Healthy and suitable to depend on. It has a long release history, frequent recent releases, an active unarchived organization-backed repository, and a documented release for this version. Maintenance is somewhat concentrated in one contributor, but other contributors remain active.
91%
Total Score
83
100
94
100
One contributor made 11 of 13 commits in the last 3 months, so recent work is concentrated; however, two additional contributors were active and the organization backing provides some maintenance continuity.
The repository uses Composer for builds, but no security-scanning tool was detected. The missing scanner is a modest transparency gap, outweighed by the project's long release history and active maintenance.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10959 symfony/routing is vulnerable to Open Redirect in versions 0.0.1 - 5.4.52, 6.0.0 - 6.4.40, 7.0.0 - 7.4.12 and 8.0.0 - 8.0.12. | 0.0.1 - 5.4.526.0.0 - 6.4.407.0.0 - 7.4.12 +1 more | Medium |
AIKIDO-2026-10958 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. symfony/routing is vulnerable to Deserialization of Untrusted Data in versions 6.4.0 - 6.4.40, 7.4.0 - 7.4.12 and 8.0.0 - 8.0.12. | 6.4.0 - 6.4.407.4.0 - 7.4.128.0.0 - 8.0.12 | High |
AIKIDO-2026-10882 symfony/routing is vulnerable to Open Redirect in versions 0.0.1 - 5.4.51, 6.0.0 - 6.4.39, 7.0.0 - 7.4.11 and 8.0.0 - 8.0.11. | 0.0.1 - 5.4.516.0.0 - 6.4.397.0.0 - 7.4.11 +1 more | Medium |
| Dependency | Last Release | Score |
|---|---|---|
symfony/deprecation-contracts Version ^2.5|^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.