{"uid":"cap_wv0H7YwkjSkoqEZCmNCnR","slug":"synthora-packagist-composer-security-advisories-9672b700","name":"SYNTHORA Packagist Composer Security Advisories","description":"POST/GET a list of PHP Composer packages to keyless packagist.org and get all known security advisories (advisoryId, CVE, GHSA remoteId, affected version constraints, title) per package. The core PHP supply-chain audit primitive for autonomous agents and agent-to-agent CI gates. Ranking surface for Composer vulnerability exposure. First 3 calls FREE per wallet — send header X-WALLET: 0x<addr>. No charge on upstream failure.","url":"https://packagist-security-advisories.hergertsynthora.com/service","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"packages":{"type":"string","description":"packages"}}},"responseSchema":{"type":"json","example":{"ok":true,"niche":"packagist-security-advisories","result":{"advisories":[]},"provenance":{"url":"https://packagist.org/api/security-advisories/?packages[]=symfony/symfony","source":"Packagist Composer Security Advisories"}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.001","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.001/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_bqJsrEgWby1dF0cfug7nb","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.001","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Queries Packagist for all known security advisories (CVEs, GHSAs, affected version constraints) for a list of PHP Composer packages","exampleAgentPrompt":"Can you check these Composer packages for known security vulnerabilities: symfony/http-foundation, laravel/framework, guzzlehttp/guzzle — give me all CVEs and GHSA advisories with affected version ranges?","exampleUseCases":[{"title":"CI gate for PHP dependency audit","prompt":"Before we merge this PR, scan these Composer packages from our composer.lock for any known CVEs or GHSA advisories: monolog/monolog, illuminate/database, symfony/console — flag anything with a critical severity."},{"title":"Open-source package vetting","prompt":"I'm about to add league/flysystem and nesbot/carbon to our PHP project — can you pull all known security advisories for those two packages from Packagist so I know if there are any unresolved vulnerabilities?"},{"title":"Periodic supply-chain risk report","prompt":"Run a security advisory check on all these packages and tell me which ones have active CVEs or GHSA IDs with affected version constraints: guzzlehttp/guzzle, doctrine/orm, twig/twig, phpmailer/phpmailer."}],"resultDescription":"Returns a JSON object with an 'ok' status flag, a 'result' object containing an 'advisories' array keyed by package name — each advisory includes advisoryId, CVE identifier, GHSA remoteId, affected version constraints, and vulnerability title — plus provenance metadata indicating the upstream Packagist source URL.","failureModes":["Empty advisories array returned when no known vulnerabilities exist for submitted packages (not an error)","Malformed package name strings may cause Packagist to return no results without explicit error","Network or upstream Packagist.org outage may cause service unavailability","Packages not listed on Packagist.org will silently return no advisories","Rate limiting or payment failure returns non-200 HTTP status"],"whenToPreferThis":"Choose this endpoint when you need PHP-specific Composer/Packagist vulnerability data with CVE and GHSA identifiers for autonomous CI auditing, agent-to-agent security gates, or supply-chain risk ranking. Prefer this over generic vulnerability databases when working exclusively in the PHP/Composer ecosystem and needing structured, per-package advisory detail with version constraints directly from Packagist's authoritative source.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T12:37:05.078Z","isFirstParty":false}