Clear documentation, tests, and release notes make integration easier. The main remaining weakness is limited security-process evidence, so pinning this exact version is sensible.
87%
Total Score
100
50
89
75
The package declares 34 runtime dependencies for a broad Symfony security bundle, creating a relatively large maintenance and compatibility surface. The scope of the bundle helps explain the size, but the profile remains a moderate caution.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, so this limits external validation but does not outweigh the active maintenance signals.
Composer build tooling is present, but no security-scanning tools were detected. For a security-focused bundle, that is a meaningful process gap.
The repository has no security policy. That weakens vulnerability-reporting transparency for a package handling authentication and account-security features.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, both action references are unpinned, leaving avoidable action-supply-chain exposure.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
psr/clock Version ^1.0 | — | — |
twig/twig Version ^3.0 | — | — |
symfony/form Version ^6.4|^7.4 | — | — |
symfony/clock Version ^6.4|^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.