The extension is small and clearly packaged, with a focused runtime dependency and a matching source repository. Maintenance appears inactive, and the repository has no security policy, so future compatibility and response capacity are uncertain.
58%
Total Score
50
100
88
83
The repository is owned by an individual rather than an organization, so the project has a narrow visible backing structure. That increases reliance on one maintainer, but does not by itself indicate abandonment.
The package has had only one release, about four years and five months ago, with no releases in the last 12 months. This is substantial evidence of limited ongoing maintenance, though a small stable extension may need few releases.
The repository recorded no commits and no active maintainers in the last three months. Combined with the old release history, this indicates weak current maintenance capacity.
The repository uses Composer build tooling, but no security scanning tools were detected. The build setup is appropriate, while the lack of scanning is a modest transparency and hygiene gap.
No repository security policy was found. For a small extension this is a minor gap rather than a severe dependency risk, but it gives maintainers and users no documented vulnerability-reporting path.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.