The MIT license, README, release notes, and small runtime dependency set make the package straightforward to evaluate and integrate. Its maintenance evidence is weak, with no releases since 2021 and no commits in the last three months; workflow references also lack pinning.
52%
Total Score
50
100
86
75
This is a 1,742-day-old package with only one release and no releases in the last 12 months. That limited history and lack of ongoing releases materially increase abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the single-release history, this is meaningful evidence of weak current maintenance.
Composer is used as a build tool, but no security scanning tools are configured. The missing scanning is a modest transparency and hygiene gap, not evidence that the release is unsafe.
The repository has no security policy. This weakens disclosure transparency, though it is less significant for a small extension than the maintenance gaps.
Both analyzed workflows completed the audit without findings or dangerous triggers, but all 2 of 2 action references are unpinned. That leaves avoidable workflow supply-chain hygiene risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.