Clear licensing, tests in the repository, and an organization-backed source provide useful maintenance context. The package still warrants caution because its identity resembles spiral/core, recent commit activity is absent, and workflow actions are unpinned.
42%
Total Score
75
100
89
75
The package borrows the identity of the much more established spiral/core, with 55,6263 versus 65,401 monthly downloads and borrows_lookalike_identity=true; the rule treats this as strong evidence consumers may have wanted spiral/core instead.
The repository recorded 0 commits and 0 active maintainers in the last three months, which weakens evidence of ongoing maintenance despite a release during the observed period.
The repository has no security policy, leaving vulnerability-reporting expectations and response guidance undocumented.
Both workflows were analyzed without trigger or audit findings, but all 2 of 2 action references are unpinned, leaving their fetched code less reproducible and harder to control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
symfony/http-client Version ^6.2 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.