A dynamic rendering system for Symfony
72%
Total Score
caution
Active but very new: 55 releases in 9 days, with nearly all commits from one contributor.
The package declares post-install and post-update Composer scripts. These add install-time behavior that consumers should understand, although the signal alone does not establish a severe risk.
The package is only 9 days old but already has 55 releases, with a median interval of 0 days. That shows active publishing, but the unusually compressed history provides little evidence of long-term stability.
One contributor made 74 of 77 recent commits, creating a high concentration risk. The second active contributor and organization ownership partly compensate, so this remains a caution rather than a severe abandonment signal.
Composer build tooling is present, but no security scanning tools were detected. For a development-only fixture this is a transparency gap, not evidence of unsafe code.
The linked repository has no security policy. That weakens vulnerability-reporting transparency, though the package's README identifies it as a development fixture rather than an application runtime dependency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
wexample/symfony-loader Version >=22.0.0 | — | — |
wexample/symfony-design-system Version >=32.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.