The package has clear documentation, release notes, a matching source repository, and a permissive MIT license. Its only release is brand new, so maintenance history is unproven; the missing security policy and repository scanning add modest transparency concerns.
64%
Total Score
88
67
The package was first and last released on the same day, with only one release and no established release cadence. This is expected for a new project but leaves maturity and maintenance unproven.
Composer build tooling is present, but no security scanning tools were detected. That is a modest repository hygiene gap rather than evidence of unsafe code.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.
Both workflows were analyzed without audit findings or untrusted checkouts, but one workflow grants top-level write permissions, which is broader than necessary and mildly weakens workflow hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.