Licensing, tests, a readme, and static analysis give consumers useful safeguards. The repository is tied to the package and has no install-time scripts.
82%
Total Score
67
100
67
Recent contribution is fully concentrated in one contributor, which creates handoff risk; organization ownership provides some backing but no second active contributor is shown.
Seven commits occurred in the last 3 months, showing recent work, although all activity came from one active maintainer.
The repository has no published security policy, leaving vulnerability-reporting expectations less transparent.
Both workflows were fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, both of the two action references are unpinned, creating a modest reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spiral/core Version ^3.17.2 | — | — |
spiral/hmvc Version ^3.17.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.