The small dependency surface and clear MIT licensing reduce integration friction. Long-term maintenance remains uncertain, so pin this exact version and test it with your Flarum upgrade path.
57%
Total Score
67
100
79
75
The registry namespace and repository owner match, so the source ownership is coherent. The owner is an individual rather than an organization, which provides less visible maintainer redundancy.
This is the package's only release, published nearly 4 years 9 months ago, with no releases in the last 12 months. That limits evidence of ongoing compatibility maintenance, although recent repository activity partly offsets the concern.
There were no commits and no active maintainers in the last 3 months, which weakens evidence of current maintenance. The recent push shown by repository_archived and three merged pull requests in the last month provide some compensating activity.
Composer is used for the build, but no security scanning tools are reported. The missing scanning is a hygiene limitation, not evidence that the package is unsafe or abandoned.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap for a package intended for application deployments.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.