The project has a clear license, tests, release notes, and organizational backing. Its last registry release was over a year ago, security scanning and a security policy are absent, and workflows use unpinned container images.
62%
Total Score
75
50
88
50
The package declares 17 runtime dependencies for a full Symfony application skeleton, including framework, database, mailer, and frontend tooling. The breadth is consistent with its stated application-template role but increases maintenance surface.
Install and update commands run post-install and post-update lifecycle scripts. These add execution exposure during dependency operations, though this signal alone does not show unsafe behavior.
The package has 11 releases over roughly four years, but no releases in the last 12 months and its latest release was in March 2025. This indicates a meaningful maintenance slowdown for a starter application.
There were no new or closed issues or pull requests in the measured month, and no pull requests are open. This is consistent with limited current activity, although issue counts are partly unavailable.
Composer build tooling is present, but no security-scanning tooling was detected. For an application template with many runtime dependencies, that is a modest supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.7 | — | — |
doctrine/orm Version ^2.13 | — | — |
symfony/flex Version ^2 | — | — |
symfony/yaml Version 7.2.* | — | — |
symfony/dotenv Version 7.2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.