The package has a clear MIT license, a usable README, tests, and a changelog in its source project. Symfony organization backing and eight active contributors provide resilience beyond the single registry publisher.
94%
Total Score
100
100
94
100
Composer is used as a build tool, which fits the package ecosystem. No security-scanning tool was detected, a minor transparency limitation, but the repository does provide a security policy and other maintenance evidence.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-11066 symfony/ux-autocomplete is vulnerable to Information Exposure in versions 2.2.0 - 2.35.0 and 3.0.0 - 3.0.0. | 2.2.0 - 2.35.03.0.0 - 3.0.0 | Low |
AIKIDO-2026-11055 symfony/ux-autocomplete is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 2.35.0 and 3.0.0 - 3.0.0. | 0.0.1 - 2.35.03.0.0 - 3.0.0 | Medium |
CVE-2023-41336 symfony/ux-autocomplete is vulnerable to Improper Input Validation in versions 0.0.0 - 2.11.2. | 0.0.0 - 2.11.2 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
symfony/http-kernel Version ^7.4|^8.0 | — | — |
symfony/http-foundation Version ^7.4|^8.0 | — | — |
symfony/property-access Version ^7.4|^8.0 | — | — |
symfony/dependency-injection Version ^7.4|^8.0 | — | — |
symfony/deprecation-contracts Version ^2.5|^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.