Support capacity is thin, with one maintainer and no commits in the last three months. It remains transparent through an MIT license and README, but the old prerelease line makes long-term support uncertain.
48%
Total Score
25
67
75
Only three releases were published, with none in the last 12 months; the latest release is over four years old, indicating a stalled release stream.
The repository had zero commits and zero active maintainers in the last three months, consistent with the older release history and raising maintenance risk.
The registry lists one publisher account. That is not proof of poor maintenance by itself, but it provides little visible publishing redundancy alongside the inactive repository.
Composer build tooling is present, but no security scanning tool was detected; this is a modest transparency and maintenance gap rather than a severe issue.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented for a package intended to run in a forum.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^1.2.0 | — | — |
afrux/forum-widgets-core Version ^0.1.0 | — | — |
v17development/flarum-blog Version >=0.6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.