MD5 would not be safer, since anyone with the URL could still visit the page which has the activation code.
When you download something from a downloader and run it, you are trusting that downloader quite a lot already. It is inherently unsafe to send your traffic through a third party. No matter what security is used for the Spine download link, consider that the downloader could see you are downloading an executable file and insert malicious code into it. I would not recommend using any downloader software, if you can avoid it.