Package Health

topthink/framework

The ThinkPHP Framework.

Latest v8.1.4PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Are you affected? Scan for Free

Health Score Breakdown

Release historycaution

The project has existed for over 10 years with 120 releases, but only one release in the last 12 months indicates a substantially slower release cadence.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, a meaningful warning about current maintenance capacity despite the recent release and push metadata.

Repo issue activitycaution

There is still some issue activity, with one new issue in the last month and nine open issues, but no issues or pull requests were closed or merged during that period.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and automated-checking gap.

Security policycaution

No repository security policy was found, so the project provides less visible guidance for reporting and handling vulnerabilities.

Vulnerabilities

TitleVersionsSeverity
CVE-2025-50706
topthink/framework is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 5.1.41.
0.0.0 - 5.1.41
Critical
CVE-2024-44902
topthink/framework is vulnerable to Deserialization of Untrusted Data in versions 6.1.3 - 8.0.4.
6.1.3 - 8.0.4
Critical
CVE-2024-34467
topthink/framework is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 8.0.0 - 8.0.4, 6.1.0 - 6.1.5 and 0.0.0 - 6.0.17.
0.0.0 - 6.0.176.1.0 - 6.1.58.0.0 - 8.0.4
Medium
CVE-2022-47945
topthink/framework is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 6.0.14.
0.0.0 - 6.0.14
Critical
CVE-2022-44289
topthink/framework is vulnerable to Unrestricted Upload of File with Dangerous Type in versions 0.0.0 - 5.0.24 and 5.1 - 5.1.41.
0.0.0 - 5.0.245.1 - 5.1.41
High

Package versions

Maintainers

liu21st
yunwuxin

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.0|^2.0|^3.0
—
—
psr/http-message
Version ^1.0|^2.0
—
—
psr/simple-cache
Version ^1.0|^2.0|^3.0
—
—
topthink/think-orm
Version ^3.0|^4.0
—
—
topthink/think-helper
Version ^3.1
—
—

Weekly Downloads

Info

Last Published
8 months ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform