Usable with caveats: the package is licensed, stable, backed by an organization, and has tests plus a release for this version. However, the repository has had no commits in the last three months, has no security policy or scanning tools, and has very little adoption evidence.
65%
Total Score
67
100
89
75
Only one registry account has publishing access, which is a limited release-management base. The organization-owned repository partly compensates for this narrow registry maintainer list.
The repository recorded zero commits and zero active maintainers in the last three months. Although the release was recent, this is a meaningful sign of limited current maintenance activity.
The repository has zero stars, zero watchers, and one fork, so there is little external adoption evidence. Popularity is supporting evidence rather than decisive proof, but this lowers confidence in project maturity.
Composer is used for builds, but no security scanning tools are configured. The missing scanning is a transparency and maintenance gap, though it is not by itself a severe dependency risk.
The repository has no security policy. This weakens vulnerability-reporting transparency, although the package is a focused configuration-template module rather than a security-sensitive service.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spiral/boot Version ^3.15 | — | — |
spiral/files Version ^3.15 | — | — |
symfony/yaml Version ^6.0 | ^7.0 | ^8.0 | — | — |
spiral/console Version ^3.15 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.