Documentation and repository structure are strong, with established organizational backing. Workflow hygiene needs attention before relying on automated publishing and scanning paths.
68%
Total Score
75
100
94
100
There were no commits and no active maintainers in the last 3 months, despite a release during the broader period; this weakens evidence of ongoing maintenance capacity.
Only 4 issues and 2 pull requests are open, but there was no issue or pull-request movement in the last month; this is a mild activity concern rather than evidence of abandonment by itself.
This is a beta release, so its API may change and the release notes explicitly call for an upgrade-guide review; recent prereleases are only 15% of releases, which partly offsets the concern.
All five workflows were analyzed successfully, with no untrusted checkouts or script-injection findings; however, high-confidence template-injection and bot-condition findings, one top-level write-permission workflow, and one unpinned action create workflow-hygiene concerns. The template-injection and bot-condition findings are not independently shown to combine with an exploitable trigger.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-50157 auth0/symfony is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 5.0.0-BETA0 - 5.8.0. | 5.0.0-BETA0 - 5.8.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
symfony/cache Version ^6.4 || ^7.0 || ^8.0 | — | — |
auth0/auth0-php Version ^9.0@beta | — | — |
symfony/security-bundle Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/framework-bundle Version ^6.4 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.