The extension has a matching repository, a readable README, a clear license, and a documented release. Its pre-1.0 status, unpinned workflow actions, and absent security policy add maintenance and hygiene concerns.
42%
Total Score
0
79
50
There were zero commits and zero active maintainers in the last three months, consistent with the roughly 2-year release gap. This is a substantial abandonment concern for an extension with ongoing platform dependencies.
The package has had no release in about 2 years and 2 months, after 112 releases were clustered into a short initial period. This strongly suggests abandonment despite the substantial release count.
The repository uses Composer for builds, but no security-scanning tools were detected. This is a modest transparency and maintenance weakness, not evidence that the package is unsafe.
No repository security policy was found. For a small extension this is a transparency gap, although it does not outweigh the direct maintenance evidence by itself.
Version v0.0.111 is not a stable major release, so compatibility expectations are limited. The release is not marked as a prerelease, which partly offsets that concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^1.2.0 | — | — |
ramsey/uuid Version ^4.0 | — | — |
s9e/text-formatter Version ^2.14 | — | — |
symfony/dom-crawler Version ^6.4 | — | — |
google/cloud-translate Version ^1.17 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.