Clear documentation, exact-version release notes, and a matching source repository improve transparency. One workflow grants broad write access, and the project has no security scanning configured.
68%
Total Score
50
88
50
One registry maintainer is responsible for publishing the package. That is workable for a small extension, but it leaves limited visible redundancy if the maintainer becomes unavailable.
This is the package's first release, published today, so there is no track record yet for maintenance or release reliability. Its newness explains the gap but does not remove the uncertainty.
The repository has no commits in the last three months and no active maintainers in that period. Because the repository was created and released today, this is limited evidence rather than proof of abandonment.
The repository has no published security policy. This is a transparency and reporting gap, though it is not by itself evidence that the package is unsafe.
Both workflows were analyzed without untrusted triggers, injection findings, or audit failures, but one workflow grants top-level write permissions. That is a mild workflow-hygiene concern because the token scope is broader than necessary.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.