Healthy and suitable to depend on. It has frequent stable releases, active contributions from many developers, clear licensing, tests, and an organization-backed repository that is still maintained.
97%
Total Score
90
100
94
100
There were no new or closed issues or pull requests in the last month, but the open issue and pull request totals are unavailable. This is limited evidence and does not outweigh the recent commits and release cadence.
Composer is used as the build tool, which fits the package ecosystem. No repository security-scanning tool was detected, leaving a modest transparency gap.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-608303 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. symfony/mailer is vulnerable to SMTP Command Injection in versions 4.3.0 - 6.4.42, 7.0.0 - 7.4.14, 8.0.0 - 8.0.14 and 8.1.0 - 8.1.1. | 4.3.0 - 6.4.427.0.0 - 7.4.148.0.0 - 8.0.14 +1 more | Low |
AIKIDO-2026-10886 symfony/mailer is vulnerable to Argument Injection in versions 0.0.1 - 5.4.51, 6.0.0 - 6.4.39, 7.0.0 - 7.4.11 and 8.0.0 - 8.0.11. | 0.0.1 - 5.4.516.0.0 - 6.4.397.0.0 - 7.4.11 +1 more | High |
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1|^2|^3 | — | — |
symfony/mime Version ^7.4|^8.0 | — | — |
psr/event-dispatcher Version ^1 | — | — |
egulias/email-validator Version ^2.1.10|^3|^4 | — | — |
symfony/event-dispatcher Version ^7.4|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.