Eight contributors made 22 commits in the last three months, and the package has a long, regular release history. It also includes tests, a changelog, a license, and security reporting guidance; the repository has no recorded security-scanning tool.
93%
Total Score
100
100
94
100
Composer build tooling is present, but no security-scanning tools were detected, leaving a modest repository-hygiene gap.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-47946 symfony/ux-twig-component is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.25.1. | 0.0.0 - 2.25.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.24|^4.0 | — | — |
psr/container Version ^1.1|^2.0 | — | — |
twig/html-extra Version ^3.29|^4.0 | — | — |
symfony/property-access Version ^7.4|^8.0 | — | — |
symfony/event-dispatcher Version ^7.4|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.