Capabilities

PHP

PHP package analysis and vulnerability scanning capabilities

Package analysis

Cataloger + EvidenceLicenseDependenciesPackage Manager Claims
DepthEdgesKindsFilesDigestsIntegrity Hash
php-composer-installed-cataloger
installed.json
TransitiveRuntime, Dev
php-composer-lock-cataloger
composer.lock
TransitiveRuntime
php-interpreter-cataloger
php*/**/*.so, php-fpm*, apache*/**/libphp*.so
DirectFlatRuntime
php-pear-serialized-cataloger
php/.registry/**/*.reg
DirectRuntime
php-pecl-serialized-cataloger deprecated
php/.registry/.channel.*/*.reg
DirectRuntime

Vulnerability scanning

Data SourceDisclosuresFixesTrack by
Source
Package
AffectedDateVersionsDate
National Vulnerability Database (NVD)

Grype Configuration
Configuration KeyDescription
match.stock.using-cpesUse CPE package identifiers to find vulnerabilities

Next steps

Last modified November 26, 2025: allow local too invocation (d20d613)