^6.1 | — | — |
php-standard-library/default Version ^6.0 | — | — |
php-standard-library/date-time Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.