Healthy and suitable to depend on. It has a long, active release history, current repository activity, tests, changelog, clear licensing, and organizational backing, with no deprecation or archive status.
94%
Total Score
100
100
94
100
Composer is used for builds, supporting reproducible package management; no security-scanning tool was detected, which is a minor transparency gap but not decisive given the other evidence.
| Title | Versions | Severity |
|---|---|---|
CVE-2024-36610 symfony/var-dumper is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 6.4.4 and 7.0.0 - 7.0.4. | 0.0.0 - 6.4.47.0.0 - 7.0.4 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
symfony/polyfill-mbstring Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.