An API extension for DateTime that supports 281 different languages.
79%
Total Score
healthy
Healthy, backed by active maintenance and a fresh release, with workflow pinning as the main concern.
One contributor made 26 of 31 recent commits, so activity is concentrated. The organization-owned repository and two other active contributors partly compensate, making this a mild resilience concern rather than a severe risk.
All 35 analyzed action references are unpinned, and the audit found a high-confidence, high-severity unpinned container image in phpcs.yml. The workflows were fully analyzed and have no untrusted checkouts or script-injection findings, but the pinning gap warrants caution.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-22145 nesbot/carbon is vulnerable to Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') in versions 3.0.0 - 3.8.4 and 0.0.0 - 2.72.6. | 0.0.0 - 2.72.63.0.0 - 3.8.4 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
psr/clock Version ^1.0 | — | — |
symfony/clock Version ^6.3.12 || ^7.0 || ^8.0 | — | — |
symfony/translation Version ^4.4.18 || ^5.2.1 || ^6.0 || ^7.0 || ^8.0 | — | — |
symfony/polyfill-mbstring Version ^1.0 | — | — |
carbonphp/carbon-doctrine-types Version <100.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.