The repository has no commits, new issues, or merged pull requests in the last three months, and it lacks a security policy. Its long history, organization backing, tests, release notes, and clear licensing provide useful stability despite the slower visible activity.
68%
Total Score
75
50
94
50
The package declares 21 runtime dependencies for a substantial Symfony bundle, a sizable integration surface that modestly increases maintenance and compatibility burden.
The repository recorded zero commits and zero active maintainers over the last three months. The recent release partly offsets this, but the visible maintenance cadence is currently stalled.
There were no new or closed issues and no new or merged pull requests in the last month, with 107 open issues and 10 open pull requests; this indicates limited current issue-management activity.
The project uses Make and Composer, but no security scanning tools were detected, leaving a security-hygiene gap for a widely integrated library.
No repository security policy was found, reducing transparency about how vulnerabilities are reported and handled.
| Title | Versions | Severity |
|---|---|---|
CVE-2013-5750 friendsofsymfony/user-bundle is vulnerable to Uncontrolled Resource Consumption in versions 1.2.0 - 1.2.5 and 1.3.0 - 1.3.3. | 1.2.0 - 1.2.51.3.0 - 1.3.3 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^2.13 || ^3.0 | — | — |
symfony/form Version ^7.3 | — | — |
symfony/yaml Version ^7.3 | — | — |
symfony/config Version ^7.3 | — | — |
symfony/routing Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.