Package Health

nesbot/carbon

An API extension for DateTime that supports 281 different languages.

Latest 3.14.2PackagistPackagist

79%

Total Score

healthy

Healthy, backed by active maintenance and a fresh release, with workflow pinning as the main concern.

Are you affected? Scan for Free

Health Score Breakdown

Repo bus factorcaution

One contributor made 26 of 31 recent commits, so activity is concentrated. The organization-owned repository and two other active contributors partly compensate, making this a mild resilience concern rather than a severe risk.

Workflow auditcaution

All 35 analyzed action references are unpinned, and the audit found a high-confidence, high-severity unpinned container image in phpcs.yml. The workflows were fully analyzed and have no untrusted checkouts or script-injection findings, but the pinning gap warrants caution.

Vulnerabilities

TitleVersionsSeverity
CVE-2025-22145
nesbot/carbon is vulnerable to Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') in versions 3.0.0 - 3.8.4 and 0.0.0 - 2.72.6.
0.0.0 - 2.72.63.0.0 - 3.8.4
Medium

Package versions

Maintainers

Brian Nesbitt
kylekatarnls

Direct Dependencies

DependencyLast ReleaseScore
psr/clock
Version ^1.0
—
—
symfony/clock
Version ^6.3.12 || ^7.0 || ^8.0
—
—
symfony/translation
Version ^4.4.18 || ^5.2.1 || ^6.0 || ^7.0 || ^8.0
—
—
symfony/polyfill-mbstring
Version ^1.0
—
—
carbonphp/carbon-doctrine-types
Version <100.0
—
—

Weekly Downloads

Info

Last Published
6 days ago
Created
14 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform