Healthy and suitable to depend on. It has a long, frequent release history, active contributors, current repository activity, clear licensing, and strong Symfony organization backing; the artifact’s missing tests are covered by repository tests.
94%
Total Score
100
100
94
100
Composer build tooling is present. No security-scanning tool was detected, but this is a limited transparency gap rather than a severe health concern given the strong release and maintenance evidence.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10883 symfony/cache is vulnerable to SQL Injection in versions 0.0.1 - 5.4.51, 6.0.0 - 6.4.39, 7.0.0 - 7.4.11 and 8.0.0 - 8.0.11. | 0.0.1 - 5.4.516.0.0 - 6.4.397.0.0 - 7.4.11 +1 more | Medium |
CVE-2019-10912 symfony/cache is vulnerable to Deserialization of Untrusted Data in versions 3.1.0 - 3.4.26, 4.0.0 - 4.1.12 and 4.2.0 - 4.2.7. | 3.1.0 - 3.4.264.0.0 - 4.1.124.2.0 - 4.2.7 | High |
CVE-2019-18889 symfony/cache is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 3.1.0 - 3.4.35, 4.0.0 - 4.2.12 and 4.3.0 - 4.3.8. | 3.1.0 - 3.4.354.0.0 - 4.2.124.3.0 - 4.3.8 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1|^2|^3 | — | — |
psr/cache Version ^2.0|^3.0 | — | — |
symfony/var-exporter Version ^8.1 | — | — |
symfony/cache-contracts Version ^3.6 | — | — |
symfony/service-contracts Version ^2.5|^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.