Its MIT license, tests, and active CI provide useful transparency, while the missing security policy and narrowly concentrated maintenance leave meaningful uncertainty. The README also documents a pre-release core-interface dependency, so compatibility may require careful version pinning.
68%
Total Score
67
88
67
The package is less than one day old with only two releases, so its maintenance record and maturity are not yet established.
One contributor accounts for all recent commits, creating a narrow handoff path. Organization backing partly compensates, but no second active contributor is shown.
Only three commits from one active maintainer were recorded in the last three months; activity is recent but provides little evidence of durable maintenance capacity.
No repository security policy was found, leaving reporting and response expectations undocumented.
The sole workflow has no top-level token permissions declaration, so its GitHub Actions permissions are less explicit than they should be.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version ^8.0 | — | — |
spora-ai/spora-core Version ^0.24.0 | — | — |
symfony/http-client Version ^8.0 | — | — |
symfony/event-dispatcher Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.