Healthy and suitable to depend on. It has a long release history with 60 releases in the last year, active source updates, tests, documentation, and clear Symfony organization backing. No deprecation or archival concerns are present.
94%
Total Score
100
100
94
100
Composer build tooling is present, which fits the package ecosystem. No security scanning tool was detected, a modest transparency gap, but other maintenance and security signals are strong.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2024-10381 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. symfony/form is vulnerable to Improper Neutralization of Null Byte in versions 2.0.0 - 5.4.37, 6.0.0 - 6.4.5 and 7.0.0 - 7.0.5. | 2.0.0 - 5.4.376.0.0 - 6.4.57.0.0 - 7.0.5 | Low |
CVE-2017-16790 symfony/form is vulnerable to Improper Input Validation in versions 2.7.0 - 2.7.38, 2.8.0 - 2.8.31, 3.0.0 - 3.2.14 and 3.3.0 - 3.3.13. | 2.7.0 - 2.7.382.8.0 - 2.8.313.0.0 - 3.2.14 +1 more | Medium |
| Dependency | Last Release | Score |
|---|---|---|
symfony/var-exporter Version ^8.1 | — | — |
symfony/polyfill-ctype Version ^1.8 | — | — |
symfony/property-access Version ^7.4|^8.0 | — | — |
symfony/event-dispatcher Version ^7.4|^8.0 | — | — |
symfony/options-resolver Version ^7.4|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.