Healthy and suitable to depend on. It has a long release history, frequent recent releases, active source maintenance, tests, release notes, and organization backing; recent commits are concentrated in one contributor, which is the main caveat.
88%
Total Score
83
100
100
100
One contributor made all 6 commits in the last 3 months, so recent activity has a concentrated bus factor. This is a caution, though the Symfony organization provides backing that can support handoff.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10869 symfony/dom-crawler is vulnerable to XML External Entity (XXE) in versions 0.0.1 - 5.4.51, 6.0.0 - 6.4.39, 7.0.0 - 7.4.11 and 8.0.0 - 8.0.11. | 0.0.1 - 5.4.516.0.0 - 6.4.397.0.0 - 7.4.11 +1 more | Low |
| Dependency | Last Release | Score |
|---|---|---|
symfony/polyfill-ctype Version ^1.8 | — | — |
symfony/polyfill-mbstring Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.