PHP

PHP package analysis and vulnerability scanning capabilities

Package analysis

Cataloger + Evidence License Dependencies Package Manager Claims
Depth Edges Kinds Files Digests Integrity Hash
php-composer-installed-cataloger
installed.json
transitive runtime, dev
php-composer-lock-cataloger
composer.lock
transitive runtime
php-interpreter-cataloger
php*/**/*.so, php-fpm*, apache*/**/libphp*.so
direct flat runtime
php-pear-serialized-cataloger
php/.registry/**/*.reg
direct runtime
php-pecl-serialized-cataloger
php/.registry/.channel.*/*.reg
direct runtime

Vulnerability scanning

Data Source Disclosures Fixes Track by
Source
Package
Affected Date Versions Date
National Vulnerability Database (NVD)
Grype Configuration
Configuration Key Description
match.stock.using-cpes Use CPE package identifiers to find vulnerabilities

Next steps

Last modified October 23, 2025: fix section ref (9417a27)