The repository has no security policy, and both workflow actions are unpinned. Releases are regular, the project is actively backed by an organization, and repository tests and security tooling are present.
78%
Total Score
67
100
75
One contributor made 100% of the recent commits, leaving the project dependent on a single observed source of maintenance activity despite organization backing.
The repository recorded 8 commits in the last 3 months, showing recent activity, but all were made by one active maintainer.
The repository has no documented security policy, which leaves vulnerability reporting and response expectations less transparent.
Both workflows were fully analyzed with no reported audit findings or untrusted checkouts, but both of their two action uses are unpinned, reducing build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spiral/core Version ^3.17.2 | — | — |
spiral/debug Version ^3.17.2 | — | — |
spiral/files Version ^3.17.2 | — | — |
spiral/config Version ^3.17.2 | — | — |
spiral/events Version ^3.17.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.