Tests, release notes, and a clear MIT license make the package easier to adopt and maintain. Workflow references are mostly unpinned, with high-confidence template-injection findings and no security policy, so keep deployment controls tight.
76%
Total Score
100
50
100
67
The package has 45 runtime dependencies, which increases dependency-chain complexity for a framework component and warrants more transitive maintenance attention.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
All 57 action references are unpinned, and high-confidence template-injection findings appear in split.yml; the low-confidence cache findings are hygiene concerns, while no untrusted checkout or script-injection trigger was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0|^2.0|^3.0 | — | — |
brick/math Version ^0.11|^0.12 | — | — |
league/uri Version ^7.5 | — | — |
ramsey/uuid Version ^4.7 | — | — |
symfony/uid Version ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.