PHPackages                             insite/composer-npm-audit - PHPackages - PHPackages  [Skip to content](#main-content)[PHPackages](/)[Directory](/)[Categories](/categories)[Trending](/trending)[Leaderboard](/leaderboard)[Changelog](/changelog)[Analyze](/analyze)[Collections](/collections)[Log in](/login)[Sign up](/register)

1. [Directory](/)
2. /
3. [Security](/categories/security)
4. /
5. insite/composer-npm-audit

ActiveComposer-plugin[Security](/categories/security)

insite/composer-npm-audit
=========================

Composer plugin that looks for vulnerabilities in NPM packages

0.3.4(1w ago)04.5k↓46.7%GPL-2.0-or-laterPHPCI passing

Since Mar 30Pushed 1w ago2 watchersCompare

[ Source](https://github.com/prudloff-insite/composer-npm-audit)[ Packagist](https://packagist.org/packages/insite/composer-npm-audit)[ RSS](/packages/insite-composer-npm-audit/feed)WikiDiscussions master Synced yesterday

READMEChangelogDependencies (18)Versions (14)Used By (0)

Composer NPM audit
==================

[](#composer-npm-audit)

This Composer plugin mimicks `npm audit` for packages installed with [Assets Packagist](https://asset-packagist.org/)or the [Composer Asset Plugin](https://github.com/fxpio/composer-asset-plugin).

It provides a simple way to know if your NPM dependencies have known vulnerabilities.

Install
-------

[](#install)

```
composer require insite/composer-npm-audit
```

Usage
-----

[](#usage)

Simply run `composer npm-audit` and it will display a table like this:

```
 ---------- ---------------- ------------ --------------------- ---------------------------- ----------------------------------
  Severity   Title            Dependency   Vulnerable versions   Recommendation               URL
 ---------- ---------------- ------------ --------------------- ---------------------------- ----------------------------------
  high       Code Injection   js-yaml      =3.13.1 --update-with-dependencies
```

###  Health Score

49

—

FairBetter than 94% of packages

Maintenance98

Actively maintained with recent releases

Popularity22

Limited adoption so far

Community11

Small or concentrated contributor base

Maturity54

Maturing project, gaining track record

 Bus Factor1

Top contributor holds 78.4% of commits — single point of failure

How is this calculated?**Maintenance (25%)** — Last commit recency, latest release date, and issue-to-star ratio. Uses a 2-year decay window.

**Popularity (30%)** — Total and monthly downloads, GitHub stars, and forks. Logarithmic scaling prevents top-heavy scores.

**Community (15%)** — Contributors, dependents, forks, watchers, and maintainers. Measures real ecosystem engagement.

**Maturity (30%)** — Project age, version count, PHP version support, and release stability.

###  Release Activity

Cadence

Every ~207 days

Recently: every ~350 days

Total

12

Last Release

11d ago

### Community

Maintainers

![](https://www.gravatar.com/avatar/87d4515168f3d16dcaf23af7184edbe8ef073c99dddd36b3ca5b2953ba415e03?d=identicon)[prudloff-insite](/maintainers/prudloff-insite)

![](https://www.gravatar.com/avatar/9b241b88818e2034c1257f4a425564231c89ded760ecf239a25e23804de55715?d=identicon)[gaelg](/maintainers/gaelg)

---

Top Contributors

[![prudloff-insite](https://avatars.githubusercontent.com/u/50333926?v=4)](https://github.com/prudloff-insite "prudloff-insite (40 commits)")[![dependabot[bot]](https://avatars.githubusercontent.com/in/29110?v=4)](https://github.com/dependabot[bot] "dependabot[bot] (11 commits)")

### Embed Badge

![Health badge](/badges/insite-composer-npm-audit/health.svg)

```
[![Health](https://phpackages.com/badges/insite-composer-npm-audit/health.svg)](https://phpackages.com/packages/insite-composer-npm-audit)
```

###  Alternatives

[aws/aws-sdk-php

AWS SDK for PHP - Use Amazon Web Services in your PHP project

6.3k543.5M2.6k](/packages/aws-aws-sdk-php)[neuron-core/neuron-ai

The PHP Agentic Framework.

2.0k656.1k38](/packages/neuron-core-neuron-ai)[tencentcloud/tencentcloud-sdk-php

TencentCloudApi php sdk

3741.3M47](/packages/tencentcloud-tencentcloud-sdk-php)[oro/platform

Business Application Platform (BAP)

645143.5k115](/packages/oro-platform)[tempest/framework

The PHP framework that gets out of your way.

2.2k34.4k15](/packages/tempest-framework)[drupal/core-vendor-hardening

Hardens the vendor directory for when it's in the docroot.

174.9M48](/packages/drupal-core-vendor-hardening)

PHPackages © 2026

[Directory](/)[Categories](/categories)[Trending](/trending)[Changelog](/changelog)[Analyze](/analyze)
