The project has tests, a changelog, an MIT license, and organization backing. Its three workflow actions are unpinned, and it has no security policy; issue and pull-request activity is also stalled.
53%
Total Score
50
100
81
75
The package has had no release in more than 6 years, despite 27 releases overall; this strongly suggests the release line is no longer actively maintained.
The repository recorded zero commits and zero active maintainers over the last 3 months, reinforcing the abandonment concern raised by the old release history.
There were no new or closed issues and no new or merged pull requests in the last month, while 83 issues and 18 pull requests remain open; this indicates stalled project activity.
Composer build tooling is present, but no security-scanning tool was detected, leaving repository security hygiene weaker than it could be.
The repository has no security policy or documented disclosure path, which reduces transparency for handling vulnerabilities in a security-sensitive CMS.
| Title | Versions | Severity |
|---|---|---|
CVE-2011-4340 symphonycms/symphony-2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.2.4. | 0.0.0 - 2.2.4 | Low |
CVE-2015-8766 symphonycms/symphony-2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.6.4. | 0.0.0 - 2.6.4 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
composer/semver Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.