String é seguro?
String — Nerq Trust Score 63.2/100 (Grau C+). Com base na análise de 2 dimensões de confiança, é geralmente seguro, mas com algumas preocupações. Última atualização: 2026-04-05.
Use String com cautela. String é um PHP package com um Nerq Trust Score de 63.2/100 (C+), com base em 3 dimensões de dados independentes. It is below the recommended threshold of 70. Security: 90/100. Popularity: 100/100. Data sourced from packagist.org, GitHub, and NVD. Last updated: 2026-04-05. Machine-readable data (JSON).
String é seguro?
CAUTION — String has a Nerq Trust Score of 63.2/100 (C+). It has moderate trust signals but shows some areas of concern that warrant attention. Suitable for development use — review security and maintenance signals before production deployment.
Qual é a pontuação de confiança de String?
String tem uma Pontuação de Confiança Nerq de 63.2/100, obtendo grau C+. Esta pontuação é baseada em 2 dimensões medidas independentemente.
Quais são as principais descobertas de segurança de String?
O sinal mais forte de String é popularidade com 100/100. Nenhuma vulnerabilidade conhecida foi detectada. Ainda não atingiu o limiar verificado Nerq de 70+.
O que é String e quem o mantém?
| Autor | symfony |
| Categoria | packagist |
| Stars | 1,795 |
| Source | N/A |
Packagist semelhantes por Pontuação de Confiança
Compare
Safety Guide: String
What is String?
String is a PHP package — Provides an object-oriented API to strings and deals with bytes, UTF-8 code points and grapheme clusters in a unified way.
How to Verify Safety
Run composer audit. Check packagist.org.
You can also check the trust score via API: GET /v1/preflight?target=symfony/string
Key Safety Concerns for PHP packages
When evaluating any PHP package, watch for: dependency vulnerabilities, PHP compatibility.
Trust Assessment
String has a Nerq Trust Score of 63/100 (C+) and has not yet reached Nerq trust threshold (70+). This score is based on automated analysis of security, maintenance, community, and quality signals.
Key Takeaways
- String has a Trust Score of 63/100 (C+).
- Review carefully before use — below trust threshold.
- Always verify independently using the Nerq API.
Análise Detalhada da Pontuação
| Dimension | Score |
|---|---|
| Security | 90/100 |
| Privacy | 80/100 |
| Reliability | 90/100 |
| Transparency | 50/100 |
| Maintenance | 60/100 |
Based on 5 dimensions. Data from packagist.org, GitHub, and NVD.
Quais dados String coleta?
String is a PHP package maintained by symfony. It receives approximately 720,375,555 weekly downloads.
As a development package, String does not directly collect end-user personal data. However, applications built with it may collect data depending on implementation. Privacy score: 80/100.
Review the package's dependencies for potential supply chain risks. Run your package manager's audit command regularly.
Full analysis: Relatório de Privacidade · Privacy review
String é seguro?
Security score: 90/100. This meets the recommended security threshold for production use.
Nerq monitors this entity against NVD, OSV.dev, and registry-specific vulnerability databases for ongoing security assessment.
Full analysis: String Security Report
Como calculamos esta pontuação
String's trust score of 63.2/100 (C+) is computed from packagist.org, GitHub, and NVD. The score reflects 5 independent dimensions: security (90/100), privacy (80/100), reliability (90/100), transparency (50/100), maintenance (60/100). Each dimension is weighted equally to produce the composite trust score.
Nerq analyzes over 7.5 million entities across 26 registries using the same methodology, enabling direct cross-entity comparison. Scores are updated continuously as new data becomes available.
This page was last reviewed on April 05, 2026. Data version: 1.0.
Full methodology documentation · Machine-readable data (JSON API)
Perguntas Frequentes
Is String safe to use?
What is String's trust score?
What are safer alternatives to String?
Does String have known vulnerabilities?
How actively maintained is String?
Popular em packagist
Disclaimer: As pontuações de confiança da Nerq são avaliações automatizadas baseadas em sinais publicamente disponíveis. Não são endossos ou garantias. Sempre realize sua própria verificação.