Healthy and reasonable to depend on, with a short but active release history and a matching, maintained repository. The main caveats are no security policy or scanning and a small project with no adoption metrics.
79%
Total Score
88
100
83
80
Only one account has registry publishing access, which limits publishing redundancy. The repository's two active contributors partly compensate for this operational concentration.
The package is only 117 days old and has three releases, all within the last 12 months, with a median interval of about 16 hours. This shows early release activity but not yet long-term maintenance maturity.
The repository has zero stars, forks, and watchers. This is weak supporting evidence for maturity, though the package is new and popularity alone does not establish that it is unsafe to use.
Composer is used for the build, but no security-scanning tool is present. The missing scanning is a transparency gap rather than evidence of a supply-chain incident.
The repository has no SECURITY.md or other security policy, leaving vulnerability-reporting expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^2.0 | — | — |
flarum/tags Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.