The project is easy to identify and install, with clear consumer documentation and release notes. Its longer-term maintenance record and security practices are not yet established.
70%
Total Score
83
100
88
50
The repository is owned by an individual rather than an organization, so there is no shown organizational handoff capacity. The two active contributors partly offset that limitation.
This is the package's first release, published today, so there is no registry history to demonstrate sustained maintenance or compatibility over time.
Composer build tooling is present, but no security-scanning tools were detected. That is a modest transparency and maintenance gap for a new package.
The repository has no security policy. This does not make the release unsafe by itself, but it leaves vulnerability reporting and response expectations unclear.
Both workflows were fully audited with no reported findings, no untrusted checkouts, and no unpinned action references. One workflow grants top-level write permission, a mild hygiene concern, but no untrusted path was found to reach it.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^2.0 | — | — |
ernestdefoe/picks Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.