↑ ↓ select, Enter open, Esc close

Check Composer packages for known vulnerabilities

Adjust the values, the command updates live
user@server
composer audit --working-dir=/var/www/vhosts/example.com/httpdocs

Matches the packages from composer.lock against the Packagist database of security advisories and lists affected packages with CVE and fixed version. Available since Composer 2.4. composer outdated --direct shows outdated packages without known vulnerabilities.

Note: Debian 12 ships Composer 2.5 as a package. Update older Composer versions with composer self-update, provided it was installed as a Phar.

Also searched as

  • find composer security vulnerabilities
  • outdated php packages with vulnerabilities
  • composer security check

Related one-liners

All in PHP

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.