Usable with caveats: the release is licensed, documented, tested, and actively being published, but the project is only one day old and has no recorded three-month commit activity or community adoption. Treat it as an early-stage dependency until a longer maintenance track record emerges.
64%
Total Score
75
100
83
90
The package is only 1 day old, with 9 releases compressed into roughly 25 hours. That shows active initial development but provides almost no long-term maintenance evidence.
No commits or active maintainers were recorded in the preceding 3 months. Because the repository is only 1 day old, this mainly reflects insufficient history rather than demonstrated abandonment, but it remains a material maturity gap.
The repository has zero stars, forks, and watchers. A new package need not be popular, but these counters provide no external adoption or community support evidence.
Composer build tooling is present, but no security scanning tools were detected. This is a modest supply-chain transparency gap, partly offset by the repository's CI and other workflow checks.
The repository has no SECURITY.md or other detected security policy. That weakens vulnerability-reporting transparency, though it is not by itself evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.