Work with the Meta / Facebook Conversions API in your Symfony application
62%
Total Score
caution
Usable with caveats: a high-confidence workflow template-injection finding is the main adoption risk.
Both workflows were analyzed without incomplete files, but all 21 action references are unpinned. More importantly, a high-confidence, high-severity template-injection finding may expand attacker-controlled input into code; the absence of dangerous trigger and untrusted-checkout counts does not compensate for that finding.
Fourteen runtime dependencies, including Symfony components and the related SDK, create meaningful compatibility surface for a beta bundle. The dependencies are coherent with the package's Symfony integration role rather than appearing excessive or unrelated.
Only one registry account has publish access, which is a publishing continuity concern. However, the repository is organization-owned and recent repository activity shows active project backing.
One contributor made all 27 commits in the last three months, creating a concentrated maintenance dependency. Organization ownership provides some handoff capacity, but no second active contributor is evidenced here.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a hygiene gap, not evidence of abandonment or unsafe code by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || ^2.0 || ^3.0 | — | — |
symfony/config Version ^6.4 || ^7.4 | — | — |
composer/semver Version ^3.0 | — | — |
symfony/messenger Version ^6.4 || ^7.4 | — | — |
symfony/http-kernel Version ^6.4 || ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.