It has a clear MIT license, release notes, and a matching source repository. One maintainer and no security policy limit long-term resilience; reassess after sustained activity.
65%
Total Score
50
79
75
Only one registry maintainer is listed, and the repository owner is an individual rather than an organization. This leaves limited publishing and continuity redundancy.
The package was first released today and has only two releases, with a median interval of about 25 minutes. This is too little history to demonstrate durable maintenance, though the short age also explains the limited evidence.
The repository records zero commits and zero active maintainers in the last three months. Because the project is brand new, this is partly explained by its age, but it provides no evidence of sustained maintenance yet.
Composer build tooling is present, but no security scanning tools were detected. The missing scanner is a modest repository hygiene gap, not evidence that the release is unsafe.
The repository has no security policy. For a package that handles search integration and server-side credentials, this reduces transparency for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.