The package includes tests, a changelog, a license, and a security policy, with no install-time scripts. Repository activity is light and concentrated in one contributor, but organizational backing and a long release history reduce abandonment risk.
86%
Total Score
67
100
100
100
One contributor made all commits in the last three months, creating a concentrated short-term bus factor. The repository is owned by an organization, which provides some capacity for handoff.
Only one commit was recorded in the last three months, which indicates light recent activity. Release history and the broader Symfony organizational backing partly compensate for this limited snapshot.
| Title | Versions | Severity |
|---|---|---|
CVE-2017-16653 symfony/security-csrf is vulnerable to Cross-Site Request Forgery (CSRF) in versions 2.7.0 - 2.7.38, 2.8.0 - 2.8.31, 3.0.0 - 3.2.14 and 3.3.0 - 3.3.13. | 2.7.0 - 2.7.382.8.0 - 2.8.313.0.0 - 3.2.14 +1 more | Medium |
| Dependency | Last Release | Score |
|---|---|---|
symfony/security-core Version ^7.4|^8.0 | — | — |
symfony/deprecation-contracts Version ^2.5|^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.