A clear README, tests in the repository, release notes, and matching MIT licensing improve confidence in the project. Its very short history, absent security policy, and unpinned workflow actions leave meaningful maintenance and build-integrity gaps.
68%
Total Score
75
100
83
75
The repository is owned by an individual account, so there is no organizational backing shown to offset the package's short history.
All three releases were published on the same day, so the package has no demonstrated long-term release or maintenance track record yet.
The repository has no stars, forks, or watchers. This is weak supporting evidence, though the package's zero-day age makes the lack of audience unsurprising.
Composer is used for builds, but no security scanning tool is configured, leaving a modest repository-hygiene gap.
The repository has no security policy, reducing clarity about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^2.0.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.