A single maintainer and no security policy limit resilience and transparency. The MIT license, release notes, matching repository, and clean workflow audit provide useful compensating evidence.
62%
Total Score
50
100
92
67
Only one registry maintainer is listed, which leaves limited publishing redundancy; the repository is user-owned rather than organization-backed.
The package is 0 days old with four releases clustered within hours, so it has not yet demonstrated sustained maintenance or a settled release cadence.
The repository reports zero commits and zero active maintainers in the last three months. Because the package is 0 days old, this mainly shows that sustained maintenance has not yet been demonstrated.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities in a package intended for forum deployments.
Both workflows were analyzed cleanly with no untrusted checkout, script injection, or audit findings, but one workflow grants top-level write permissions. That is a mild hygiene concern without an observed untrusted trigger or sink.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.